frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Radicle: Disclosure of Vulnerability in the Network Protocol

https://radicle.dev/2026/09/23/disclosure-of-vulnerability-in-network-protocol
32•lostmsu•1h ago

Comments

Tiberium•1h ago
I honestly thought there would be some elaborate chain there, not "we forgot to use encryption"...
pixl97•1h ago
Honestly issues like this crop up pretty commonly. JWT alg:none for example. Or even older people forcing SSL to downgrade to encryption null.

In any system that provides security it should only be designed to run if the security is in use, and to fail immediately with no further action if the security is not used.

csomar•21m ago
And not using authentication.

> Peer authentication in the connection handshake is broken and allows impersonation. An attacker can connect to your node and present a Node ID that is not its own. Private repositories are shared only with allow-listed Node IDs. An attacker who fakes an allow-listed Node ID can fetch a private repository directly, without being on the network path. This was reported to us by cryptocode on 2026-08-12. We proposed a fix upstream, see this pull request.

They are trying to sweet write it as much as possible. But basically there is neither encryption nor authentication. The person who made the protocol/program simply didn't care.

Velocifyer•1h ago
My main wish is if radicle had a way to make issues online, without installing the software. Runing a piece of software is a high barrier of entry to make a bug report, which the entire reason I use codeberg instead.
someonebaggy•35m ago
That's a downside of all decentralised software, isn't it? If there's a convenient access point, that access point is also a point of centralisation. To be distributed, you have to be running the software yourself. The big problem is that the software always ends up being inconvenient. People have no problem using bittorrent because the software is actually usable.
john_strinlai•50m ago
>This was reported to us by Konstantinos Maninakis on 2026-06-24.

announcement 3 months later is not super great, considering that the current advice is "Stop using private repositories (over the network) until the security update is released."

ewy1•37m ago
thankfully (for me), this is about the git forge and not the oss calendar and contact synchronization software by the same name

https://radicale.org/v3.html

kamranjon•35m ago
it's not the same name
gojomo•14m ago
Is there a risk that other projects that may be using the same cyphernet-labs/netservices.rs code, like Nym & Farcaster, have also been expecting authentication & encryption where it hasn't been happening?

Fixing the Portobello Police Station Clock

https://pointinthecloud.com/2026-04-11-211700.html
144•avidly•1h ago•31 comments

28% of job postings on company career sites have been open over 90 days

https://unlisted.careers/ghost-jobs/report/2026-09
22•rubatrejo•32m ago•13 comments

Radicle: Disclosure of Vulnerability in the Network Protocol

https://radicle.dev/2026/09/23/disclosure-of-vulnerability-in-network-protocol
33•lostmsu•1h ago•10 comments

Gemini 3.8 text-to-speech

https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-8-text-to-speech/
78•swolpers•1h ago•39 comments

Stripe's Knowledge AI Platform

https://stripe.dev/blog/meet-stripes-knowledge-ai-platform
106•ltononro•3h ago•60 comments

Jev in 25 Lines of Python

https://www.nobodywho.ai/posts/jev-in-25-lines/
489•bashbjorn•9h ago•150 comments

Strands Harness

https://strandsagents.com/blog/introducing-strands-harness/
81•zuckerborg0101•2h ago•54 comments

Claude Code reads AGENTS.md only when telemetry is on [fixed]

https://blog.szypowi.cz/p/claude-code-reads-agents.md-only-when-telemetry-is-on/
360•pszypowicz•4h ago•199 comments

GPT-6 Sol and Luna

https://openai.com/index/introducing-gpt-6-sol-and-luna/
1679•OfficialTurkey•23h ago•804 comments

Z80 REPL (2018)

https://abagames.github.io/z80-repl/index.html
108•adunk•6h ago•14 comments

Tokens Too Cheap to Meter

https://jyn.dev/tokens-too-cheap-to-meter/
128•teoruiz•7h ago•90 comments

Claude Opus 5.5

https://www.anthropic.com/claude-opus-5-5
1701•km144•1d ago•1039 comments

I don't want the details

https://michaelheap.com/i-dont-want-the-details/
200•mooreds•4h ago•123 comments

GPT-6 Astra has gained the ability to drive a car

https://drivingbench.com/
159•plurby•1h ago•123 comments

Web-based IBM 1620 emulator and IPL-V from 1963

https://github.com/pkimpel/retro-1620
17•abrax3141•17h ago•3 comments

QuestDB (YC S20) Is Hiring a Sales Engineer

https://questdb.com/careers/pre-sales-engineer-north-america/
1•nhourcard•5h ago

Seattle City Council votes to ban surveillance pricing in sale of groceries

https://advocacy.consumerreports.org/press_release/seattle-city-council-votes-to-ban-surveillance...
82•ortusdux•3h ago•18 comments

OpenAI GPT–6 Astra breaks Enigma message that has resisted solution since 2005

https://www.cryptocellar.org/bgac/the-mvueh-break.html
708•sohkamyung•1d ago•426 comments

Transit rewards

https://waymo.com/blog/2026/09/transit-rewards/
220•raybb•14h ago•275 comments

The GitHub wiki is an anti-pattern (2022)

https://michaelheap.com/github-wiki-is-an-antipattern/
122•ibobev•4h ago•71 comments

What California is learning from solar panels built over irrigation canals

https://www.kqed.org/science/2002033/heres-what-california-is-learning-from-solar-panels-built-ov...
312•Jtsummers•1d ago•602 comments

Microsoft killed FoxPro in 2007. Anyway, here's FoxPro revived

https://foxscript.org/
427•boredjohnny•20h ago•235 comments

How did AMD Ryzen get 50% faster in two years?

https://lemire.me/blog/2026/09/18/how-did-amd-ryzen-get-50-faster-in-two-years/
435•ibobev•4d ago•177 comments

'We hacked the FBI:' Hackers say they have data on all FBI employees

https://www.404media.co/we-hacked-the-fbi-hackers-say-they-have-data-on-all-fbi-employees/
749•spenvo•23h ago•540 comments

SAML: A fractal of bad design

https://blog.trailofbits.com/2026/09/21/saml-a-fractal-of-bad-design/
314•aray07•22h ago•163 comments

ReBarUEFI: Resizable BAR for almost any UEFI system

https://github.com/xCuri0/ReBarUEFI
211•nateb2022•2d ago•66 comments

Data-only attacks are easier than you think (2024)

https://www.usenix.org/publications/loginonline/data-only-attacks-are-easier-you-think
86•segfaultbuserr•13h ago•33 comments

WordPress: Unauthenticated path traversal leading to conditional RCE

https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp
223•vntok•1d ago•121 comments

Pentagon says overreliance on AI contributed to missile strike on Iran school

https://www.bloomberg.com/graphics/2026-iran-school-attack/
832•devonnull•22h ago•446 comments

Claude Opus 5.5 Intelligence, Performance and Price Analysis (Max)

https://artificialanalysis.ai/models/claude-opus-5-5
320•theanonymousone•1d ago•101 comments