frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Show HN: Kakehashi – Experimental userspace to run macOS binaries on Linux ARM

https://github.com/wie-project/kakehashi
59•vlad_kalinkin•2h ago•21 comments

How the words we teach English language learners changed

https://pudding.cool/2026/07/essential-words/
123•c-oreills•2h ago•62 comments

Rooting, firmware analysis and persistent credentials of TP-Link TL-841N

https://blog.juni-mp4.com/posts/42/rooting-the-tplink-tl841n-pt1/
30•mindracer•2h ago•1 comments

Developers are attached to tools because tools encode trust

https://stackoverflow.blog/2026/07/29/developers-are-attached-to-tools-because-tools-encode-trust/
22•HieronymusBosch•4d ago•5 comments

Twenty Years of RISC OS Open

https://www.riscosopen.org/news/articles/2026/06/20/twenty-years-of-risc-os-open
111•AlexeyBrin•6h ago•18 comments

Welcome to Agents Week

https://blog.cloudflare.com/agents-week-welcome/
6•tosh•16m ago•2 comments

Show HN: NixOS-DGX-Spark – Nix and NixOS on the DGX Spark

https://github.com/graham33/nixos-dgx-spark
30•graham33•1h ago•4 comments

F*: A general-purpose proof-oriented programming language

https://fstar-lang.org/
100•ducktective•6h ago•32 comments

Harvesting SSH Credentials: Insights from My Honeypot Network

https://uphillsecurity.com/articles/harvesting-ssh-credentials-insights-from-my-honeypot-network/
5•whatbackup•54m ago•1 comments

Meshdiff – visually compare two STL versions in the browser, client-side

https://meshdiff.com/
143•projscope•7h ago•13 comments

Karpathy’s Pelican

https://twitter.com/karpathy/status/2083749667410727319
141•delichon•14h ago•129 comments

Fasttracker II clone in C using SDL 2

https://16-bits.org/ft2.php
70•andsoitis•4d ago•23 comments

When transit passes were designed by hand (2022)

https://letterformarchive.org/news/milwaukee-transit-passes/
46•nate•2d ago•15 comments

Folding Paper Globes

https://foldingglobes.com/globes
99•dango2506•4d ago•18 comments

Show HN: Bor – Open-source policy management for Linux desktops

https://getbor.dev/blog/2026-08-02-bor-v080-release/
140•eniac111•9h ago•19 comments

Show HN: Fuse – statically typed functional programming language

https://fuselang.org
75•the_unproven•7h ago•14 comments

Great Question (YC W21) Is Hiring Senior Demand Gen Manager

https://www.ycombinator.com/companies/great-question/jobs/YutDxyf-senior-demand-generation-manager
1•nedwin•6h ago

Rust All Hands 2026 Retrospective

https://blog.rust-lang.org/inside-rust/2026/07/31/all-hands-2026-retrospective/
61•dcminter•8h ago•26 comments

Turtle-inspired interactive Python project

https://www.codembark.com/projects/fv20lz9map/spider-web-drawing
5•camdenreslink•5d ago•0 comments

Pushes to arch AUR are suspendended right now.

https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/message/YPJ3FQYJTJXXY3R...
35•EbNar•1h ago•10 comments

Artificial Intelligence: Ars Notoria and the Promise of Instant Knowledge

https://publicdomainreview.org/essay/ars-notoria/
98•jruohonen•8h ago•24 comments

Go 1.27 Interactive Tour

https://victoriametrics.com/blog/go-1-27/index.html
321•Hixon10•17h ago•160 comments

Show HN: I'm a 15 Year Old Wannabe Engineer, This Is a Cycloidal Gearbox I Built

https://github.com/tom-ilan/cycloidal_gearbox
282•tomilan•16h ago•94 comments

Holocloth

https://holocloth.vercel.app
122•ingve•2d ago•21 comments

Diátaxis

https://diataxis.fr/
480•ryanseys•22h ago•55 comments

Norway Salmon

https://www.abc.net.au/news/2026-07-28/how-norway-s-salmon-industry-became-a-global-behemoth/1069...
85•CHB0403085482•5d ago•53 comments

