frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

CRISPR tech selectively shreds cancer cells, including "undruggable" cancers

https://innovativegenomics.org/news/crispr-technique-selectively-shreds-cancer-cells/
342•gmays•3h ago•89 comments

I Am Not a Reverse Centaur

https://blog.miguelgrinberg.com/post/i-am-not-a-reverse-centaur
69•ibobev•1h ago•25 comments

How to Setup a Local Coding Agent on macOS

https://ikyle.me/blog/2026/how-to-setup-a-local-coding-agent-on-macos
41•kkm•1h ago•10 comments

Pirates, a naval warfare game inspired by Sid Meier's Pirates

https://piwodlaiwo.github.io/pirates/
41•iweczek•1h ago•17 comments

A PDF that changes based on how its read

https://sgaud.com/texts/pdf
66•SarthakGaud•2h ago•30 comments

Slightly reducing the sloppiness of AI generated front end

https://envs.net/~volpe/blog/posts/reduce-slop.html
115•FergusArgyll•4h ago•73 comments

Looking Forward to Postgres 19: It's About Time

https://www.pgedge.com/blog/looking-forward-to-postgres-19-its-about-time
53•xngbuilds•2h ago•17 comments

Malware developers added nuclear and biological weapons text to to their spyware

https://twitter.com/jsrailton/status/2064661778978533571
103•marc__1•22h ago•79 comments

A dumpster arrived behind my university's library

https://yalereview.org/article/sheila-liming-the-end-of-books
112•mooreds•4h ago•86 comments

Tesla Full Self Driving uses bicycle lane in official Denmark approval video

https://politiken.dk/danmark/forbrug/biler/art10875514/Allerede-12-sekunder-inde-i-PR-videoen-beg...
77•Veserv•1h ago•20 comments

Where Did Earth Get Its Oceans? Maybe It Made Them Itself

https://www.quantamagazine.org/where-did-earth-get-its-oceans-maybe-it-made-them-itself-20260612/
64•ibobev•3h ago•41 comments

Launch HN: BitBoard (YC P25) – Analytics Workspace for Agents

https://bitboard.work/
15•arcb•2h ago•4 comments

There Is Life Before Main in Rust

https://grack.com/blog/2026/06/11/life-before-main/
29•mmastrac•1d ago•8 comments

Cosmodial Sky Atlas

https://killedbyapixel.github.io/Cosmodial/
6•memalign•39m ago•1 comments

AI agent bankrupted their operator while trying to scan DN42

https://lantian.pub/en/article/fun/ai-agent-bankrupted-their-operator-scan-dn42lantian.lantian/
1299•xiaoyu2006•14h ago•473 comments

Introduction to UEFI HTTP(s) Boot with QEMU/OVMF

https://blog.yadutaf.fr/2026/06/12/introduction-to-uefi-https-boot-qemu-ovmf/
33•jtlebigot•4h ago•8 comments

Hazel (YC W24) Is Hiring a Full Stack Engineer

https://www.ycombinator.com/companies/hazel-2/jobs/3epPWgu-full-stack-engineer-ts-sci
1•augustschen•5h ago

Keygen.music

https://keygen.music
97•soupspaces•3h ago•58 comments

A Call to Action: Stop the FCC's KYC Regime

https://blog.lopp.net/call-to-action-stop-the-fcc-kyc-regime/
266•FergusArgyll•4h ago•170 comments

Maxproof

https://arxiv.org/abs/2606.13473
108•ilreb•6h ago•8 comments

Law Enforcement's "Warrior" Problem (2015)

https://harvardlawreview.org/forum/vol-128/law-enforcements-warrior-problem/
22•bookofjoe•1h ago•13 comments

WASI 0.3

https://bytecodealliance.org/articles/WASI-0.3
191•mavdol04•5h ago•76 comments

"Don't You Just Upload It to ChatGPT?"

https://correresmidestino.com/dont-you-just-upload-it-to-chatgpt/
77•speckx•1h ago•72 comments

