frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

.self: A new top-level domain designed to support self-hosting

https://hccf.onmy.cloud/2026/06/21/reclaiming-our-digital-selves-hccfs-vision-for-a-human-centere...
203•HumanCCF•3h ago•131 comments

Qwen 3.6 27B is the sweet spot for local development

https://quesma.com/blog/qwen-36-is-awesome/
509•stared•5h ago•444 comments

Free the Icons

https://weblog.rogueamoeba.com/2026/06/26/free-the-icons/
74•zdw•2d ago•12 comments

Is It Out Yet?

https://outyet.ai
26•partsch•1h ago•10 comments

Rocketlab acquires Iridium

https://investors.rocketlabcorp.com/news-releases/news-release-details/rocket-lab-acquire-iridium...
332•everfrustrated•8h ago•203 comments

Ornith-1.0: self-improving open-source models for agentic coding

https://github.com/deepreinforce-ai/Ornith-1
125•danboarder•5h ago•27 comments

Scientists find molecular-level evidence for two structures in liquid water

https://phys.org/news/2026-06-scientists-molecular-evidence-liquid.html
9•wglb•41m ago•1 comments

A native graphical shell for SSH

https://probablymarcus.com/blocks/2026/06/28/native-graphical-shell-for-SSH.html
211•mrcslws•7h ago•96 comments

WATaBoy: JIT-Ing Game Boy Instructions to WASM Beats a Native Interpreter

https://humphri.es/blog/WATaBoy/
163•energeticbark•7h ago•24 comments

Wallace the 6 inch f/2.8 telescope, building it, and hiking with it

https://lucassifoni.info/blog/hiking-with-wallace/
89•chantepierre•3d ago•13 comments

JumpServer: Open-Source Privileged Access Management

https://github.com/jumpserver/jumpserver
44•neitsab•3h ago•11 comments

US Supreme Court rules geofence warrants require constitutional protections

https://www.theguardian.com/us-news/2026/jun/29/supreme-court-geofence-warrants-case-decision
373•cdrnsf•7h ago•174 comments

Micro-Agent: Beat Frontier Models with Collaboration Inside Model API

https://vllm.ai/blog/2026-06-29-micro-agent-frontier-models
40•matt_d•4h ago•11 comments

What happens when you run a CUDA kernel?

https://fergusfinn.com/blog/what-happens-when-you-run-a-gpu-kernel/
190•mezark•9h ago•24 comments

Apple Neural Engine: Architecture, Programming, and Performance

https://arxiv.org/abs/2606.22283
77•Jimmc414•1d ago•9 comments

Working With AI: A concrete example

https://htmx.org/essays/working-with-ai/
61•comma_at•8h ago•23 comments

South Korea to spend $1T on more memory chip production and humanoid robots

https://arstechnica.com/ai/2026/06/south-korea-to-spend-1t-on-more-memory-chip-production-and-hum...
16•jnord•38m ago•0 comments

30-year sentence for transporting zines is a five-alarm fire for free speech

https://theintercept.com/2026/06/26/daniel-sanchez-estrada-zines-prairieland-free-speech/
160•xrd•1d ago•64 comments

Ornith-1.0: Self-scaffolding LLMs for agentic coding

https://deep-reinforce.com/ornith_1_0.html
47•kordlessagain•1d ago•6 comments

European ISPs Want Rightsholders Held Accountable for Overblocking Damage

https://torrentfreak.com/european-isps-want-rightsholders-held-accountable-for-overblocking-damage/
319•Brajeshwar•6h ago•83 comments

Dark Sky Lighting

https://www.savingourstars.org/darkskylighting#whatisdarkskylighting
118•alexandrehtrb•4d ago•16 comments

One million passports leaked online

https://cambridgeanalytica.org/data-breaches-scandals/passports-driver-licenses-exposed-public-in...
81•jruohonen•1d ago•54 comments

Sandia National Labs SA3000 8085 CPU

https://www.cpushack.com/2026/06/03/sandia-national-labs-sa3000-8085-cpu/
151•rbanffy•12h ago•38 comments

You Don't Know Jack About Formal Verification

https://queue.acm.org/detail.cfm?id=3819084
84•eatonphil•8h ago•37 comments

Font-Family Recommendations

https://chrismorgan.info/font-family
41•birdculture•3d ago•12 comments

Venetian Bridge Brawls in 17th and 18th Century Art

https://publicdomainreview.org/collection/venice-bridge-fights/
50•pepys•3d ago•28 comments

Rebuilding the Computer Room

https://alexwlchan.net/2026/computer-room/
87•ingve•11h ago•45 comments

Is sunscreen the new margarine? (2019)

https://www.outsideonline.com/health/wellness/sunscreen-sun-exposure-skin-cancer-science/
57•markgavalda•17h ago•56 comments

Samsung, SK Hynix, Micron Sued in US over Memory Price Fixing

https://en.sedaily.com/international/2026/06/29/samsung-sk-hynix-micron-sued-in-us-over-memory-pr...
322•donohoe•11h ago•156 comments

Halvar's Guide to Entrepreneurship

https://thomasdullien.github.io/guides/entrepreneurship/
191•nekitamo•4d ago•44 comments
Open in hackernews

One million passports leaked online

https://cambridgeanalytica.org/data-breaches-scandals/passports-driver-licenses-exposed-public-internet-2026-51096/
81•jruohonen•1d ago
https://www.theverge.com/tech/947157/passports-data-breach-c...

https://www.schneier.com/blog/archives/2026/06/one-million-p...