A Rant About “Technology” (2005)

https://www.ursulakleguin.com/a-rant-about-technology
113•jamesgill•3h ago•63 comments

MkLinux and the pimped-out Apple Workgroup Server 9150

http://oldvcr.blogspot.com/2026/08/mklinux-and-pimped-out-apple-workgroup.html
96•goldenskye•15h ago•12 comments

Show HN: Syncular – offline-first SQL sync with TypeScript and Rust cores

https://github.com/syncular/syncular
66•quambo•8h ago•23 comments

ESP32-C3 SuperMini antenna modification

https://peterneufeld.wordpress.com/2025/03/04/esp32-c3-supermini-antenna-modification/
62•ta988•11h ago•11 comments
Open in hackernews

Pushes to arch AUR are suspendended right now.

https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/message/YPJ3FQYJTJXXY3RUXCYLMHUKHLIUNVFF/
35•EbNar•1h ago

Comments

mijoharas•39m ago
So another active attack? Does anyone have any other details?
evil-olive•39m ago
for context, 2 days ago:

Arch Linux disables AUR package adoption (https://news.ycombinator.com/item?id=49123208)

numeri•29m ago
Well, I guess I'll avoid updating for the next few days. A bit worrisome that I did so last night.

I wish I had a clear operating system to switch to for safety and the benefits that come with the AUR or the Nix ecosystem. Unfortunately it seems that the era of being able to naively and gratefully trust in the armies of volunteer maintainers is over.

LLMs make large scale and long-term attacks easy and cheap. You could (and if I was a three letter agency, I would probably do so!) maintain ten thousand packages as three thousand separate "individuals" for years before cashing in the trust you've built up.

embedding-shape•23m ago
> naively and gratefully trust in the armies of volunteer maintainers is over

I'm almost scared to ask, did you not even review the PKGBUILD or anything else before installing stuff from the AUR?

Nixpkgs has a completed different model compared to AUR, the changes that end up in nixpkgs are all reviewed by maintainers, while AUR is literally free-for-all "anyone can push anything at any time", I don't think you ever could "naively and gratefully trust" AUR in the way you might have been.

dijit•19m ago
> did you not even review the PKGBUILD or anything else before installing stuff from the AUR?

I'd venture most people actually don't review pkgbuild; especially on upgrades.

The other issue of course is that, the devils in the details. Fetch a binary as part of the installation (or, just fetch a binary itself, no compilation) then you're boned.

You can even hide nefarious code in the compilation/build steps, Jia Tan style.

embedding-shape•15m ago
> I'd venture most people actually don't review pkgbuild; especially on upgrades.

No, I'm sorry but who on earth installs random software from random strangers, without a single step of validating before giving it access to (presumably) the same computer you do banking on?

> The other issue of course is that, the devils in the details. Fetch a binary as part of the installation (or, just fetch a binary itself, no compilation) then you're boned.

Sure, that's why when you review the PKGBUILD, and instead of it using the official GitHub organization / domain (which you of course validate) for downloading the binary/source, you don't install it.

I agree it's still vulnerable to Jia Tan style attacks, but installing from AUR is essentially "curl http://random-website.com/script.sh | bash", and reviewing a PKGBUILD takes a few seconds, and stop/cancel if something is sus, it's really that easy.

fantyoon•2m ago
> No, I'm sorry but who on earth installs random software from random strangers, without a single step of validating before giving it access to (presumably) the same computer you do banking on?

I would assume essentially everyone? `curl https://random-website.com/script.sh | sh` is one of the most common way of installing software outside of perhaps Flatpak. AppImage is essentially the same as piping a script from the internet into bash.

> reviewing a PKGBUILD takes a few seconds

This assumes a naive attack that is easily visible from the PKGBUILD. Unless the attacker makes no effort to hide their activity, the PKGBUILD will look perfectly ordinary while still installing malware.

skydhash•18m ago
I used alpine linux and it looks pretty easy to setup your own repository, including build scripts for packages. I now use OpenBSD and the port systems of the BSD (each are different BTW) make it also easy to add extra software.