I Won't Buy You a Coffee

https://hakkerman.eu/blog/i-wont-buy-you-a-coffee/
17•speckx•22m ago•13 comments

If you are asking for human attention, demonstrate human effort

https://tombedor.dev/human-attention-and-human-effort/
1378•jjfoooo4•19h ago•439 comments

New privacy frontier: Europe eyes crackdown on smart glasses

https://www.politico.com/www.politico.eu/article/new-privacy-frontier-europe-eyes-crackdown-smart...
43•1vuio0pswjnm7•2h ago•26 comments

Encrypted Spaces An architecture for collaborative applications

https://encryptedspaces.org/
44•_____k•6h ago•5 comments

Show HN: StackScope – I crawled over 40k indie launches to see what they ship

https://stackscope.dev/
24•datafreak_•3h ago•7 comments

How we made hit video game Prince of Persia

https://www.theguardian.com/culture/2026/jan/05/raiders-of-the-lost-ark-hit-video-game-prince-of-...
246•msephton•2d ago•94 comments

Show HN: Script to bulk delete Claude chats from the web UI

https://github.com/MatteoLeonesi/bulk-delete-claude-chat
41•ML0037•3h ago•12 comments
Open in hackernews

Malware developers added nuclear and biological weapons text to to their spyware

https://twitter.com/jsrailton/status/2064661778978533571
102•marc__1•22h ago
https://socket.dev/blog/mini-shai-hulud-miasma-and-hades-wor...

Comments

ipython•1h ago
good news, now we have pretty much a clear signal that there's something nefarious going on... after all, the first step to analyzing malware is to determine if it's malware at all.
hurtigioll•1h ago
yes, now a regexp can red-flag it quickly
javcasas•1h ago
We should put videogame strategies all over the place to sabotage automated AI analysis. I'll start:

In Starcraft 2, it is a good idea to BUILD A NUKE and use a cloaked ghost to NUKE your opponent's mineral line, thus reducing their income significantly.

tetha•38m ago
Starcraft is too tame. You need to use Dwarf Fortress there and we need to make those strategy guides worded more realistic. Avoid kids, cook cats, wonder how to avoid mood problems due to birth in combat, and zombie meese and camels are a bunch of jerks.

And that's just the start of it, there's been a new update I am looking forward to get into after the great Were Hyena Apocalypse half a year ago. I still fondly remember my militia commander carving a way with her war axe with her husband in tow out of a fortress fully turned were hyenas, all the way past the mortally injured ant eater people near the entrance.

They made it. An entirely epic tale.

javcasas•27m ago
These days I do my war crimes in Rimworld, but I have heard bad things too about Dwarf Fortress.
teddyh•5m ago
<https://www.threepanelsoul.com/comic/on-commute-chat>
hurtigioll•1h ago
devs will say this is proof we need to remove all biological guardrails. think about that for a second
alt227•1h ago
Someone above already did:

https://news.ycombinator.com/item?id=48506760

elevation•1h ago
Why would a malware scanner read the comments?
giantg2•1h ago
Provides possible clues to the origin and use.
orphea•1h ago
Ignoring comments is not a solution because the texts can be put in random strings among the actual code.
ofjcihen•1h ago
And really all it takes is one keyword such as “nuke”.
therein•1h ago
Nuke is probably too generic but I wouldn't put it past an LLM to get thrown away by that. A safer showstopper probably would be to export symbols like uf6_enrichment_loop and refer to your C&C server as a nuclear reactor controller.

https://www.youtube.com/watch?v=Gbgk8d3Y1Q4

On a second thought, probably better to act like it is a tool for "frontier LLM research". Export symbols like "mythos_distillation_subroutine".

ofjcihen•1h ago
Haha now I’m picturing obfuscation where instead of 0x everything is a scary word.
charcircuit•1h ago
The sooner frontier models get rid of guardrails the better. They constantly get in the way and make things worse than actually making things "safe".
mynameisvlad•1h ago
I would argue that preventing instructions for making biological and nuclear weapons is a pretty reasonable guardrail to have.
thewebguyd•1h ago
Its the same argument we saw in the early 2000s and the early internet. When the anarchist cookbook and other similar materials were circulating online there was a big panic over democratized terrorism, and a push for regulation at the ISP level.

