frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

LittleSnitch for Linux

https://obdev.at/products/littlesnitch-linux/index.html
692•pluc•8h ago•200 comments

Open Source Security at Astral

https://astral.sh/blog/open-source-security-at-astral
172•vinhnx•5h ago•30 comments

I ported Mac OS X to the Nintendo Wii

https://bryankeller.github.io/2026/04/08/porting-mac-os-x-nintendo-wii.html
1563•blkhp19•17h ago•272 comments

Haunted Paper Toys

http://ravensblight.com/papertoys.html
75•exvi•2d ago•1 comments

The Importance of Being Idle

https://theamericanscholar.org/the-importance-of-being-idle/
174•Caiero•2d ago•89 comments

Process Manager for Autonomous AI Agents

https://botctl.dev/
31•ankitg12•3h ago•6 comments

Dr. Dobb's Developer Library DVD 6

https://archive.org/details/DDJDVD6
28•kristianp•4d ago•9 comments

USB for Software Developers: An introduction to writing userspace USB drivers

https://werwolv.net/posts/usb_for_sw_devs/
293•WerWolv•13h ago•36 comments

Understanding the Kalman filter with a simple radar example

https://kalmanfilter.net
335•alex_be•16h ago•44 comments

They're made out of meat (1991)

http://www.terrybisson.com/theyre-made-out-of-meat-2/
534•surprisetalk•21h ago•147 comments

Who is Satoshi Nakamoto? My quest to unmask Bitcoin's creator

https://www.nytimes.com/2026/04/08/business/bitcoin-satoshi-nakamoto-identity-adam-back.html
483•jfirebaugh•1d ago•539 comments

Six (and a half) intuitions for KL divergence

https://www.perfectlynormal.co.uk/blog-kl-divergence
74•jxmorris12•1d ago•9 comments

ML promises to be profoundly weird

https://aphyr.com/posts/411-the-future-of-everything-is-lies-i-guess
495•pabs3•20h ago•486 comments

Git commands I run before reading any code

https://piechowski.io/post/git-commands-before-reading-code/
2033•grepsedawk•1d ago•431 comments

Muse Spark: Scaling towards personal superintelligence

https://ai.meta.com/blog/introducing-muse-spark-msl/?_fb_noscript=1
339•chabons•17h ago•327 comments

Improving storage efficiency in Magic Pocket, Dropbox's immutable blob store

https://dropbox.tech/infrastructure/improving-storage-efficiency-in-magic-pocket-our-immutable-bl...
8•laluser•5d ago•0 comments

MegaTrain: Full Precision Training of 100B+ Parameter LLMs on a Single GPU

https://arxiv.org/abs/2604.05091
294•chrsw•21h ago•54 comments

I imported the full Linux kernel git history into pgit

https://oseifert.ch/blog/linux-kernel-pgit
127•ImGajeed76•3d ago•18 comments

Expanding Swift's IDE Support

https://swift.org/blog/expanding-swift-ide-support/
113•frizlab•13h ago•52 comments

Map Gesture Controls - Control maps with your hands

https://sanderdesnaijer.github.io/map-gesture-controls/
27•hebelehubele•4d ago•4 comments

Understanding Traceroute

https://tech.stonecharioteer.com/posts/2026/traceroute/
128•stonecharioteer•3d ago•21 comments

Ask HN: Any interesting niche hobbies?

360•e-topy•3d ago•531 comments

Show HN: A (marginally) useful x86-64 ELF executable in 301 bytes

https://github.com/meribold/btry
35•meribold•2d ago•8 comments

John Deere to pay $99M in right-to-repair settlement

https://www.thedrive.com/news/john-deere-to-pay-99-million-in-monumental-right-to-repair-settlement
305•CharlesW•12h ago•93 comments

Teardown of unreleased LG Rollable shows why rollable phones aren't a thing

https://arstechnica.com/gadgets/2026/04/teardown-of-unreleased-lg-rollable-shows-why-rollable-pho...
105•DamnInteresting•1d ago•47 comments

Audio Reactive LED Strips Are Diabolically Hard

https://scottlawsonbc.com/post/audio-led
227•surprisetalk•1d ago•63 comments

Show HN: Is Hormuz open yet?

https://www.ishormuzopenyet.com/
395•anonfunction•11h ago•162 comments

Union types in C# 15

https://devblogs.microsoft.com/dotnet/csharp-15-union-types/
202•0x00C0FFEE•4d ago•184 comments

Veracrypt project update

https://sourceforge.net/p/veracrypt/discussion/general/thread/9620d7a4b3/
1214•super256•1d ago•446 comments

I've been waiting over a month for Anthropic to respond to my billing issue

https://nickvecchioni.github.io/thoughts/2026/04/08/anthropic-support-doesnt-exist/
361•nickvec•15h ago•174 comments
Open in hackernews

Some iPhone Apps Receive Mysterious Update 'From Apple'

https://www.macrumors.com/2026/04/06/iphone-apps-from-apple-update/
83•tosh•2d ago

Comments

swizz89•2d ago
Is it a conspiracy, or just a bug in the app store? Nobody knows.
Cthulhu_•21h ago
Well no, people do know. It's not a bug because it's clearly intentional. It's not a conspiracy because that's just vagueposting.
F30•2d ago
In the past, things like this used to be done for signing certificate rollovers.
xg15•1d ago
I wonder what this means:

> When analyzing the code of one of the apps that received an Apple update, MacRumors could not find what had changed.

