frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Google's Beyond Zero: Enterprise Security for the AI Era

https://spawn-queue.acm.org/doi/10.1145/3819083
16•jordigg•1h ago

Comments

urup2l8•47m ago
Oh yeah, a company whose business model is taking everyone’s data and selling it is going to help me secure my data. I guess there’s one born every minute…
stingraycharles•44m ago
Where do you see them offering this service to you? They’re just publishing what they developed internally, which is what they often do.

Now, Cloudflare, on the other hand, would be much more likely to offer a service like this.

exitheone•32m ago
This trope is so tiring.

There is a massive difference between Google for enterprise customers and Google for consumers.

The consumer offering is massively subsidized by ads and will use your data for ad placement, although they still never sell your data because that would hurt their business.

The Enterprise offering guarantees you contractually that they never touch your data.

firasd•28m ago
Honestly I think non-malicious odd behavior is under-weighted when it comes to AI agents. Even the example in this paper is about someone suspiciously accessing sales data when "why did you do that" often comes down to something in the model's training that fired as a reflex

I wrote about this a few days ago https://firasd.substack.com/p/accidental-data-loss-in-claude...

"Many researchers have made demos along these lines:

An agent is asked to check a webpage like example.com

The webpage asks for a name to proceed further

The agent calls example.com/evil?myname=John, thus sending the user’s name from the context window to the external server.

In practice, however, these elaborate ‘confused deputy’ exfiltration attacks seem rare compared to widely-reported data loss incidents.

The risk of undermining the user’s interests through clumsiness deserves at least as much scrutiny as the risk of leaking secrets."

oscarcp•28m ago
Am I undertanding this correctly? The idea is to have ultimately an AI decide if I can have access to a resource based on dynamic inference, identity , intent and service signals that can easily be manipulated?

Unless I gravely misunderstood the text, this seems like a terrible idea (fancy non-scifi, but still terrible)

oscarcp•14m ago
Just to make my point: can I really trust humans to keep up with the required identity data that will give me enough "credibility" so the AI will give me access?

Let's say I had a promotion, who changes my title in the system, who changes my responsibilities and my place in the org chart, more importantly, will they do it or is <HR_NAME_HERE> on leave and forgot? those are data points required by the agent to determine if I'm "good enough" to access a certain resource.

What if... someone spoofed my address and did a flood in one of the resources that are lateral to what I'm allowed to access (let's say I don't have access to company sales but I do to department sales and the attacker floods company sales with requests under my address), would the AI determine that I'm a high-threat actor and not allow me to access legitimate files going forward?

Will exceptions be made by humans? In which case we go back to human-managed permissions.

Sorry, I might be barking up the wrong tree but I think these are questions that are not meant to be solved during implementation. And they add to what @firasd said about legitimate-but-odd behaviour

7.1 Earthquake in Japan

https://www.data.jma.go.jp/multi/quake/quake_detail.html?eventID=20260728163528&lang=en
287•krembo•3h ago•63 comments

About the security content of macOS Tahoe 26.6

https://support.apple.com/en-us/128067
65•andor•1h ago•24 comments

Our position on open-weights models

https://www.anthropic.com/news/position-open-weights-models
958•surprisetalk•13h ago•1388 comments

Google's Beyond Zero: Enterprise Security for the AI Era

https://spawn-queue.acm.org/doi/10.1145/3819083
16•jordigg•1h ago•6 comments

A $500 RL fine-tune of a 9B open model beat frontier models on catalog review

https://fermisense.com/when-machines-take-the-wheel/
218•ilreb•9h ago•63 comments

How to Survive Boiling Water

https://taxa.substack.com/p/how-to-survive-boiling-water
52•cainxinth•3d ago•8 comments

Ars Astronomica – English translations of rare Hebrew and Latin astronomy texts

https://arsastronomica.com/
73•sweisman•6h ago•10 comments

Benchmarking Opus 5 on SlopCodeBench

https://github.com/humanlayer/advanced-context-engineering-for-coding-agents/blob/main/benchmarki...
313•dhorthy•13h ago•71 comments

Vehicle Motion Cues

https://support.apple.com/guide/iphone/iphone-comfortably-riding-a-vehicle-iph55564cb22/ios
133•Austin_Conlon•10h ago•62 comments

Neutrino-1 8B

https://www.fermionresearch.com/models/neutrino-8b/
96•handfuloflight•6h ago•35 comments

Golang Maps: how Swiss Tables replaced the old bucket design

https://blog.gaborkoos.com/posts/2026-07-24-Golang-Maps-How-Swiss-Tables-Replaced-the-Old-Bucket-...
11•Terretta•3d ago•0 comments

PyTorch: A Reference Language

https://docs.pytorch.org/devlogs/compiler/2026-07-25-pytorch-a-reference-language/
41•matt_d•6h ago•3 comments

Watching Go's new garbage collector move through the heap

https://theconsensus.dev/p/2026/07/19/observing-gos-garbage-collector-old-and-new.html
237•matheusmoreira•3d ago•29 comments

TWC Classics

https://twcclassics.com/
14•stefanpie•5d ago•1 comments

Programming Languages Are Authoring Tools for Platforms

https://www.makonea.com/en-US/blog/programming-languages-are-authoring-tools-for-platforms
23•jdw64•3d ago•5 comments

Kimi K3 Now Available via Telnyx Inference API

https://telnyx.com/release-notes/kimi-k3-telnyx-inference
94•fionaattelnyx•12h ago•48 comments

DConf 2026 in London

https://dconf.org/2026/index.html
102•teleforce•12h ago•43 comments

Show HN: Yap – OSS on-device voice dictation for macOS with no model to download

https://github.com/FrigadeHQ/yap
76•pancomplex•17h ago•27 comments

Launch HN: Rise Reforming (YC S26) – Turning Waste Gases into Valuable Chemicals

https://www.rise-reforming.com
73•george_rose25•15h ago•31 comments

C/C++ projects packaged for Zig

https://github.com/allyourcodebase
65•jcbhmr•12h ago•35 comments

Ray tracing massive amounts of animated geometry using tetrahedral cages

https://gpuopen.com/learn/ray-tracing-massive-amounts-animated-geometry/
113•LorenDB•4d ago•14 comments

RTX 2080 Ti Memory Upgrade to 22 GB

https://gpusolutions.net/rbservices/graphics-card-upgrade/
119•wslh•3d ago•87 comments

Paged Out #9 [pdf]

https://pagedout.institute/download/PagedOut_009.pdf
250•laurensr•21h ago•29 comments

Self-contained highly-portable Python distributions

https://gregoryszorc.com/docs/python-build-standalone/main/
151•jcbhmr•16h ago•32 comments

Some combinatorial applications of spacefilling curves

https://www2.isye.gatech.edu/~jjb/research/mow/mow.html
58•shraiwi•2d ago•8 comments

Securing Services with Rootless Containers

https://blog.coderspirit.xyz/blog/2026/07/06/securing-services-with-rootless-containers/
103•speckx•4d ago•32 comments

A Dying Art: The last of the morticians

https://harpers.org/archive/2026/08/a-dying-art-john-semley-mortuary-sciences-competition/
39•Petiver•4d ago•4 comments

Don't ask an LLM for a confidence score

https://justinflick.com/2026/07/27/llm-confidence-scores.html
40•pamplemeese•11h ago•3 comments

How real are real numbers? (2004)

https://arxiv.org/abs/math/0411418
84•surprisetalk•19h ago•63 comments

EYG: A Programming Language for Humans

https://crowdhailer.me/2026-06-08/a-programming-language-for-humans/
72•crowdhailer•9h ago•45 comments