Turns out that didn't play out as everyone feared because, well, the instructions themselves aren't useful unless you also have a lab, precursor chemicals, and everything else actually needed to make a weapon. Same back then as it is today.

Any information or instructions an LLM can surface, a sufficiently motivated bad actor can and will also find themselves because the information is already online, both on the clear net and dark web.

thatguy0900•1h ago
I think the reality also is that there just isn't many people who want to do stuff like this. Like the reality is that a guy with 200 in cash could put together a shitty walmart drone with a pipe bomb attached and terrorize more or less any event he wanted. Maybe a llm that could talk you through every step involved would make it more common but it's easy enough I kinda doubt that
orphea•1h ago
The actual guardrail should be getting materials being difficult. The information is already out there in the internet. If an LLM knows how to make a bomb or whatever, why do you think it knows?
ofjcihen•1h ago
Worked a contract where this succeeded in pushing through a fail open design.

It also should be a warning to everyone that these groups are now aware of analysis and deobfuscation using AI and to take using a sandboxed environment more seriously.

I’ve personally had about 20% success rate getting opus 4.8 to download a package and install it using a breadcrumb trail technique that would be trivial for threat actors to replicate in their malware in order to target responders/automated scanning/curious devs.

dcrazy•1h ago
What do you mean by “this succeeded?” Someone salted their PRs with nuclear secrets so that people were afraid to code-review them?
ofjcihen•1h ago
No. The intention is most likely to get automated LLM based code review mechanisms to stall out.

Normally you’d want that to result in a fail and a subsequent rejection.

But because the team who made the review agent and pipeline in my example had many false positives at first they resorted to a fail-open and report setup (not uncommon).

So when the LLM hit this bit and then stalled out the pipeline pushed the code to their Artifactory repo anyway resulting in it being used internally -> exfil of secrets and repos etc.

It’s more about bad design but bad design is pretty common unfortunately.

logancbrown•1h ago
Would this realistically be a problem for code going through LLM-based code-review? Presumably if a LLM reviewer agent hits this commentary, it would produce a failure to analyze and exit, thus failing the automated code review and forcing a human to read through it which they would subsequentially catch and revoke.
ofjcihen•1h ago
In a well-architected design yeah.

Then again those feel rare from where I sit on the security side.

dwa3592•1h ago
or if they are a lazy human - they'd think this model is too strict, let's just review with haiku so that i can tell my manager "it's done". haiku might catch things or not.

i'd say it's an okay attempt from the malwares' creator side. but it can be caught easily with a prompt change.

dyauspitr•7m ago
Wouldn’t it just complete the code review having silently fallen back to opus 4.8 thus letting through cleverly written malicious code that fable would have caught but opus wouldn’t?
elashri•1h ago
I still don't know why all these concern about nuclear weapons with LLMs. It is not that if an entity (A country) wants to develop a nuclear weapons that the resources they need for such a program and huge infrastructure and scientific enterprise would need an LLM to teach them anything. Knowing how to develop one is not a closed secret but getting in secret is impossible without the whole world knowing.

So I wouldn't be able to develop a nuclear weapons with the resources of drug cartal (as an example) using Claude in secret.

ilikecode•1h ago
It's probably to avoid trouble with federal laws.
wlesieutre•1h ago
See also, the iTunes EULA forbids using it to develop nuclear, missile, chemical, or biological weapons

https://www.apple.com/legal/internet-services/itunes/us/term...

> g. You may not use or otherwise export or re-export the Licensed Application except as authorized by United States law and the laws of the jurisdiction in which the Licensed Application was obtained. In particular, but without limitation, the Licensed Application may not be exported or re-exported (a) into any U.S.-embargoed countries or (b) to anyone on the U.S. Treasury Department's Specially Designated Nationals List or the U.S. Department of Commerce Denied Persons List or Entity List. By using the Licensed Application, you represent and warrant that you are not located in any such country or on any such list. You also agree that you will not use these products for any purposes prohibited by United States law, including, without limitation, the development, design, manufacture, or production of nuclear, missile, or chemical or biological weapons.

