frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Meta Muse Glimmer – open weights 30B local coding model

https://research.meta.ai/blog/introducing-muse-glimmer-open-agentic-model
383•riordan•3h ago•179 comments

Mistral Patent for "Code implemented tool calls"

https://patentsgazette.uspto.gov/week26/OG/html/1547-5/US12670045-20260630.html
39•theanonymousone•30m ago•34 comments

50k Boat Names

https://www.beautifulpublicdata.com/boat-names/
32•jonathanmkeegan•1h ago•17 comments

Squeak/Smalltalk 6.1 Release Notes

https://squeak.org/release_notes/6.1/
36•fniephaus•1h ago•8 comments

Docker Sandboxes – Disposable, isolated sandboxes for AI agents

https://www.docker.com/products/docker-sandboxes/
357•etoxin•7h ago•221 comments

Tail-call optimization in C is relatively recent

https://lwn.net/Articles/1034703/
52•prakashqwerty•2h ago•22 comments

Parametron: 50s Japanese computer that uses neither transistors nor vacuum tubes

https://ethw.org/Milestones:Parametron,_1954
47•xeonmc•3h ago•14 comments

Over 181,000 AI meeting recordings left wide open in note taking app

https://bobdahacker.com/blog/tldv-hack
97•colesantiago•1h ago•32 comments

What Happened to HackerOne?

https://blog.teknogeek.io/posts/what-happened-to-hackerone/
297•hipparchus•11h ago•153 comments

DeepSeek costs OpenCode Go user $1.14/day; dual DGX breaks even in 24 years

https://twitter.com/thdxr/status/2086599224674681242
43•delduca•1h ago•36 comments

Run Android ARM64 VR APKs on Apple Vision Pro

https://github.com/shinyquagsire23/Klepton
128•LorenDB•10h ago•25 comments

Why a Raspberry Pi shouldn't be powered through its GPIO pins

https://82mhz.net/posts/2026/08/why-a-raspberry-pi-shouldn-t-be-powered-through-it-s-gpio-pins/
17•speckx•4d ago•7 comments

An Interesting Fourier Transform – 1/F Noise

https://www.dsprelated.com/showarticle/40.php
76•q7m•3d ago•16 comments

Tail-Call Interpreters in Rust – Jimmy Ostler

https://lordgoati.us/blog/tail-call/
54•amatheus•3d ago•17 comments

Show HN: Voice driven murder mystery, Interview AI suspects with your voice

https://www.whodunnitai.com/
138•MrRowTheBoat•10h ago•54 comments

Defending my own brain against enshittification

https://mrmarket.lol/how-i-feel-calmin-control-of-my-life-in-the-time-of-enshittification/
17•mrmarket•39m ago•2 comments

How Blackwing Pencils are Made [video]

https://www.youtube.com/watch?v=fow-LsdaH2E
42•NaOH•4d ago•16 comments

Findphone: Locate a nearby Bluetooth device by signal strength

https://github.com/ben-z/findphone
13•helsinkiandrew•5d ago•9 comments

Taxi drivers rarely die of Alzheimer's

https://theconversation.com/taxi-drivers-rarely-die-of-alzheimers-how-complex-mental-maps-and-spa...
335•jader201•22h ago•235 comments

How I use LLMs to learn complex topics

https://laurentiugabriel.github.io/blog/articles/how-i-use-llms-to-learn/
723•laurentiurad•18h ago•465 comments

How We Pushed CDC into Postgres

https://www.snowflake.com/en/blog/engineering/postgres-to-snowflake-replication-mirroring/
115•craigkerstiens•12h ago•23 comments

Ask HN: What are you working on? (August 2026)

279•david927•20h ago•961 comments

ATProto for Distributed Systems Engineers

https://atproto.com/articles/atproto-for-distsys-engineers
112•LelouBil•3d ago•21 comments

Because It's Not Fun Enough: why languages fail

https://bytecode.news/posts/2026/08/because-it-s-not-fun-enough
68•jottinger•2h ago•71 comments

Cool URIs Don't Change (1998)

https://www.w3.org/Provider/Style/URI
263•Klaster_1•23h ago•63 comments

An alias-based formulation of the borrow checker (2018)

https://smallcultfollowing.com/babysteps/blog/2018/04/27/an-alias-based-formulation-of-the-borrow...
19•parksb•2d ago•1 comments

Picophysics: Single file physics for games on platforms like N64, PSX, DC

https://gitlab.com/Kazade/picophysics
73•klaussilveira•5d ago•22 comments

Tuxedo No. 2 – Cocktail recipes

https://tuxedono2.com
120•smartmic•17h ago•35 comments

Everything you do is being recorded

https://www.theatlantic.com/technology/2026/05/ai-wearable-surveillance-countermeasures/687203/
351•ike_usawa•1d ago•314 comments

Nearest Pint

https://knowwhereconsulting.co.uk/maps/pubs/
43•bookofjoe•5d ago•26 comments
Open in hackernews

Over 181,000 AI meeting recordings left wide open in note taking app

https://bobdahacker.com/blog/tldv-hack
93•colesantiago•1h ago

Comments

sktb•1h ago
Six Months !?! If I'd left a vulnerability like that open for 6 hours there'd be hell to pay. Something that critical is call for hitting the big red off button.
idiotsecant•57m ago
Is this still active? I wouldn't mind spying on some meeting notes. Sounds fun.
blitzar•49m ago
"Lets circle back and touch base to tease out any low hanging synergies we can capitalise on" - repeated 181,000 times
mdrzn•45m ago
If they haven't fixed it in 6 months, I'd say it's fair game to scrape as much as you can.
yellow_lead•30m ago
Seems so
Ekaros•53m ago
I keep being amazed how most basic things are not checked. Cross-tenant isolation is one of the main things I check for... With other generic information leaks.
pc86•49m ago
Sturgeon's Law is proved correct time and again. Most things are crap. Most people produce some crap in their lives. Some people only produce crap. Those people still need to eat but unfortunately some of them (somehow) find their way into tech and actually convince people to pay money for crap.

