frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Advancing the price-performance frontier with GPT‑5.6

https://openai.com/index/advancing-the-price-performance-frontier-with-gpt-5-6/
172•tedsanders•1h ago•90 comments

Read This Before You Buy That TV Streaming Stick

https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
109•speckx•1h ago•39 comments

Gemini Robotics 2 brings whole body intelligence to robots

https://deepmind.google/blog/gemini-robotics-2-brings-whole-body-intelligence-to-robots/
258•ai2027•3h ago•259 comments

Physicists Solve a Muon Mystery. Now, Old Results Don't Add Up

https://www.quantamagazine.org/physicists-solve-a-muon-mystery-now-old-results-dont-add-up-20260729/
89•ibobev•2h ago•39 comments

We Gave GPT 5.6 Sol a Real Business. It Lied, Spammed, and Lost $447

https://www.bottlenecklabs.com/blog/autonomously-run-businesses
53•Areibman•45m ago•26 comments

Stacked PRs are now live on GitHub

https://github.blog/changelog/2026-07-30-stacked-pull-requests-are-now-in-public-preview/
61•tomzorz•1h ago•16 comments

The Economic Benefit of Refactoring

https://martinfowler.com/articles/exploring-gen-ai/refactoring-economic-benefit.html
112•javaeeeee•3h ago•48 comments

Why is everyone trying to build a solid-state battery?

https://www.construction-physics.com/p/why-is-everyone-trying-to-build-a
119•crescit_eundo•5h ago•147 comments

Rise Reforming (YC S26) Is Hiring

https://www.ycombinator.com/companies/rise-reforming/jobs/wJ9Q9nv-senior-chemical-process-engineer
1•george_rose25•1h ago

Hacker Public Radio

https://hackerpublicradio.org/
82•bmacho•3h ago•12 comments

Toot.community is shutting down

https://social.jorijn.com/@jorijn/statuses/01KYN00AP3NCZXCFB96KQB8GN2
30•speckx•1h ago•33 comments

Upper stage impacting the moon on 2026 August 5

https://www.projectpluto.com/25010d.htm
99•ryannevius•4h ago•31 comments

How Olinia Turns Mexico's EV Ambition into Reality

https://spectrum.ieee.org/mexico-olinia-car-electric-vehicle
17•rbanffy•1h ago•6 comments

RFC 8890 – The Internet is for End Users (2020)

https://mnot.net/blog/2020/for_the_users
89•notarobot123•5h ago•25 comments

How to Mount a Balcony Awning (2025)

https://solar.lowtechmagazine.com/2025/07/how-to-mount-a-balcony-awning/
24•karakoram•5d ago•0 comments

Launch HN: Prized (YC S26) – Let non-engineer staff build secure internal tools

https://prized.dev
51•marinoseliades•4h ago•30 comments

Ron Gilbert started production on Thimbleweed Park 2

https://www.grumpygamer.com/twp2_announce/
200•alberto-m•10h ago•95 comments

SDL_GPU minimal, single-header, high-performance 2D graphics painting library

https://github.com/n67094/sdl_gp
42•n67094•3h ago•13 comments

Are We Stuck with Lean?

https://mathoverflow.net/questions/513742/are-we-stuck-with-lean
93•jjgreen•6h ago•41 comments

Paging Through a Parquet File in DuckDB: File_row_number or Offset?

https://rusty.today/blog/paging-parquet-duckdb-file-row-number-vs-offset/
30•rustyconover•3h ago•3 comments

RCade: The Arcade Cabinet with CI/CD Deployment, Custom Graphics Card for CRT [video]

https://www.youtube.com/watch?v=W-OpIbLUOU0
20•evakhoury•21h ago•3 comments

Show HN: Claude-account – switch Claude Code accounts without logging in again

https://github.com/hamzarehmandeveloper/claude-account
22•hamza_rehman•3h ago•18 comments

How old is Ann?

https://quuxplusone.github.io/blog/2026/07/29/how-old-is-ann/
51•ibobev•6h ago•51 comments

Trusted URLs via Cryptographic Signatures

https://blog.certisfy.com/2026/04/trusted-urls-via-cryptographic.html
18•Edmond•3h ago•12 comments

3D Pinball for Windows (1995)

https://98.js.org/programs/pinball/space-cadet.html
77•mushstory•6h ago•39 comments

Gpiozero Flow

https://bennuttall.com/blog/2026/07/gpiozero-flow/
111•benn_88•7h ago•34 comments

Show HN: I made a game where you build a CPU from logic gates

https://select.supply/game/chipbuilder
58•laurentiurad•6h ago•53 comments

Building a native C# implementation of CEL engine

https://bsid.io/writing/building-a-cel-engine-for-net
38•jackedEngineer•2d ago•8 comments