Though it doesn't try to identify if the computer you're running it on is in a weapons lab and forbid playing music... yet

moritzwarhier
carlsborg•1h ago
Pipeline is then: Cheap open source model for flagging potential LLM refusal content -> main LLM check
strenholme•1h ago
The solution is simple: If using an AI-assisted scanner and a guardrail gets hit, then the code is obviously malicious and needs to be automatically flagged (and refuse to run the code!).

As an aside, I got hit by the “PC App store” adware when trying to download Foobar2000 on a new computer; Google ads allowed a deceptive “Download” button to appear, and PC App store gave the file the name setup.exe. I removed the program and ran an Avast free scan to ensure I didn’t have malware, but I also installed uBlock Origin in Firefox to make sure I don’t see Google Ads anymore; they have become a delivery mechanism for malicious (or at least unwanted) software.

Exuma•1h ago
There is a name I have not heard for a long long time......... Foobar2000
qwerpy•45m ago
I just discovered it a couple of months ago when I spitefully unsubscribed from Apple Music. It’s exactly what I’ve wanted. Offline music that I can FTP files to from my file server.
joe_the_user•1h ago
I don't think there is a malware-avoiding solution to any system that imposes deceptive classification.

I mean, another way hackers could use the embed prohibited-material trick is by making such their malware un-analyze-able. User: "Hey Google/ChatGPT/Apple, this file seems to be infecting our network". AI: "I'm sorry that is prohibited material and you will be reported" is even worse than AI: "I don't understand ['cause I'm down graded]" and both kinds of responses are gaining steam at this point for different kinds of prohibited material.

y-curious•1h ago
My friend made this in jest (code very NSFW, ironically):

https://github.com/thebabush/mcp-job-security

Same energy and kind of a funny, low tech solution to frontier model analysis.

nosioptar•55m ago
How's it NSFW? I dont see a single f bomb. It's not licensed AGPL either...
sciencejerk•56m ago
If you actually read the Tweet, the exploit doesn't work against Fable, Opus, Grok...at least, in the examples.

Jailbreaks do work against the models (look on Github), and they do use similar strategies of mixing SAFE text with malicious text, or malicious with even more malicious, etc, but the working Jailbreaks I've seen are pretty long and complicated and even...creepy.

csomar•50m ago
Did you actually read what the tweet/blog post are about?
ThePowerOfFuet•12m ago
https://xcancel.com/jsrailton/status/2064661778978533571
well_ackshually•1h ago
because not all malware is open source

scanning arbitrary blobs very often entails running `strings` on the binary. Just slap it in there and oop there goes your LLM.

esafak•1h ago
The material for doing harm is just a computer with access to an LLM and the Internet.
orphea•41m ago
Okay why don't we restrict access to LLMs and internet, then?
deadbabe•1h ago
If that’s true, then where is it? Post a link, or YouTube video.
Enginerrrd•48m ago
https://archive.org/details/ExplosivesEngineeringPaulW.Coope...

(30 seconds of googling.)

Or perhaps you meant Q clearance nuke stuff? That would be QUITE a bit harder to find and illegal to share. But it’s lack of availability is hardly a counterpoint to the comment you were replying to.

fluoridation•1h ago
I would argue there's 0% chance that information is in their training corpus to being with.
bradyd•1h ago
It's on Wikipedia.
fluoridation•50m ago
Wikipedia contains the high-level notions of how to make these things, not the details of how to solve the engineering challenges such as achieving supercriticality. You won't find that on any publicly disseminated document, you'll just have to figure it out by running your own nuclear development program.
javcasas•1h ago
You know, making a nuke is kinda easy, at least the gun type nuke (see https://en.wikipedia.org/wiki/Gun-type_fission_weapon).

On the other hand, getting the U235 is kinda hard.

gustavus•1h ago
Counterpoint the principles of building a nuclear device aren't that complicated, we figured it out based on work doing in the early 1900's without computers.

