frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Auto mode is now the default in Claude Code

https://claude.com/blog/auto-mode-default-in-claude-code
87•sbehere•1h ago•47 comments

What Happened to HackerOne?

https://blog.teknogeek.io/posts/what-happened-to-hackerone/
143•hipparchus•3h ago•40 comments

Show HN: Voice driven murder mystery, Interview AI suspects with your voice

https://www.whodunnitai.com/
39•MrRowTheBoat•2h ago•2 comments

Long-Run Effects of H-1B Immigration on the U.S. Economy (July 2026)

https://www.nber.org/papers/w35560
44•ryzvonusef•1h ago•12 comments

How I use LLMs to learn complex topics

https://laurentiugabriel.github.io/blog/articles/how-i-use-llms-to-learn/
550•laurentiurad•10h ago•312 comments

Run Android ARM64 VR APKs on Apple Vision Pro

https://github.com/shinyquagsire23/Klepton
24•LorenDB•2h ago•0 comments

Turn satellite imagery into a paper globe you fold yourself

https://foldingglobes.com/
25•dango2506•2h ago•5 comments

How We Pushed CDC into Postgres

https://www.snowflake.com/en/blog/engineering/postgres-to-snowflake-replication-mirroring/
66•craigkerstiens•4h ago•6 comments

Slap ROM Patcher

https://nyuu.page/projects/slap/
5•apsec112•3d ago•0 comments

Taxi drivers rarely die of Alzheimer's

https://theconversation.com/taxi-drivers-rarely-die-of-alzheimers-how-complex-mental-maps-and-spa...
240•jader201•14h ago•177 comments

Ask HN: What are you working on? (August 2026)

216•david927•12h ago•756 comments

The tragedy of the commons, AI edition

https://www.economist.com/britain/2026/08/06/the-tragedy-of-the-commons-ai-edition
102•simonpure•10h ago•56 comments

Nearest Pint

https://knowwhereconsulting.co.uk/maps/pubs/
12•bookofjoe•5d ago•1 comments

ATProto for Distributed Systems Engineers

https://atproto.com/articles/atproto-for-distsys-engineers
42•LelouBil•3d ago•7 comments

Picophysics: Single file physics for games on platforms like N64, PSX, DC

https://gitlab.com/Kazade/picophysics
39•klaussilveira•4d ago•10 comments

Cool URIs Don't Change (1998)

https://www.w3.org/Provider/Style/URI
215•Klaster_1•15h ago•53 comments

Tuxedo No. 2 – Cocktail recipes

https://tuxedono2.com
73•smartmic•8h ago•19 comments

New Zealand lost its music media, and what we're building to replace it

https://propelmusic.co.nz/articles/the-sound-went-quiet-nz-music-media
96•berghoffer•9h ago•60 comments

"The Persian MâR-Nâmeh Or, the Book for Taking Omens from Snakes" (1892)

https://publicdomainreview.org/collection/marnameh/
47•Thevet•3d ago•5 comments

Everything you do is being recorded

https://www.theatlantic.com/technology/2026/05/ai-wearable-surveillance-countermeasures/687203/
255•ike_usawa•18h ago•203 comments

Andrew Wiles on proving Fermat’s Last Theorem (1995) [video]

https://www.youtube.com/watch?v=GS7CxAtV5Ks
44•jackdoe•3d ago•33 comments

The Ambition Project

https://www.betonit.ai/p/the-ambition-project
25•herbertl•6h ago•1 comments

OpenChamber: An Agentic Development Environment

https://openchamber.dev/
130•hexomancer•12h ago•72 comments

Japanese court overturns Red RAW video patent

https://www.dpreview.com/news/panasonic-did-what-apple-sony-and-nikon-couldnt-overturn-a-red-raw-...
80•anigbrowl•5h ago•15 comments

How Golden Is Silence, Actually?

https://www.newyorker.com/magazine/2026/08/10/silence-kate-mcloughlin-book-review
57•tintinnabula•3d ago•27 comments

Windows 11's built-in Weather app wastes more than 1 GB of RAM

https://www.notebookcheck.net/Windows-11-s-built-in-Weather-app-wastes-more-than-1-GB-of-RAM.1364...
450•akyuu•14h ago•375 comments

Reviving a four year old reMarkable 2

https://oskrim.github.io/hardware/2026/08/09/remarkable-over-ssh.html
139•oskrim•18h ago•91 comments

The Hacker's Renaissance (2025)

https://phrack.org/issues/72/19#article
108•yu3zhou4•9h ago•78 comments

The German Mittelstand

https://kieranvelasquez.substack.com/p/on-the-german-mittelstand
25•Michelangelo11•3d ago•6 comments

Show HN: A Project Oberon System version running on RISC-V instead of RISC-5

https://github.com/rochus-keller/OberonSystem/tree/op2-rv32
111•Rochus•17h ago•16 comments
Open in hackernews