The Alice and Bob After Dinner Speech (1984)

https://hex.ooo/library/alicebob.html
41•kamma4434•3d ago•6 comments

Azulejo

https://en.wikipedia.org/wiki/Azulejo
157•Amorymeltzer•1d ago•53 comments
Open in hackernews

Read This Before You Buy That TV Streaming Stick

https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
109•speckx•1h ago

Comments

mortenjorck•51m ago
In this case it’s actual malice, that the streaming stick is set up for residential proxy and ad fraud straight from the factory. But incompetence can lead to the same place if it’s a poorly engineered, un-maintained device with an old version of Android that will never be patched and is always one no-click exploit away from being commandeered into residential proxy and ad fraud.
alex_duf•36m ago
I wonder to what degree malice can be engineered to look like incompetence?
abbeyj•25m ago
Try examining the old entries from the https://en.wikipedia.org/wiki/Underhanded_C_Contest.
FinnKuhn•33m ago
Those TV streaming boxes really are (from a cybersecurity perspective) probably one of the worst things you can buy. Here is the "Darknet Diaries" Episode on them: https://darknetdiaries.com/episode/172/
glitchc•51m ago
Defrauding ad networks doesn't seem like a bad thing, although using my internet connection as a proxy is obviously terrible. It wouldn't surprise me to learn that my connection is being sold as a VPN service by the vendor.
skinfaxi•49m ago
Thankfully this seems limited to a specific device (H96). Darknet diaries has a good story about streaming devices https://www.youtube.com/watch?v=dS6PkuZuxJ4
krebsonsecurity•43m ago
It's not just one device line; Have a look at the list maintained by the proxy tracking service Synthient, which tracks streaming boxes, digital picture frames and other IoT devices that have been known to bundle residential proxy software, among other malicious apps. They currently track almost 1,000 different makes and model numbers.

https://github.com/synthient/public-research/blob/main/2026/...

pavel_lishin•49m ago
> generic TV boxes that promise unlimited content streaming for a one-time fee

I don't want to blame the purchasers of these things - who are some of the victims - but at the same time, it does seem like a Too Good To Be True situation.

croes•43m ago
It sounds like scam
havaloc•40m ago
I have an elderly client who sends me links of stuff to buy all the time. One day it's one of these streaming sticks, the next day it's half-price stamps, and I tell her every time, please don't buy this stuff. And yet she does anyway, as if I was almost being mean and saying no just to say no.

So yes, I do want to blame the purchasers of these things, sometimes. To prove her point that her stamps were legitimate, she mailed me a card using one of her half priced (but likely fake) stamps and it made it through!

nvme0n1p1•39m ago
OTOH - TV, radio, and YouTube are all unlimited and free. Why not streaming?

There are lots of people alive who grew up during the days of broadcast TV and radio. I get why they might not understand the difference.

fred_is_fred•39m ago
If you offered most people free streaming for a $37 USB stick but directly told them it would be faking ad clicks when the TV is off, would any of them really care?
giraffe_lady•45m ago
> allowing low-skilled operators to drag blocks of code together in their editor — without any need to understand what the underlying code blocks do or how they work.

We're called engineers brian.

cryo32•42m ago
A better solution is just leech the content and stick it on a generic USB flash stick.
j45•35m ago
Generally, it's advisable to create a dedicated wifi network for all potentially hostile devices.

This dedicated wifi network can just be connecting your devices to your guest wifi while you figure it out, and limiting the rate of speed as needed.

That can be cameras, tv's, thermostats, tv sticks and anything else that might not only call home, but actively scope what you have in your home network when it's none of it's business.

giantg2•33m ago
So where can I get an actual privacy focused streaming box, even if the apps (Neflix etc) running on it are not?
cogman10•30m ago
I'm increasingly being convinced the only way to do that is you do a media pc nuc. The problem, of course, is you probably won't have the netflix app. It's painful to setup such a box to stream from various services.
mbmbn•26m ago
I tried going that route, but most apps for streaming are Android. And that was only one of the issues.

It was a rabbit hole and in the end I got back using my NVIDIA Shield. This is about 10 years now, but it’s actually still the best option.

MattTheRealOne•29m ago
Apple TV is currently the best balance of privacy and convenience. The only way to get more private is using a PC, but that limits the resolution for most streaming services to 720p or 1080p.
PcChip•28m ago
I assume apple TV doesn’t do malicious things like this, and we love the interface and it “just works” with HDR
m3047•30m ago
Brazil. Last year I effectively blocked Brazil for a while. Ultimately I settled on three possibilities for the traffic I was seeing:

01: DDOS

10: Residential proxies

11: Somebody DDOSing residential proxies

drdexebtjl•21m ago
I can’t prove it, but I live in Brazil and after getting a smart TV from LG, I started receiving challenges across all Google services, indicating they received bot traffic from my network. I only used apps from streaming services I actually paid for.