Comments

adithyaharish•1d ago
I am sure even my passport would be part of the breach, are the passport holders beign notified of the breach?
dgellow•1d ago
Oh god that’s pretty bad

> The documents were hosted by systems used by cannabis clubs and a company called Nefos, which operates PuffPal, a platform that manages membership and age verification for cannabis retailers and clubs across Europe. The infrastructure storing these identity documents—full passport scans, driver’s licenses with photos, names, and identifying numbers—was left completely unprotected on publicly accessible web servers.

I cannot imagine the level of fines under GDPR for leaking that much PII

real_chudson•1d ago
The EU's verification laws will ensure much more of these leaks in the future, and therefore much more fines
dgellow•1d ago
Yep… not sure about more fines, but for sure more leaks
Kuinox•1d ago
How so, are you purely speculating or you found a hole in the zero knowledge proof system some countries are implementing ?
2748484848•1h ago
He's stating the obvious
forestry•1d ago
Is it requirement to retain the documents? Many are waiting for gatekeeper tech companies to organise around attestation rather than submission to third parties. I hope they are making progress.
TacticalCoder•1h ago
I had to receive a letter from France (I'm not french, I don't live in France, but we've got family real estate there). To be able to open this letter, online (!), I had to scan my EU ID card, tilt it, and scan my face (pointing at the camera, looking to the left, etc.).

We're talking about a major french institution here, either public or private but colluding with the government to have their monopoly (don't know, don't care: they're all the same worms to me).

Speaking of which... There's been a recent case in France where a very nice lady working for some public institution (basically the IRS) was giving the name/wealth of "targets" to her brother so that her brother and his friends could go and kidnap/torture (fingers of victims have been cut) family members of rich french persons.

It's sickening and the real culprits are those creating the laws mandating this full on surveillance apparatus.

dgellow•1d ago
Could we update the link to the original article? https://cambridgeanalytica.org/data-breaches-scandals/passpo...
ericpauley•1d ago
CA article is just AI;dr on a two week old Verge article: https://www.theverge.com/tech/947157/passports-data-breach-c...
dgellow•1d ago
Ok, then changing the link to the verge article. Thanks for pointing that out
wolvoleo•23h ago
The verge is not a good source as it's pay walled
gavinsyancey•1h ago
From the HN FAQ:

> Are paywalls ok?

> It's ok to post stories from sites with paywalls that have workarounds.

> In comments, it's ok to ask how to read an article and to help other users do so. But please don't post complaints about paywalls. Those are off topic. More here.

https://news.ycombinator.com/newsfaq.html

You can pay for the paywall, or there are ways around.

raverbashing•1d ago
That's good, just grab one of those whenever your need to prove your age online /s
Cider9986•1h ago
For liveness i suppose you need a good graphics card.

So dystopian

gertrunde•1d ago
The lack of security is one thing, but why have they retained the information at all!

iirc, one of the elements of GDPR is "storage limitation", i.e. you must not keep personal data for longer than you need it - and in this case, the data is only needed to verify the age of the user, and shouldn't ever be required again (unless people can now get younger).

Once a document has been used to verify a person's identity and that the person is of legal age, there is no reason to retain a copy of the document any more.

It would be reasonable and fair to retain a photo of the user to verify that the person matches the account, but that's it.

rationalist•21h ago
10 years after I took the ACT, I received a letter from a university that I never went to, saying my SSN was leaked.

WHY THE F**k ARE THEY HOLDING ON TO THAT 10 YEARS LATER!?!?!?

Of course now I know better than to give out my SSN to anyone who asks for it, but I didn't know that as a teenager.

Until stupid s**t like this becomes illegal, it will just keep continuing.

robrtsql•1h ago
Don't be so hard on 17-ish-year-old you. What exactly were you supposed to do? Not take the ACT (and probably not get into your desired college)?
DANmode•25m ago
Ask if it’s required, instead of assuming it is, is the point.

Modern equivalent “move over here for your picture ‘for the doctor’.”

No thanks, I’d like to opt-out!

