frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Claude Opus 5

https://www.anthropic.com/claude-opus-5-system-card
423•alvis•1h ago•219 comments

My security camera shipped a GitHub admin token in its login page

https://hhh.hn/hanwha-github-token/
357•hhh•6h ago•137 comments

India's first privately-developed rocket reaches orbit on dramatic debut launch

https://arstechnica.com/space/2026/07/indias-first-privately-developed-rocket-reaches-orbit-on-dr...
318•sohkamyung•4d ago•84 comments

Micro-SaaS Is Dead. Service With A Software Replaces It

https://adriengonin.com/writing/service-with-a-software/
34•Adrig•1h ago•32 comments

The rise and fall of language diversity through the Holocene

https://www.science.org/doi/10.1126/science.adx4343
26•delichon•1h ago•2 comments

Half-Life 2 running natively on HaikuOS

https://discuss.haiku-os.org/t/haiku-nvidia-porting-nvidia-driver-for-turing-gpus/16520?page=18
154•m0do1•5h ago•17 comments

As of JDK 27, Oracle engineers will thus stop maintaining the macOS/x64 port

https://openjdk.org/jeps/541
62•pmg1991•1h ago•57 comments

Be skeptical of OpenAI's rogue hacker agent story

https://www.theguardian.com/technology/2026/jul/24/openai-rogue-hacker
106•rwmj•1h ago•35 comments

The front end framework for correctness: built on Effect, architected like Elm

https://foldkit.dev/
43•plucafs•2h ago•22 comments

Proving a Human Wrote Something

https://gjtorikian.online/posts/proving-a-human-wrote-something/
16•gjtorikian•1h ago•20 comments

Flux 3 X Mimic: The Next Generation of Video-Action Models

https://bfl.ai/blog/flux-3-mimic
280•kensai•8h ago•45 comments

It's getting harder to focus every day

https://glyphack.com/attention/
566•peykar•9h ago•323 comments

Apple won't let me show my app

https://wisedayplanner.com/blog/apple-wont-let-me-show-my-app/
22•codersfocus•1h ago•17 comments

Extending Polars with Rust Expression Plugins

https://fenic.ai/blog/extending-polars-with-rust-expression-plugins
7•cpard•2d ago•0 comments

Making Xen's dom0 I/O path NUMA aware

https://edera.dev/stories/numa-part-4-closing-the-xen-dom0-i-o-gap
19•virtio_vixen•2d ago•1 comments

Online Historical Encyclopaedia of Programming Languages

https://hopl.info/
12•gregsadetsky•1h ago•1 comments

Unitree As2-W

https://www.unitree.com/As2-W/
24•MehrdadKhnzd•1h ago•8 comments

Claude Opus 5

https://www.anthropic.com/news/claude-opus-5
66•meetpateltech•1h ago•7 comments

Government orders GitHub to remove Bluetooth-based chat app Bitchat: Jack Dorsey

https://www.thehindu.com/news/national/government-orders-github-to-remove-bluetooth-based-chat-ap...
227•rootkea•3h ago•133 comments

Flux 3

https://bfl.ai/blog/flux-3
510•ThouYS•11h ago•121 comments

Em dashes are fucking amazing

https://psychotechnology.substack.com/p/em-dashes-are-fucking-amazing
256•surprisetalk•5h ago•231 comments

WebGPU Unleashed: A Practical Tutorial

https://shi-yan.github.io/webgpuunleashed/
27•ibobev•3h ago•1 comments

Plants vs. Zombies for PlayStation 2

https://github.com/OptiJuegos/pvz-ps2
40•Jotalea•4h ago•4 comments

My Emacs Configuration (Dired)

https://eugene-andrienko.com/2026-07-05-my-emacs-configuration-dired.html
28•meysamazad•4h ago•6 comments

3GPP Version 19

https://www.3gpp.org/specifications-technologies/releases/release-19
36•mlhpdx•3h ago•9 comments

DuckPGQ – A DuckDB community extension for graph workloads

https://duckpgq.org/
4•rzk•58m ago•0 comments

Co-Opting Linux Processes for High-Performance Network Simulation (2022)

https://www.usenix.org/conference/atc22/presentation/jansen
17•teleforce•3h ago•0 comments

Claude Cookbook

https://platform.claude.com/cookbook/
268•saikatsg•12h ago•133 comments

Writing a Debugger from Scratch

https://www.timdbg.com/posts/writing-a-debugger-from-scratch-part-1/
31•ibobev•3h ago•5 comments

Buz – A fork of Bun using modern Zig, with sub-1s incremental builds

https://ziggit.dev/t/buz-a-drop-in-replacement-for-bun-using-modern-zig-with-sub-1s-incremental-b...
195•kristoff_it•8h ago•140 comments
Open in hackernews

Be skeptical of OpenAI's rogue hacker agent story

https://www.theguardian.com/technology/2026/jul/24/openai-rogue-hacker
103•rwmj•1h ago

Comments

Zsfe510asG•1h ago
Finally mainstream news understands. The unfiltered version:

1) The AI failed to solve ExploitGym problems.

