frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Someone used my open source project to phish 14,000 people

https://andrej.sh/posts/phishing-through-my-open-source-project
19•andrejsshell•3h ago

Comments

sandeepkd•14m ago
Couple thing:

1. You are not alone, this happens at a large scale across the board with companies of all sizes.

2. More than likely the abuser did not do it manually, more than likely they automated it

3. As a thoughtful business one may have rolled out all the authentication features/gates if the business picks up, as a starter the safe idea could have been to put it behind any openly available OAuth provider

no_multitudes•13m ago
Please write your blog post yourself if you expect people to read it. The LLM output is very grating.
eggbrain•6m ago
There will always be a subset of users whose goal is to not use your service, but to arbitrage your service into the maximum value for themselves.

For example -- let's say you offer $100 in free AWS credits by signing up to your platform. Expect a malicious user to eventually come to your platform, realize they can resell those $100 in credits for $50, and start using your platform for their own gain. Unless the mechanisms you add in place to reduce fraud / second sign ups / etc is greater than the value that they are receiving ($50), they will continue.

With sites where the platform is free, the math almost always makes sense for these malicious users to eventually abuse. In this case it was leveraging the email reputation of another domain at no cost to their own (along with the added value of anyone getting phished), but on other sites it's public profiles being used for backlinks / spam, etc.

Bijou64: A variable-length integer encoding

https://www.inkandswitch.com/tangents/bijou64/
103•justinweiss•1h ago•37 comments

The Dead Economy Theory

https://www.owenmcgrann.com/p/the-dead-economy-theory
103•WillDaSilva•1h ago•76 comments

GTA 6 Developers Unionize

https://rockstarintel.com/gta-6-developers-announce-rockstar-games-union/
166•AndrewKemendo•1h ago•67 comments

I Am Retiring from Tech to Live Offline

https://openpath.quest/2026/i-am-retiring-from-tech-to-live-offline/
401•PinkG•2h ago•271 comments

High Density Living, 2000 Years Ago: Inside the Roman Apartment Building

https://commonedge.org/high-density-living-2000-years-ago-inside-the-roman-apartment-building/
79•surprisetalk•4h ago•22 comments

Danish Pension Blacklists SpaceX over 'Catastrophic Governance'

https://www.bloomberg.com/news/articles/2026-05-29/danish-pension-fund-blacklists-spacex-citing-g...
116•leopoldj•1h ago•66 comments

Notes from the Mistral AI Now Summit in Paris

https://koenvangilst.nl/lab/mistral-ai-now-summit
6•vnglst•35m ago•0 comments

Tulip mania: when a single flower was worth more than a house (2025)

https://dutchreview.com/culture/tulip-mania-netherlands/
113•dotcoma•5h ago•104 comments

CAPTCHAs can still detect AI agents

https://research.roundtable.ai/captchas-detect-ai/
8•timshell•1h ago•0 comments

Real-time LLM Inference on Standard GPUs: 3k tokens/s per request

https://blog.kog.ai/real-time-llm-inference-on-standard-gpus-3-000-tokens-s-per-request/
147•NicoConstant•7h ago•69 comments

Blue Origin's New Glenn blows up during static fire test

https://twitter.com/nasaspaceflight/status/2060164928472854821
420•enraged_camel•15h ago•419 comments

The UK Government's Low Value Purchase System Is a Waste of Time

https://shkspr.mobi/blog/2026/05/the-uk-governments-low-value-purchase-system-is-a-waste-of-time/
121•ColinWright•4h ago•72 comments

Someone used my open source project to phish 14,000 people

https://andrej.sh/posts/phishing-through-my-open-source-project
22•andrejsshell•3h ago•4 comments

Durable execution, the hard way

https://github.com/hatchet-dev/durable-execution-the-hard-way
15•abelanger•1d ago•0 comments

Headway Therapy Patients Forced to Scan Their Faces to Keep Getting Care

https://www.404media.co/headway-therapy-facial-scan-biometric-data-identity-verification/
62•pavel_lishin•2h ago•16 comments

Cedana (YC S23) Is Hiring

https://www.ycombinator.com/companies/cedana/jobs/d1vYocG-forward-deployed-engineer-ai-hpc
1•neelm•4h ago

The Secret Garden of Rock-Paper-Scissors

https://theshamblog.com/the-secret-garden-of-rock-paper-scissors/
14•scottshambaugh•2h ago•1 comments

Claude Code – Everything You Can Configure That the Docs Don't Tell You

https://buildingbetter.tech/p/i-read-the-claude-code-source-code
301•ankitg12•14h ago•60 comments

Orchestrating AI code review at scale

https://blog.cloudflare.com/ai-code-review/
99•pramodbiligiri•3d ago•37 comments

The Framework 12 is dead. Apple killed it [video]

https://www.youtube.com/watch?v=aPVAnwuSjfk
5•throwaway2037•1h ago•3 comments

Claude Opus 4.8

https://www.anthropic.com/news/claude-opus-4-8
1688•craigmart•1d ago•1311 comments

Bricks and Minifigs Stole a Man's $200k Lego Collection

https://mybricklog.com/blog/bricks-minifigs-corporate-stole-old-mans-200000-lego-collection
1220•philips•21h ago•534 comments

Even (very) noisy LLM evaluators are useful for improving AI agents

https://www.tensorzero.com/blog/even-very-noisy-llm-evaluators-are-useful-for-improving-ai-agents/
22•GabrielBianconi•2d ago•5 comments

Let's compile Quake like it's 1997

https://fabiensanglard.net/compile_like_1997/
143•goranmoomin•13h ago•48 comments

Local Git Remotes

https://cblgh.org/posts/local-git-remotes/
60•surprisetalk•4h ago•46 comments

We should be more tired than the model

https://vickiboykis.com/2026/05/28/we-should-be-more-tired-than-the-model/
86•tosh•4h ago•82 comments

An Obsessive Focus on UX: Pilot's Pressure-Regulating Kire-Na Highlighter

https://www.core77.com/posts/143832/An-Obsessive-Focus-on-UX-Pilots-Pressure-Regulating-Kire-Na-H...
44•surprisetalk•3d ago•11 comments

Is AI causing a repeat of Front end's Lost Decade?

https://mastrojs.github.io/blog/2026-05-23-is-AI-causing-a-repeat-of-frontends-lost-decade/
186•xyzal•5h ago•179 comments

Wterm – Terminal Emulator for the Web

https://wterm.dev/
38•m3h•8h ago•11 comments

Volkswagen blocks Home Assistant by requiring client assertion

https://github.com/robinostlund/homeassistant-volkswagencarnet/issues/967
328•Kwastie•11h ago•167 comments