Especially with a low bar to entry like what is essentially AI-backed transcription-as-a-service, I'm not sure 90% is high enough. There will be 100 companies offering essentially the same thing and it's unfortunately the responsibility of the customer to find the one written by someone who doesn't have a parsnip where their brain should be.

noir_lord•41m ago
Fortunately we have LLM's to not produce that crap... wait, those LLM's were trained on the existing crap and produce the same crap... oh no.
user43928•22m ago
I doubt SOTA models nowadays are going to produce an implementation without any kind of authentication like here, and not tell you about it.

And even if, a later "is this ready for release" will probably surface such obvious issues.

I do not think LLMs are the problem here. Today, they are most likely more competent than whoever set this up.

skydhash•6m ago
Still the six month wait time when everything should be good? /s
SpaceL10n•47m ago
Hmm, does Ukraine know that Russia is watching the Ministry of Digital Transformation's meetings?
palmotea•44m ago
Don't worry, I'm sure this was all an AI agent's fault, so no one to blame and all they need to do is update their code review prompts to not make mistakes.
HPsquared•10m ago
Also add the word "secure" a lot.
Aeroi•37m ago
holy crap. how do you respond as CEO to this and not escalate to like priority #1?

then kick the can for 6 months?

root-parent•27m ago
A post on LinkedIn where this CEO seems very active should solve that.
lostlogin•23m ago
> how do you respond as CEO to this and not escalate to like priority #1? then kick the can for 6 months?

We might be able to check the meeting minutes and get the answer?

gyanchawdhary•37m ago
This is bad. I run a company in this space (deepfake voice phishing), and one of the most common pushbacks we hear from buyers is: “Where are attackers going to get audio clips of our employees?” ... excluding senior leadership, which most companies already recognize as a risk.

Another similar incident that happened recently was 4TB/40,000 contractors voice + government ID + selfie leaked .. https://oravys.com/blog/mercor-breach-2026

PS: To demonstrate how this can be exploited with real time voice changers i.e. a voice phishing simulator .. we also built a free tool that shows this attack combined with someones voice ..

https://www.callstrike.ai/voice-phishing-simulator (Voice Phishing Simulator)

https://www.callstrike.ai/deepfake-security-training (Deepfake Video Simulator)

It’s obviously a heavily restricted PoC, but it helps demonstrate the attack path in practice.

lostlogin•25m ago
> 4TB/40,000 contractors voice + government ID + selfie leaked

Leaked selfies? Do you mean ID photos?

Oras•36m ago
Not the first time I read a shitty implementation with Firebase, I'm not blaming the platform, but seems there is a huge skill issues around it.

Wasn't a dating app exposed this year with same negligence or firebase security?

hluska•34m ago
I understand the need to shame this platform, but why expose all their clients to this much risk? This disclosure here just named a whole bunch of clients. Why?
root-parent•28m ago
You need to read the article.
hluska•18m ago
I read the entire article. Did you? There’s no reason in there to expose this company’s clients.

Edit - Are you capable of answering my actual question or was that the best you could do?

root-parent•10m ago
He has been emailing the CEO for six months with no replies. This is has also been posted here before with not a single pip or comment ... :-)

And these customers absolute lack of technical due diligence, on this nth example, of move fast and break things...makes them deserve what they are getting.

mikestew•4m ago
Read the article again, then. Anyone that has could get the list with a trivial amount of work. Security through obscurity isn’t going to hide that client list.

And who knows? Maybe someone competent whose company is a client will see that list and say, “hey, boss, I was on HN today, and…”

gossamer•12m ago
seb1204•26m ago
So did he email privacy@tldv.io? Why not? Maybe someone who understands it would read it.
ncr100•19m ago
It's unclear. Only stating the existence of the privacy email.

> [...] Buried at the bottom, a single line: "If you have discovered a privacy or security issue that we should address, please always let us know at privacy@tldv.io. Our security team will respond within 24 hours." I emailed the CTO directly. Six months. No response. [...]

This is near the disclosure schedule

Aeroi•18m ago
"Government meetings from 23 countries: Brazil, Colombia, Peru, Ukraine, El Salvador, the Philippines, Chile, Indonesia, Mexico, the United States, Qatar, Malaysia, Uzbekistan, Sri Lanka, Haiti, South Africa, Jamaica, Honduras, Argentina, Thailand, Japan, Israel, and Belize. "

oof

As I see it he is not the one exposing clients to risk. He is frustrated that no one is fixing it. The company that left themselves open like this are the ones that are exposing their clients.

If this person is doing his best to do the right thing, there are probably other people who know about this vulnerability and are using it without telling anyone.

masfuerte•7m ago
What's the alternative? Seriously. He's spent six months trying to get them to fix it. The risk is already there.