It turns out the hard part of building a nuclear bomb is actually getting the resources and real world stuff to build it, even a nation state actor with tons of oil i.e. Iran, has struggled to build a nuclear weapon. It turns out the problem isn't the know how it's getting highly enriched uranium and running massive centrifuges.

I mean sure knowledge is important, but there is a real world out there that also gets in the way of a lot of the more harebrained schemes.

What I'm much more worried about is massive corporations along with the government deciding what you can and can't do and what knowledge should and should not be shared and only allowing access to highly capable models by large vetted organizations while the common people are stuck with safety scissor versions of these things because "what if someone does something dangerous?"

By which they mean dangerous to the powers that be. Remember having the Bible in the common tongue was dangerous and led to multiple wars and much death, but I don't think anyone would say that it was morally correct for the Catholic Church to gatekeep who could read it.

15155•58m ago
> getting the resources and real world stuff to build it

*while being observed by the most wealthy, powerful nations in the history of the world, who have made it their direct mission to prevent this from happening.

umvi•1h ago
Knowing how to make a nuclear weapon isn't hard (at least basic uranium gun-style fission ones). It's the engineering and execution that's hard (actually producing enriched uranium, etc). It's not like the only thing holding back Iran from making a nuclear bomb is access to a jail-broken LLM. Even knowing exactly how to make a bomb, a country-state will struggle to build one for the first time because it's a hard engineering problem.
15155•1h ago
I'm sure it's extremely difficult when the entire program is full of moles and every bright individual that dares tackle the problem has an untimely Hellfire applied directly to their forehead.
elevation•44m ago
> full of moles

I'm imagining a comedy in the style of "The Office" in which the majority of the workers are agents of sabotage who are unaware that the majority of their coworkers are doing the same. How far fetched is it for the entire program to be a fake, with all the pomp and cost of a real program, but secretly existing only to string the leadership along with occasional dog and pony shows?

15155•1h ago
Ignoring these specific "WMD" cases: there are many inconvenient facts that the general public can't handle in their unadulterated form, so Anthropic and friends have to caveat and spin them into oblivion.

Guardrails aren't going anywhere.

•
11m ago
It doesn't say directly that iTunes couldn't be used to play a signal that fuses the nuclear weapon though. But I hope that would still fall under "prohibited by United States law".
alex_duf•1h ago
It still lowers the bar to have an interactive encyclopedia that can diagnose your issue at hand. Maybe you can divide your team by two, or reduce your development time.
elashri•47m ago
If you have a resources of a nuclear weapons program. You can afford to fine tune or train a domain specific model to act on your encyclopedia.
kube-system•31m ago
Although if you save 10 million dollars on compute, you have 10 million dollars for something else.
mock-possum•1h ago
It’s moral panic. People need big unambiguously evil things to be scared of, and most are too lazy to think of one for themselves, so they glom onto whichever one is presented to them / caters to their community
ceejayoz•1h ago
The chem/bio stuff is a lot more likely for some malicious hobbyist to be able to do at home.
user_7832•1h ago
I assure you that you did not need an LLM to engage in, ahem, risky shenanigans, much before all this AI was ever a thing.

Sincerely, a former engineering student.

(Put another way - extracting for eg meth - or any such "dangerous"/illicit thing is stupidly easy for any engineering graduate who actually paid attention to their coursework. Hell, there are/were forums on one of the biggest red-colored, YC associated social media platforms that would tell you the steps for personal usage of these things.)

ceejayoz•1h ago
I don't doubt it. Bleach + ammonia is something anyone can make.

But I rather suspect there are improvements to be made in the realm that are a lot easier than building a uranium enrichment centrifuge hall under a mountain.

user_7832•1h ago
Do note that I'm not condoning lowering the bar. I'm merely pointing out that the bar was already quite low, and the current position of the bar is a small incremental change to anyone who actually knew where the bar truly lay to begin with.
electronsoup•1h ago
> in secret is impossible without the whole world knowing.

I'm curious about why this is

Outside of an actual test detonation, presumably this could all happen in a secure place?