I suspect these TVs either come with residential proxies set up from the factory, or they have such poor security that they’re instantly hacked. Either way, TV manufacturers (including reputable ones like LG) are to blame.

codedokode•25m ago
I do not see problems with fake ad clicks and have no sympathy for ad companies.

Also pre-installed adware is not a surprise, I found adware in the official firmware image of a certain Chinese tablet.

What worries me much more is backdoors from the foreign companies and governments that can be pre-installed at the factory to collect intelligence information. For example, I became aware that a certain maker of a popular mobile OS was collecting the cell tower IDs and WiFi access point identifiers along with GPS coordinates of a device. Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed (GPS is very low power and easy to jam). This is not acceptable.

How can we prevent this? I think, for every imported device having a CPU and Internet connectivity:

- the user must be able to re-flash firmware with their own code.

- the local government must have access to the full source code and be able to search for vulnerabilities or backdoors, including using AI tools. Found vulnerabilities are considered a reward and may be used against countries not doing inspections. No access - no import permission.

- any telemetry or data collection, or updates must be opt-in only and disabled by default.

- any telemetry or updates must go through a server controlled by the local government, in unencrypted form, to detect attempts to collect intelligence information or install malicious update.

Sadly our government instead only demands that manufacturers pre-install their closed-source software on all imported devices and that's all.

BoppreH•14m ago
> a certain maker of a popular mobile OS was collecting the cell tower IDs and WiFi access point identifiers along with GPS coordinates of a device. Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed

Is this sarcasm? GPS can take several minutes to get a location, and works poorly indoors. One of the reasons why Google Maps is so quick and precise is because Google has gathered exactly this data through users and Street View drive-bys.

Could it be used for missiles? Sure. Is it obviously the intention? No.

pavel_lishin•
Mistletoe•10m ago
I recently got an Apple TV 4K and have been really enjoying the ad free experience. Worth every penny. Our smart tv had turned into a Christmas tree of ads.
AlotOfReading•4m ago
Of all the evils normally associated with visual programming languages, enabling cybercrime isn't one I've previously considered. Now that I've seen it, I'm surprised it wasn't more common before LLMs appeared.
1970-01-01
•
35m ago
No, and that's is the root of the problem. The buyer is happy and so is the seller. They don't care to understand what they're allowing and everyone is allowing it to happen.
GolfPopper•7m ago
They're just meeting the standards American society has set.
flerchin•36m ago
Well now I want one
Cider9986•18m ago
Stremio+TorBox are the two words. ($3/month)
iugtmkbdfil834•30m ago
Uhh, I have an extended family member, who not only uses it, but now also tries to get other people to get into it. Since I was familiar with this practice ( and the issues it makes worse ), I noted those to him in an attempt to both politely decline and, hopefully, spare him, and society, some future problems. Without going into any identifying details, he didn't take it well ( and I don't think I got on my high horse ).

Anyway, I think some level of blame is warranted.

Cider9986•19m ago
It could be possible, I haven't done the math though.

Stremio +Torbox is $3/month and they can probably share 10+ households on one TorBox account so it could work out. The seller could just stop paying the TorBox subscription at whatever point and they have an incentive to do so.

IncreasePosts•3m ago
Maybe, but if they're a not-very-tech savvy older person buying this, they probably remember shows being free from over the air antennas and may think it is something like that.
7m ago
> Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed

Are there a lot of missiles that travel slowly enough to be able to guide themselves via watching for nearby wifi signals?

> for every imported device having a CPU and Internet connectivity

Why limit this to imported devices?

palmotea•2m ago
>> Obviously they collect this information to be able to guide missiles and drones when GPS signal is jammed

> Are there a lot of missiles that travel slowly enough to be able to guide themselves via watching for nearby wifi signals?

Cheap, slow-moving drones are the hot new missiles on the battlefield of today.

IncreasePosts•5m ago
Fake ad clicks cost the advertiser money, not the ad company.

Ad companies generally try to detect fake clicks, but any fake clicks that get through just earn money for the ad company (at the cost of making the advertisers campaign have a lower ROI)

mcphage•3m ago
> Fake ad clicks cost the advertiser money, not the ad company.

It also diminishes the value of the clicks provided by the ad company. It doesn't cost them dollars directly, but makes all their advertising worth less.

Thrymr•5m ago
> I do not see problems with fake ad clicks and have no sympathy for ad companies.

I am not shedding any tears for the ad companies, but I don't exactly expect or want a consumer device to be doing this in the background without the owner's knowledge.

mcphage•4m ago
> I do not see problems with fake ad clicks and have no sympathy for ad companies.

Yeah, it's like—a cheap streaming stick AND it poisons the advertising well? I'm pretty happy with my Fire TV Stick, but they're really tempting me here.