AgentOrange1234•24m ago
joe_mamba•1h ago
Damn, we even got passport leaks before GTA 6.
emayljames•1h ago
This is the best one. Not a shady company website, or a paywalled site:

https://boingboing.net/2026/06/28/a-million-passports-leaked...

tartoran•1h ago
> Note what happened. A high-value credential—a passport—was used in an ancillary low-value authentication system: ID verification for cannabis dispensaries. And it’s the low-value system that got hacked, putting the high-value credential at risk.

Why do these systems hold onto user's data post verification?

observationist•1h ago
Why wouldn't they? There are probbaly significant downsides if they fail an audit requirement, and they're probably mandated to retain records for some period, with no consequences to extended retention.

Set up a system so that it costs you nothing to do a bad thing but possibly wrecks you legally and financially to do the good thing, and people will inevitably do the bad thing. They shouldn't be collecting this information in the first place.

The people who design these policies are incapable of actually building things that work. They are not the intelligent, competent leaders exercising a careful craft that they like to pretend they are.

They keep going after age verification, online ID, central bank digital currencies, etc - keep this incident in mind. The people who implement and write these policies are morons. They don't game things out and plan for redundancy or resiliency. They don't take into account bad faith actors. They don't account for deliberate exploitation of the system.

charles_f•1h ago
> Why wouldn't they?

They most likely weren't allowed to keep it past the verification per GDPR art.5. Once the passport has been verified for whatever purpose they needed it ("age verified to be > 18yo on 2026-06-12" or "identity verified to be XXXX YYYY"), there is no legitimate use for the passport photo and details anymore, and they should delete it.

petercooper•51m ago
(I'm naive in this area, but..) I wonder if the various "proof of age" laws coming into play will clash with the GDPR in insidious ways. Like requiring identity providers to hold definitive "proof" of why they made an assessment rather than merely proving and discarding. I assume/hope there is some cryptographic way to do this rather than hang on to passport and ID images, however.
hhthrowaway1230•1h ago
Is this the CA from FB fame? https://en.wikipedia.org/wiki/Cambridge_Analytica? If so how come they still exist?
charles_f•1h ago
Yeah, I almost closed my tab and burnt my browser realizing that.
re•59m ago
No, it looks like the domain was taken over by squatters after CA went defunct in 2018, and they're currently using it for AI-generated "content".
vfclists•1h ago
Do the laws that mandate identity verification set security standards that the websites which collect and verify the data must meet?
shmoobadge•1h ago
Much as passports are very important for proving identity etc, people who travel have had their passport scanned, photographed or photocopied by pretty much every hotel they've stayed in. I'm not sure the shoebox in the backroom in Koh Samui with the photocopies in constitutes good storage hygiene protocols.

How that doesn't turn into rampant identity theft I don't know, or maybe it does? Not, happily, for me... yet.

Avshalom•1h ago
the whole "not being an automatable remote sql injection away from everything" quality of physical objects grants a filing cabinet a tremendous amount of inherent security compared to anything digital.
Terr_•1h ago
Much like that old quip about the bandwidth of a vehicle full of tapes: "Never underestimate the at-rest security of a room full of filing cabinets."

Friction and delay have always been aspects of security.

annzabelle•38m ago
Not sure if they're still doing this, but as of a few years ago, the IRS was still using literal trucks full of tapes to transport data to backup facilities. Tapes are good for this because they don't degrade as quickly as hard drives, so if you're actually looking to do archival storage that will outlast the cloud provider of the decade, they are surprisingly practical.
DANmode•27m ago
Does tape still burn really easily?

Or has that been fixed?

charles_f•1h ago
> Zero password protection on document storage systems > > No encryption for sensitive identity verification data > > Public URL access with no authentication requirements > > No access logging or monitoring systems in place

Pretty much the bingo of secure storage, even CTF demos make it less obvious. Storing a document that they have no business keeping in the first place, with no security whatsoever.

voakbasda•1h ago
Show me the consequences. I hear there are supposed to be repercussions, but these asshats never seem to pay for their crimes.
wolvoleo•23h ago
Wow it's insane that Cambridge Analytica is still around after the scandals.
dang•1h ago
Ok, let's use that and put the other two in the toptext.
This is a real problem.

I was appalled when renewing my car this year that I now need a Texas by Texas account (https://www.texas.gov/texas-by-texas/), which wants... a social security number because why?!?!

Anyway, yet another data breach incoming.

cute_boi•31m ago
I think every SSN is already leaked and government is doing nothing. I tried to change SSN and they told me it is not possible.
frollogaston•2m ago
I've had stuff like this happen too, and always wondered if they really leaked my data or were just notifying everyone whose data they possibly leaked.
dotancohen•1h ago

  > Once a document has been used to verify a person's identity and that the person is of legal age, there is no reason to retain a copy of the document any more.
Might KYC laws and general CYA policies prefer to keep the proof of age? For instance to protect e.g. against a minor altering the date on their passport. Especially in such a regulated industry.
charles_f•54m ago
The EDPB has explicitly ruled on that, when it comes to age verification^1, you should delete: "Trust models are crucial to prevent data breaches in age assurance contexts [...] once the user's age is verified, no record of the personal data used for the age assurance process is kept".