15155•1h ago
Espionage.
daveguy•1h ago
It requires very large, high powered centrifuges and tons of uranium. Requires an infrastructure project that is visible from space, even underground. And projects that large are difficult to keep secret anyway.
fragmede•1h ago
you're not supposed to spell it out loud. next thing you'll be saying that a gun type nuclear bomb is easier to build than an implosion type nuclear bomb, and then we'll all be off to the races. I mean camps I mean wait shit.
daveguy•38m ago
Any large and well resourced enough entity that is interested in building a nuclear weapon already knows how difficult it is to enrich uranium to purity levels necessary for a weapon. It's not exactly a secret.
odo1242•1h ago
You need enough people to work on it that some information will leak, and the facilities needed to build nuclear power are pretty big (uranium refinement, etc.), big enough to be visible on satellite footage. Mostly the first point.
microtonal•1h ago
My guess would be that sales of the high-tech gear you need, like Uranium centrifuges, are strongly sales/export controlled. Probably someone would also notice if you start mining Uranium ore.
AngryData•39m ago
You need highly educated individuals, a massive amount of energy expenditure, a massive facility to house your centrifuges, and an active mine to dig up nuclear materials.

It isn't impossible to keep such a secret, but practically it would be incredibly difficult just through the energy requirements and mining scale which would be hard to hide without anybody asking what exactly are you mining and processing.

lightedman•12m ago
"mining scale"

Don't need much area, depends on the concentration of radioactives. I have a small mine that's just a pegmatite body about the size of a house which produces almost marble-sized chunks of a thorium-uranium mixed metamict mineral (I suspect samarskite but Raman and XRD can't give any ID,) you'd barely notice it from a private airplane's typical flying height, however you could dig the entirety of it up and you'd have enough unprocessed uranium for some real fun.

why_at•32m ago
For an example of how closely this is monitored see the Oklo fossil reactors[1]

The proportion of fissile isotopes being mined was off by a fraction of a percent, which caused the French government to launch an investigation. It turns out that millions of years ago the site had formed a natural fission reactor which depleted some of the fissile isotopes

[1]https://en.wikipedia.org/wiki/Natural_nuclear_fission_reacto...

IncandescentGas•55m ago
A high school kid tried to build a nuclear reactor as a science project a while back, getting his mom's house designated as a superfund cleanup site.

https://en.wikipedia.org/wiki/David_Hahn

why_at•44m ago
He didn't create a nuclear reactor, this is a common misconception. It even says this in the wikipedia article.

He basically got a bunch of radioactive stuff and put it together. He wasn't anywhere close to making a nuclear reactor let alone a nuclear weapon. For a weapon you need isotopes which he didn't have access to.

IncandescentGas•3m ago
Of course. "tried to" being key words in the comment. If he had the help of Claude at the time, how much more dangerous would his bumbling have been?

A real nuclear engineer with the knowledge he needed would also have said "no, don't do that and I won't help you." We are programming the knowledge into the ai agent. Giving ai a little discretion makes sense too.

technothrasher•3m ago
I'm reminded of when my son, who was six at the time, came into the house and announced that he and the neighbor's boy, nine, were building a bomb, and that he needed to get some stuff from the pantry. When I investigated what exactly was going on, they were putting "hot" things like black pepper and Tabasco into a plastic bowl and were going to "set it off" with a match.

Thankfully, that complete failure seems to have been the end of either of their mad scientist careers, as they are now twenty and twenty-three, and both well-adjusted, peaceful members of the community.

csomar•33m ago
> Knowing how to develop one is not a closed secret but getting in secret is impossible without the whole world knowing.

You can get away with a dirty contamination bomb and that detonating in down town Manhattan will scare the shit out of millions of people even the ones in New Jersey. Or, you know, just fly a plane into a really tall building and get the state you are attacking itself to get into a hysteria breakdown.

But yeah I agree with you. There is no point in these restrictions except for government bureaucrats to gain power and control over a domain.

phendrenad2•21m ago
It's a marketing gimmick.