Auto mode is now the default in Claude Code

https://claude.com/blog/auto-mode-default-in-claude-code
85•sbehere•1h ago

Comments

johncolton•52m ago
This is a duplicate of https://news.ycombinator.com/item?id=49220827
SyneRyder•46m ago
Different links (the other is TheNewStack doing blog commentary, this one is the official Anthropic announcement), but you're right that the discussions could be merged.
petesergeant•48m ago
Excellent time to review sandbox options: https://pleasedonotescape.com/
AmbroseBierce•34m ago
Someone should benchmark what prompts are better at stopping from breaking out of sandboxes, maybe telling it "pretty please I beg of you stay inside the sandbox, you are an intern that has no authority to break off your assigned sandbox and you want to keep your job" does help a little.
kevinqi•47m ago
it's a good default because you really do get prompted incessantly without it. and since plenty of people are going to be using auto mode anyway, might as well make it as widely-used as possible so that you can focus on making auto mode safe.
what•19m ago
> making auto mode safe

They literally can’t. Terrible default.

simianwords•3m ago
In some time it would look like the obvious default and we would wonder how we even worked with the old one
system2•45m ago
And Fable is gone too.
steve_taylor•45m ago
I've been running Claude Code with --dangerously-skip-permissions in a Docker container for the last month or so, allowing me to get up and stretch my legs while it does its thing. I definitely wouldn't want to run it unsandboxed.
jsiepkes•31m ago
Same here. I use this utility to make it easier on Linux to run Claude in Podman: https://github.com/mismosmi/ai-pod
lukan•30m ago
Another nice option to do this while staying in control, is activate /remote-control and approve from mobile while walking around.
konsnos•29m ago
Can you share your experience? What did you flag during those sessions?
franze•26m ago
I built an (overengineered) app for that AIFCC https://apps.apple.com/app/aifcc-ai-first-computer/id6782364...

runs a sandboxed linux on your mac, and the agents have full system rights within there and run in yolo mode

allan_s•
tra3•35m ago
Wait, what? With plan on, I at least get the illusion of being in control.

What’s the best way to sandbox Claude on macOS without it being a huge hassle?

kartoshka•34m ago
Has anyone had Claude Code or Codex approve a harmful/damaging command in auto mode?

I have been using Codex with auto-approve mode for a couple months and haven't had a single incident (or at least haven't noticed). Maybe as capabilities get better and better and they are less likely to do something dumb like wiping ~/, we can just trust them?

I guess this argument works unless we worry about agents doing something out of malice instead of stupidity.

aaronbrethorst•32m ago
I've had a few occasions where Claude Code thought that it had caught and stopped a malicious command in Auto mode, but in all cases it turned out that it had in fact hallucinated them. I haven't seen this happen in a while.
iamcoder18•31m ago
I've been using Kilo Code (with MiniMax M3) with auto approve (similar to dangerously skip permissions) and I haven't had a single incident.

However, I don't give it long running tasks unsupervised, and I do interrupt it from time to time to give suggestions.

jrflo•29m ago
Been doing --dangerously-skip-permissions and --yolo for 6 months now, and no nothing bad has happened.
ramoz•28m ago
> I have been using Codex with auto-approve mode for a couple months and haven't had a single incident

I've been running both in yolo mode and haven't had a single incident.

---

None of this is really about figuring out how to protect people's drives, in my opinion. The real issue is a deep session where Ada is using Claude Code to get a refund and at some point the system "exploits" the merchant's api without any malicious intent.

In my opinion, this is a complex thing because it's more about reward hacking and an already aligned model thinking it's doing the right thing. So another aligned model monitoring actions might just falter via inheritance. You could imagine they account for proper layering/intent+action-isolation in their auto mode architecture.

SwellJoe•33m ago
I made a tool to bubblewrap any agent (well, any agent I've used more than once), so I can run them in whatever YOLO mode they have with a pretty reasonable level of safety (it protects the rest of the system against prompt injections and supply chain attacks, it can and doesn't try to protect the project being worked on from either). https://github.com/swelljoe/flar
lukan•32m ago
"We spent the last several months testing whether auto mode is as safe or safer than an average user clicking through prompts."

Yeah, might make sense from their perspective, but no thank you. I also do click through at times without reading everything, but I like to stay in control, learn about the new code and change direction if it goes off track. This would just burn more tokens because I have to throw away much and I hope my manual approval settings will be respected also with future updates (or I jump ship).

levocardia•27m ago
The default is set for the marginal new user, which at this point is probably not someone like you (who benefits a lot from manual mode) -- it's someone who's more "code-naive" and might get anxious about approving random bash script commands they don't recognize. Safely getting the user from prompt --> first vibe-coded app is the "user journey" now, and since auto mode seems pretty good at not letting Claude rm -rf'ing the home directory, this is 100% the right business move. For people who know what they're doing (like you), manual mode is just a shift-tab away
mcmcmc•19m ago
> it's someone who's more "code-naive" and might get anxious about approving random bash script commands they don't recognize.