^1: https://www.edpb.europa.eu/system/files/documents/2025-04/ed..., number 36.

dotancohen•24m ago
Thank you.
lschueller•12m ago
There are established ways / protocols to hold and provide cryptographically valid proof of a verification process, without any need to keep the actual id images in any storage. And to my knowledge there is no requirement for compliant KYC (Know your customer) to provide their ID as a proof as long as the verification process itself is compliant and audited in accordance to certain criteria.

You can compare this in a certain way to file hashes. A successful verification with a predefined minimum level of credibility can be encrypted to a special string for later being used, if a service needs to verify the person again. It doesn't matter then, that the original passport images or video ident has been deleted the second after id verification has been completed.

TZubiri•1h ago
>Why wouldn't they? There are probbaly significant downsides if they fail an audit requirement,

Right, and keeping old passports used for verification should cause an audit to fail.

lazide•44m ago
Not if there is no law about it.

If there is a law about verifying buyers, how else are they going to pass that audit?

TZubiri•1h ago
I have a story about this, although it's a bit convoluted and not entirely related. But it does showcase low-value usecase compromising a high-value auth mechanism.

I was working on a project, client is a Real Estate agency, they use a CRM where they upload houses and it in turn uploads it to various sites like Zillow. We needed a list of their listed houses, so we wanted to use that data source instead of making a CRUD where they have to add houses yet again.

We ask the CRM sales team about APIs, they tell us that there's no accounts for third parties, client accounts have APIs, so we have to ask the client for an API key (or for their account password).

Which makes sense in general I guess, but the data is public in our case, so the CRM sales staff 's idea was that we should ask the client to let us access their account in order to get public data. We proceeded to scrape the houses from a website like Zillow like cavemen.

As it happens, our project was ancilliary low-value. So I don't doubt that the clients of this CRM are vulnerable in a similar way, and the root cause of the issue isn't evident at all, I can see 2:

1- Paradoxically, having an API that always requires an API KEY (as opposed to allowing unauthenticated access for public data) is less secure, as credentials/tokens will be used more often when not necessary.

2- This CRM effectively acted as an aggregator, consuming the APIs to publish to other vendors, but they don't provide an API for other vendors to read data from them. This effectively causes third party vendors to authenticate as the client, which is just incorrect. Credentials should identify a person/group, not a usecase.

mothballed•18m ago
I'm not sure how it works in the EU, but in the US, most states have a "PMP" (prescription monitoring program) that tracks the sale of marijuana in many states (nevermind that its not an actual prescription, but it is a controlled substance) and viewable by your doctor back up to ~12 months or so. Most people don't know this however and think it works like alcohol sales where it's sold after ID verification and then everyone forgets about it. Some states treat marijuana sales like prescription drug dispensing, it has to be reported to a central database including the intimate details of the persons involved. I have no idea if this is the case in Spain, however.
Terr_•19m ago
Compared to what what option, clay tablets of cuneiform? :p

In terms of significant danger, perhaps you're thinking of nitrocellulose movie film that was phased out in the '50s.

nkrisc•59m ago
Stealing a shoebox of photocopied passports from every hotel in the city sounds like way more work and way riskier than downloading an already aggregated trove of digital data.
shmoobadge•50m ago
Ok, how about the google photos archive from the hotel next door with 1000s of pictures of passports taken on the shared unlocked $100 android phone that sits on the front desk? Not millions I grant you, but again, there doesn't seem to be an issue with active exploitation of these.
mothballed•12m ago
There is an issue with active exploitation of passports, of course the scale can change. Due to banking KYC / other KYC laws there's a market for these copied identities and of course so criminals don't even get a speedbump by KYC whereas the boot is used up the ass of the normal person trying to pass KYC when they're missing some stupid document like proof of address.
annzabelle•45m ago
My guess is that the machine readable chip standards and the production quality required to replicate a physical passport are high enough that only the most organized of organized crime can fake the highest value passports effectively, and if a passport is easy to replicate, it is less likely to have visa free access to most countries.

To second the photographed/photocopied requirements, as an expat, I am frequently asked to send a scan of my passport to people or entities that are not necessarily the most secure.

I also have a couple of important documents that are literally PDFs. My Canadian citizenship certificate is a PDF with a barcode in it, that I can print off a copy of if I need to mail it, or show on my phone to a consular office or a border guard if needed. My work visa here in New Zealand is a PDF with my passport number and a visa number, which my workplace and bank checked with an online database. Fundamentally, these and my passport are pointers to a row in various databases.