frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

The VibeSec Reckoning

https://martinfowler.com/articles/vibesec-reckoning.html
27•HieronymusBosch•1h ago

Comments

_pdp_•46m ago
We will learn the hard way... like always.
some_random•39m ago
Something worth noting is that the types of vulnerabilities LLMs introduce are notably different from what humans introduce, way fewer local issues like syntax mistakes, simple memory problems, etc and far more broad issues like authn/authz
bcjdjsndon•35m ago
Vibe coding into production? You don't need to wait for scientists to produce research to know that's not a great idea.

You played yaself

comandillos•33m ago
I mean, isn't introducing safety guardrails as part of the system prompt actually a REALLY bad idea? This way you basically fully rely on the model to follow the rule, but its clear that even frontier models like Opus will start ignoring these things after a certain context length...

In our company we are just running agents inside isolated containers with isolated network access so it cannot even SSH or fuck up anything even if it gets access into it... That's the only and safest way... inconvenient, true, but the only safe option.

PS: At the same time I've observed this way actually people uses the agent in a more reasonable way, e.g. producing helper scripts to help them with their daily stuff, produce very specific things, create simple PoCs, but they don't commit to vibe-code all the functionality in their corresponding software products.

et1337•31m ago
> prompting for test-driven development is not the same as enforcing code coverage thresholds in your build tool

Are they actually different? I would guess they have roughly the same efficacy. 100% code coverage means nothing, and this is especially true with LLMs.

Foobar8568•31m ago
First so called vulnerability, isn't how a lot platforms are actually built? Share a link/copy a link, and more often than not, I am sure to have read a warning like "anyone with that link may access that file".

Now should I mention all the screw up I have seen in several Saas 1b+ valuation, including DocuSign/ and more security oriented ones (PIM related etc?).

For any softwares, you need a minimum critical mindset and experiences that you don't usually see.

adamddev1•24m ago
> "To combat this we need to write a security context file to guide the AI, be cautious with AI permission requests, create a daily security intelligence feed, and provide builders with a secure-by-default harness and templates."

Edit: To combat this we need to actually write and understand our code.

I'm Tired of Talking to AI

https://orchidfiles.com/im-tired-of-ai-generated-answers/
1184•theorchid•4h ago•622 comments

Mini Micro Fantasy Computer

https://miniscript.org/MiniMicro/index.html#about
161•nicoloren•5h ago•63 comments

Corporations can vote in some Delaware elections, judge says

https://news.bloomberglaw.com/esg/corporations-have-the-right-to-vote-in-delaware-town-judge-says
49•marcher•35m ago•27 comments

Matrix Multiplications on GPUs Run Faster When Given "Predictable" Data

https://www.thonking.ai/p/strangely-matrix-multiplications
71•tosh•4d ago•13 comments

XLIDE: VBA without excel

https://github.com/WilliamSmithEdward/xlide_vscode
41•sts153•3h ago•7 comments

All of human cooking compressed into 2 megabytes

https://arxiv.org/abs/2605.22391
196•josefchen•7h ago•74 comments

Incident with Pull Requests, Issues, Git Operations and API Requests

https://www.githubstatus.com/incidents/xy1tt3hs572m
158•maxnoe•3h ago•128 comments

The Melancholy of Slaying Monsters

https://thereader.mitpress.mit.edu/the-strange-melancholy-of-slaying-monsters/
209•prismatic•20h ago•85 comments

My new obsession: A horse-racing board game of pure luck

https://alexanderbjoy.com/horse-race-board-game/
12•surprisetalk•1d ago•3 comments

The VibeSec Reckoning

https://martinfowler.com/articles/vibesec-reckoning.html
28•HieronymusBosch•1h ago•7 comments

Cloudflare Flagship

https://developers.cloudflare.com/flagship/
307•tjek•16h ago•157 comments

Raft Consensus with a Minority of Nodes

https://padhye.org/raft-minority/
88•moarbugs•1d ago•10 comments

Claude Code as a Daily Driver: Claude.md, Skills, Subagents, Plugins, and MCPs

https://arps18.github.io/posts/claude-code-mastery/
200•arps18•10h ago•157 comments

BadHost – CVE-2026-48710: Starlette Host-Header Auth Bypass

https://badhost.org/
103•ylk•1d ago•37 comments

Declassified CIA Cartography Maps from the 1980s

https://brilliantmaps.com/cia-maps-1980s/
26•speckx•1h ago•11 comments

Phloto for My Photo Flow

https://cceckman.com/writing/phloto/
5•evakhoury•18h ago•0 comments

Private Equity Bought America's Essential Services

https://rubbishtalk.com/economy/how-private-equity-bought-americas-essential-services/
241•NoRagrets•3h ago•296 comments

That Methyl Methacrylate Tank

https://www.science.org/content/blog-post/methyl-methacrylate-tank
384•nooks•20h ago•171 comments

The worst job interview I ever had

https://www.oliverio.dev/blog/the-worst-job-interview-i-had
501•oliverio•19h ago•376 comments

We are Poles, so, of course, we print in Latin

https://www.ustc.ac.uk/news/we-are-poles-so-of-course-we-print-in-latin
84•danielam•3d ago•46 comments

What Is a Direct Attach Copper (DAC) Cable

https://www.servethehome.com/what-is-a-direct-attach-copper-dac-cable/
60•teleforce•1d ago•46 comments

Atomically precise mechanosynthesis of carbon structures on hydrogenated Silicon

https://arxiv.org/abs/2605.27250
6•gene-h•4h ago•0 comments

A few interesting modern pixel fonts

https://unsung.aresluna.org/a-few-interesting-modern-pixel-fonts/
394•zdw•1d ago•93 comments

I built a Git-tracked book production pipeline

https://www.djspeckhals.com/posts/2026-05-22-how-i-bypassed-adobe-and-microsoft-to-build-a-git-tr...
273•dustin1114•4d ago•70 comments

Go: Support for Generic Methods

https://github.com/golang/go/issues/77273
92•f311a•6h ago•69 comments

TSDuck: Open-source toolkit for MPEG-TS analysis and manipulation

https://tsduck.io/
59•phantomathkg•13h ago•5 comments

Italy region: +200% tax on datacenters built in green/agricultural areas

https://en.ilsole24ore.com/art/lombardy-introduces-increased-charges-of-up-to-200-per-cent-for-da...
89•napolux•1h ago•132 comments

Spain blocks prediction markets Polymarket, Kalshi over lack of gambling licence

https://www.reuters.com/business/spain-blocks-prediction-markets-polymarket-kalshi-over-lack-gamb...
1037•thm•1d ago•477 comments

Launch HN: Minicor (YC P26) – Windows desktop automations at scale

https://www.minicor.com/
98•fchishtie•1d ago•61 comments

C array types are weird

https://anselmschueler.com/blogposts/2025-c-pointers/
117•signa11•2d ago•117 comments