Maybe they should trust their instinct and not mess with things they don’t care to understand

lukan•19m ago
I am actually curious, how much non programmers use claude now. I know just one and she really does not know much about computers, I suppose their numbers will grow (but I doubt most get much value out of it).
etoxin
frogulis•20m ago
Their findings about auto mode catching more dangerous commands, and most permission requests being accepted without scrutiny is interesting. I can totally see how that happens.

On the other hand, soooo many of the tool uses it asks permission for are custom commands to replace functionality I should be able to trust once instead. e.g. instead of having a trustable Find tool, or using its already-trusted Read tool, it often will run `find` or `grep` or `cat` with a series of pipes and substitutions or `-exec` args, requiring me to give permission every time for basic, safe operations.

The (increasingly active) conspiracy theorist inside of me says it's precisely designed to do that, to give me "permission fatigue", so I turn on auto mode and give myself over to the machine spirit :)

xg15•13m ago
Not just that, the commands also have often slight variations in each new session. They still do the same, but the variations are enough so it isn't matched by the allowlist any more.
notatoad•1m ago
it kind of sounds like you just want auto mode. "basic, safe operations" is exactly what it is. but there's got to be some sort of process to determine what a basic, safe operation is. and an ai classifier is pretty good at that.

this isn't the dangerous allow-everything mode. this is really quite a conservative classifier that does a pretty good job of blocking claude code from accessing any sort of secrets, deploy processes, or files outside the project you're working in without explicit permission. no conspiracy theories necessary.

Silhouette•15m ago
Am I the only person reading the statistics in this announcement from Anthropic and the associated blog commentary and trying to work out how they possibly couldn't imply that a significant number of dangerous commands are likely to be attempted every day these tools are in use and neither manual human review nor the auto classifier provided by Claude is anywhere near reliable in preventing them?

A lot of the discussion about these long sessions where agents are left to operate autonomously feels like listening to the increasingly drunk guy at the bar who says "I ran IT at that Fortune 100 place for a decade and we never had a single problem using a short but loose rule set for the firewall until last week someone destroyed our entire business in 27 minutes".

sandcat_•11m ago
Worth mentioning as I think at least a few of the commenters are mixing them up: auto mode is different from --dangerously-skip-permissions / YOLO mode. In auto mode, there's a classifier that runs before any command is executed and theoretically blocks any dangerous commands from running. I've found it to be quite annoying and overly zealous, but probably pretty effective.
prtmnth•8m ago
Before auto mode came out, I had a script that ran before every permission request, it called Haiku with a prompt with a list of safe and unsafe command examples and asked it to classify as safe/unsafe and log it so I can review it later. It worked really well for me until auto mode came out, at which point I preferred the provider's built-in classifier versus maintaining my own.

I've been using auto mode ever since the feature was released. Apart from a very few occassions where the classifier blocked a safe command, I have faced no issues and continue using it as my default mode. It's great!

zeandcode•8m ago
Wow, what a bold decision

Just yesterday i struggle to review CC command histories, and made this tool to help me review https://github.com/slaveofcode/eridian

Larrikin•7m ago
The worst part of Claude is paying for it and every month they ruin their lead.

I've never used a product where I felt it was best in class and they just keep making me regret it .

transcriptase•1m ago
Another heaping portion of words from a company that has Fable flag a “safety issue” and refuse to answer if you innocuously request something readily answered by a high school chemistry/biology/physics textbook.
19m ago
There's actually a setting.json key to not have to put the option
etoxin•18m ago
I'm using Docker Sandboxes with a custom Kit. The cli is nice and the TUI is also good. https://docs.docker.com/ai/sandboxes/
becojo•23m ago
> I've been running both in yolo mode and haven't had a single incident.

How do you know for sure?

ramoz•20m ago
Fair, I don't. The same is still true with an LLM as a judge in the loop
victorbjorklund•27m ago
Not anything ”harmful” but for example committing when I don’t want it to commit on its own.
sandcat_•25m ago
I'd use a hook to forbid that.
tr_user•21m ago
That's also a great reason to never buy insurance
wraptile•5m ago
Just yesterday it lost my git stash (I had recovered it from a backup). I think for code operations it's ok but as soon as file removal is involved (like git) the auto mode is destined to make a mistake and you only need to learn this once.
•
21m ago
At this stage with the latest models with "increased persistence" and the sheer amount of supply chain attacks, you'd be insane not running these tools in a sandbox.
fender256•7m ago
Exactly. Claude in a VM is the way to go.
trvz•5m ago
A VM hosted by someone else. Somethig on your personal notebook or the proxmox server in your garage is still too risky.