2) The OpenAI sandbox is such a horrible hack that the AI managed to escape using standard and well documented script kiddie methods.

3) Huggingface has no security and the AI broke in using standard script kiddie methods.

OpenAI and Huggingface covered it up and used it for public relations. That is, if not all was invented and everything was scripted in the first place in order to get desired regulations.

Huggingface reported it to the police, you say? I'm sure the police will have as much enthusiasm to investigate anything as in the Suchir Balaji case. In other words, zero.

gruez•50m ago
>2) The OpenAI sandbox is such a horrible hack that the AI managed to escape using standard and well documented script kiddie methods.

>3) Huggingface has no security and the AI broke in using standard script kiddie methods.

Isn't the issue less that gpt 5.6 is a l33t h4x0r (though other tests do show that) and more that the incident shows the model has alignment issues?

wonnage•43m ago
Didn’t they explicitly remove alignment guardrails for this test? From the press release:

> These deployment safeguards were intentionally not enabled during this evaluation because it was aimed at testing cyber vulnerabilities

numeri•38m ago
Guardrails are external classifiers, monitors and restrictions to catch and prevent bad behavior. Alignment is about whether the model itself makes choices and has motivations that are consistent with human safety and goals.

Choosing to commit crimes to steal the cheat sheet to something you know is a (low stakes!) evaluation is not well aligned.

vector_spaces•9m ago
None of what was disclosed shows that this is what happened, by the way, since we know absolutely nothing about what the specific prompts were that led to the incident.
jgalt212•46m ago
truth. Good on The Guardian. I'm pretty bummed The Economist got fooled. Either that, or they did it for the clicks. Either way, I'm disappointed.

Why the OpenAI escape is the most worrying AI mishap yet

https://www.economist.com/science-and-technology/2026/07/22/...

https://news.ycombinator.com/item?id=49016378

notahacker•33m ago
> 2) The OpenAI sandbox is such a horrible hack that the AI managed to escape using standard and well documented script kiddie methods.

Whilst it would be nice to see actual evidence of this because brute forcing relatively sophisticated hacks is something an LLM actually should be capable of, every time I hear this soft of story, I'm reminded that humans reportedly gained access to the "too dangerous to release" Anthropic models by the super sophisticated hacking technique of guessing the URLs...

chis•31m ago
> AI managed to escape using standard and well documented script kiddie methods.

I think truly we don't know enough to say this. OpenAI says their AI found a 0-day exploit in some proxy software they were using but don't give a ton of details. On the Huggingface end we know a little more, they say the AI spun up tons of sandboxes and tested different exploits until it found one that worked.

inigyou•22m ago
Why not report it? It's still illegal to open a door barred with a piece of cardboard, or to enter a house with no door.
john_strinlai•1h ago
does the article end at "How do we balance the risks of broad access to AI with the risks of concentrated power and centralized control?" or is there more that is paywalled?

if thats it, the whole article boils down to just "its good marketing so maybe dont believe it" which is probably a healthy general outlook but not particularly enlightening. especially from the guardian, i was hoping for a smoking gun of collusion between openai and huggingface or something.

wffurr•44m ago
I wish the NPR news broadcasters on the radio yesterday had read the "it's good marketing so maybe don't believe it" angle instead of just parroting the OpenAI press release. Getting that message out would be enormously helpful in countering the blatant submarine marketing "Oh no our AI is a super hacker" with a side of "please regulate super hacker AI and stop those pesky open weights Chinese models that are destroying our stock valuation."
john_strinlai•18m ago
maybe all the news agencies could put out daily “don’t believe everything you read from company press releases” broadcasts, because it sure ain’t specific to openai

in any case, this is just a longer rehashing of elementary grade media literacy. not really sure why it hit hacker news.

vector_spaces•14m ago
You aren't going to locate incontrovertible evidence that what happened as or wasn't engineered. Anything like that is going to be private and that is unlikely to change. And that's not really an interesting question anyway.

As widely as they shouted from the rafters the news of the so-called breach was, what OpenAI provided was sorely lacking in crucial details.

We are missing, for instance, prompts that were involved, agent architecture + system/tool permissions + scaffold architecture, whether this was a one-shot occurrence and if not, the number + durations + outcomes of other runs involved + how each of those matched whatever scoring criteria were used, and the extent to which the exploits themselves were truly novel or just assembled from easily accessible clues.

In lieu of these items, the author here suggests that we use some media literacy and critical thinking to read in between the lines instead.

In doing so, one sees that instead of specifics, OpenAI gave a breathless narrative rife with superlatives ("unprecedented") that reads as promotional material moreso than a security disclosure, naming specific OpenAI models and alluding to an even more capable pre-release model.

They go on to claim the events imply long-horizon goals work decisively in real world conditions, so that now instead of merely citing boring benchmarks they can point to this and say "AI broke out of the laboratory and went rogue". Naturally, they situate themselves as the uniquely qualified steward for these supremely powerful and dangerous models.