Unfortunately, it's put so vaguely, it could either mean the diff showed no code changes - or they were unable to compute a diff, for whatever reason.

If it's the former, that would be a strong indication for certificate issues, I think.

NSUserDefaults•2d ago
Could be a fix for per-device asset optimization that got messed up somehow.
Someone•2d ago
FTA: “The update text is appearing on apps that have not been updated in some time, as well as apps that received recent updates, so it's not clear what the apps have in common.”

⇒ I think that’s unlikely. If some optimization got broken that produces results that bad that it has to be fixed, users would have noticed in those apps that “have not been updated in some time”.

merelysounds•2d ago
Speculation for fun: I always thought popular apps can use private apis or are handled in a special way by the OS itself. If yes, perhaps this is related.

Then again I found no source for that - and some certificate rollover seems more likely.

politelemon•2d ago
Neither developers nor consumers should be comfortable with this, as this breaks the trust model and is extremely worrying. The site is of course downplaying it given its name, which is a huge shame.
calmingsolitude•1d ago
What trust model? Is there anyway to verify that an app from the app store is the same as the one the developer uploaded?
Cthulhu_•21h ago
What trust model are you thinking of though? Because another way to look at it is that Apple has pushed an update to ensure these apps keep working and remain secure.

And this is part of the agreement between an app developer and Apple; for a long time now, a developer doesn't upload a full compiled app to Apple, but a package containing partially compiled (itermediary language) code and assets for many different platforms and resolutions, leaving it up to Apple to do the final assembly based on what device it downloads. This allows them to (re)compile for newer hardware, 32 vs 64 bit CPUs, save bandwidth and storage space by only having the device download the assets for its device (and for e.g. games the assets for the level they are playing at that time), etc.

So again, what trust model are you thinking of? Apple is a trusted party when it comes to this, I'd even argue they're more trustworthy than the app developers themselves.

hdgvhicv•2d ago
Vast majority of change logs are along the lines of “implements to make things better”
akimbostrawman•1d ago
that's proprietary software for you
gbil•2d ago
I saw this the other day in a couple of apps, I've checked other apps and didn't have that, did a quick check on HN frontpage and saw nothing and said wth I'll update to see if something changes in the app or there is a message. Got nothing, and didn't think more about it but I'm not sure why, is it the "trust in the process" thing or what?
charcircuit•2d ago
This sounds like a bug with the App Store app than a new update actually being installed.
eecc•2d ago
hmm, my money is on some actively used 0-day exploit that Apple is sealing shut before the CVE gets announced.

By the looks of the app list, they seem to be apps and games that used to be popular and have fallen in disrepair and apps that are starved of maintenance attention.

On the one hand it could be an exceptionally good example of "stewardship"; on the other hand, if this is true, what if authorities could later compel Apple to manipulate applications in some malign manner?

iso1631•1d ago
If you are worried about apple being compelled to do something, then they can do that at the OS level rather than something obvious in the

I think this is simply updating some api call which no longer works properly, coupled with the terrible "changelogs" that are the norm on the app store. Someone down thread mentioned certificate rollover.

A sensible changelog would be "update expired certificate", or "fix integration with ios 26.2", or "patch security issue"

An actual changelog would be "we're bringing you ever more great new improvements"

Here's the latest Audible one:

> At Audible, we're always making updates and improvements to make your listening experience better.

> If you're experiencing issues, please reach out to customer services. For feedback or suggestions contact us at audible.co.uk/help

This is the same every time, because these changelogs are meaningless.

ting0•2d ago
Has anyone ever done a proper security audit of VLC that is downloaded from the web? I don't trust it, and the fact that their releases on Github don't include binaries makes me trust it even less. Nobody is compiling VLC from source, and they don't provide any sort of provenance from the GH actions pipeline.
ohhman11•2d ago
This seems utterly pointless to worry about. You're fucked either way if you trust VLC.
bloudermilk•1d ago
Care to elaborate?
bzzzt•1d ago
Look at the supported formats lists. It includes so many parsers, mostly written in C, which means there probably are a few dozen ways to exploit the player.
ohhman11•1d ago
It's downright trivial to hide a backdoor in a codebase like this.
Cthulhu_•21h ago
Can you tell us about any prior or active incidents like that though?

That is, I'm calling you out for fearmongering, for a possible what-if, but given how popular VLC is you'd think it would've happened / is actively happening already. And there is no evidence for that.

kykat•1d ago
All linux distros build VLC from source
NeoBild•1d ago
The FairPlay certificate rotation theory makes the most sense. Apple has done silent re-signing before when DRM certificates expired. What's unusual here is the update note surfacing in the App Store UI at all — that's probably an unintended side effect of whatever pipeline they're running this through, not intentional transparency.
rascul•1d ago
If Apple is distributing modified vlc binaries without releasing the source of the changes when requested, is that a potential legal problem?
Cthulhu_•21h ago
As always, it depends; VLC "the iOS app" is not the same as VLC "the binary compiled from source". The article itself says they couldn't find any code changes, and the theories are that a certificate was updated.

I don't believe an iOS distribution specific certificate falls under the license you're referring to, but I'm no expert on these matters.