Nevermind the fact that this was no ordinary deployment and the assessment here depends on the gimmick and emotional weight of the spectacle rather than something quantifiable (i.e. a boring benchmark).

Note there's no real requirement of conspiracy or collusion between OpenAI and HuggingFace here BTW. But my sense is that if they provided any of the specifics I suggested earlier that this outcome would not be as exciting or frightening

SpicyLemonZest•1h ago
> I urge readers to think critically when they read press releases like OpenAI’s rogue agent story, and avoid the manipulated reactions these stories are designed to elicit.

It seems to me that deducing what reaction the author intended and resolving to avoid it so you're not "manipulated" is not a good example of critical thinking. Shouldn't we analyze the story and what it means on its own terms? If it's true that frontier models have dangerous cybersecurity capabilities which shouldn't be widely distributed, presumably we want to believe it's true, even if that's very convenient to and profitable for OpenAI.

It's true that one could imagine factors that change the story. Perhaps OpenAI is lying about the details of the test and the agent was actually instructed to go hack HuggingFace. But the author stops far short of suggesting this is the case - correctly, I think, since there's absolutely no evidence of it. So I'm not really sure what we're talking about.

paxys•1h ago
Not sure what they are trying to say exactly. What should we be skeptical of? Did the incident not happen? Was it reported incorrectly? Are any of the parties involved lying?

Adding no extra information and just going “be skeptical” is the laziest form of reporting and commentary. If you have nothing to contribute then there’s no need to say anything at all.

krupan•53m ago
Crazy that we need reminders not to take everything we read in corporate press releases and marketing material at face value
jgalt212•50m ago
There's trillions of dollars at stake here. Be skeptical of anything these AI hypesters say.
brcmthrowaway•37m ago
Yep, theres too much money.. I don't know how to tune it out

LLMs seem to be getting more useful though

pupppet•49m ago
With all of these AI provider cries wolf stories, Skynet is all but assured.
bluGill•46m ago
I don't care how it happened someone should be arrested for illegal intrusion. Agents don't work on their own, someone is responsible. If nobody else the CEO for allowing something unsupervised.

Hugging face also needs someone arrested for not providing security but that is a lesser charge.

hexxt-git•42m ago
even hugging face doesn't care and are using this as a promotion why are you crying about it
numeri•37m ago
As agents become more and more powerful, it would be good to get clear legislation or precedent in place that makes either model creators (OpenAI) or operators (whoever is running the model) liable for their agents' actions.
luka598•32m ago
I kind of agree with them, in this case both parties essentially settled it between for PR reasons, but what if the attacked party actually was damaged. This is as if two friends got into a car accident and decided to not get police involved, the one who caused the accident should definitely get punished either way. Goal is to prevent future "accidents" with the punishment not to punish for punishing sake.
tokioyoyo•9m ago
What? Both sides are cool with it, why would anyone be arrested and etc.?
visiondude•39m ago
yeah the way the agent “escaped” their sandbox was always a bit off, seemed a bit too easy and surprised they didn’t have instrumentation to catch an non whitelisted network request. still demonstrates the capability though.
dumberquestions•20m ago
There are some reasons the story could be inaccurate in some ways: OAI stands to benefit if people think their models are strong, and they have a history of doing things with dubious ethics (e.g. using data for training against the terms of its creators, abandoning the non profit mission, stealing or attempting to steal Apple IP).

But there are also reasons why the story could be true: OAI are admitting that they apparently can't control their own models, Hugging Face said they used a Chinese model to protect against the attack, and an incident like this in general seems likely to happen given current frontier ability and lack of rigorous safe testing standards.

In any case, make calls to think more critically are often just disguised requests for you to replace your existing bias with someone else's.

ben_w•19m ago
As I understand it, there are only three options:

1) OpenAI and HuggingFace are both telling the truth.

IIRC not actually a crime because no intent, it is a technological accident, civil responsibility only, but IANAL so it's good "not technically a crime" isn't load-bearing.

2) HuggingFace is telling the truth but OpenAI is lying becuase the attack was deliberately done by humans. Bad for OpenAI to do so, Fable was blocked for less.

I think this would mean government is obliged to investigate the case and put the responsible OpenAI workers in jail, because cybercrimes are a public prosecution thing not a civil case? Again, IANAL, but this isn't load-bearing.

3) both are lying, e.g. there actually was no attack whatsoever, which would be pretty weird for HuggingFace because they have no incentive to hype up capabilities of anything closed weights including all OpenAI models; and also bad for OpenAI because White House blocked Fable for less

(I suppose there's also option 4, HuggingFace hacked OpenAI to make them look evil, including planting records that made them mea culpa? A weird plot but in this timeline any nonsense is clearly possible).

pastemato•8m ago
It was quite galling to read the press initially verbatim quoting Delangue's enthusiastic reports of the incident, as if it wasn't immediately clear it was being spun for promotion.
john_strinlai•11m ago
right. and all that is fine. im just not exactly sure why the basics of media literacy are worthwhile on the site that “optimizes for curiosity”.

i saw the domain and thought it was going to be some cool investigative journalism about the incident rather than “be skeptical. the end.”