frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Court agrees with EFF: Utah's VPN law demands a technical impossibility

https://www.eff.org/deeplinks/2026/10/court-agrees-eff-utahs-vpn-law-demands-technical-impossibility
244•hn_acker•20h ago•109 comments

With most information hidden, the game Stratego had stumped AI until now

https://arstechnica.com/science/2026/10/ai-finally-beat-the-best-stratego-player-in-history-and-d...
42•PaulHoule•5h ago•7 comments

The Legend of von Neumann (1973) [pdf]

https://gwern.net/doc/math/1973-halmos.pdf
200•suopspaces•5h ago•114 comments

Greg Kroah-Hartman – Security in the LLM Age [video]

https://www.youtube.com/watch?v=NnV_cWeoo5Q
40•usernomdeguerre•16h ago•5 comments

FLUX 3 Image

https://bfl.ai/models/flux-3-image
175•minimaxir•23h ago•34 comments

Loss of cell identity drives human aging: Two new papers

https://erictopol.substack.com/p/loss-of-cell-identity-drives-human
45•bookofjoe•23h ago•7 comments

Sites in ChatGPT

https://chatgpt.com/features/sites/
98•polvi•20h ago•97 comments

A 12-year sequence of telescope images of a star and four planets orbiting

https://bsky.app/profile/theplanetaryguy.com/post/3mwucf5ert22f
16•mariuz•8h ago•2 comments

Mike Tomlin spent 12 years building a Minecraft city

https://www.nytimes.com/athletic/7648198/2026/10/01/mike-tomlin-minecraft-nfl-coach/
35•CoryOndrejka•1d ago•3 comments

Our Project Suncatcher prototype satellite is in orbit

https://blog.google/innovation-and-ai/models-and-research/google-research/project-suncatcher-prot...
13•pantalaimon•8h ago•9 comments

One month coding with GLM 5.3 Flash

https://wagtail.org/blog/one-month-on-glm-53-flash/
18•ThibWeb•3h ago•8 comments

Leaderboards and speedrun.com's new terms of service

https://therun.gg/blog/leaderboards-speedruncom
17•Kayvanian•1h ago•6 comments

Decision models like Jev don't beat LLM-as-a-judge or traditional classifiers

https://developers.redhat.com/articles/2026/10/02/benchmarking-ai-decision-models-against-traditi...
9•tomncooper•5h ago•0 comments

Show HN: Giving Opus 5.5 a simulated paint canvas

https://stillwet.art/
130•alstonite•18h ago•43 comments

Blogging with Gleam, Org-Mode and Pandoc

https://byzantine-systems.github.io/blogging-with-gleam-org-mode-and-pandoc/
6•schonfinkel•7h ago•0 comments

Lace and Labor: Lessons from the actual Luddites

https://articlesofinterest.substack.com/p/lace-and-labor
6•surprisetalk•2d ago•0 comments

Apple Pass Designer

https://developer.apple.com/pass-designer/
3•soheilpro•9m ago•0 comments

Supabase is acquiring Turso

https://supabase.com/blog/supabase-is-acquiring-turso
161•cvburgess•3h ago•83 comments

Dutch computer museums (2022)

https://aresluna.org/dutch-computer-museums/
84•npollock•2h ago•24 comments

How accurately calibrated is Jev?

https://maximumeffort.substack.com/p/jev-is-poorly-calibrated
6•dblack12705•4h ago•3 comments

What if we stopped using GPUs? [video]

https://www.youtube.com/watch?v=xc2FTBGRSJo
7•sandslash•1h ago•0 comments

Anatomy of a Lean proof for software engineers

https://agostbiro.net/posts/2026-10-anatomy-of-a-lean-proof/
15•abiro•1d ago•0 comments

100 years of student radio history in the DLARC college radio collections

https://blog.archive.org/2026/10/02/100-years-of-student-radio-history-in-the-dlarc-college-radio...
7•HieronymusBosch•6h ago•1 comments

On building a worm detector

https://bencology.bearblog.dev/mapping-individual-and-collective-worm-movements/
5•surprisetalk•7h ago•0 comments

On Social Reality in China

https://www.lesswrong.com/posts/b5cSYh4emQb2qrGmK/on-social-reality-in-china
9•thicTurtlLverXX•7h ago•1 comments

Venice’s failed war against Constantinople led to the first bond market

https://bigthink.com/books/a-fabulous-debt/
9•RickJWagner•5h ago•0 comments

SequenceHash: Multihashing for the rest of us

https://blog.trailofbits.com/2026/10/02/sequencehash-multihashing-for-the-rest-of-us/
7•tob_scott_a•5h ago•0 comments

Tiny Brutalism

https://placeholders.itch.io/tiny-brutalism
106•abetusk•19h ago•27 comments

The Philadelphia Inquirer built Scrape, an AI tool to surface hyperlocal news

https://www.lenfestinstitute.org/solutions-resources/philadelphia-inquirer-scrape-ai-hyperlocal-n...
4•giuliomagnifico•11h ago•0 comments

Show HN: Our space game has a built-in RISC-V emulator that runs Linux

https://againstallodds.games/
5•nor-and-or-not•8h ago•1 comments
Open in hackernews

Greg Kroah-Hartman – Security in the LLM Age [video]

https://www.youtube.com/watch?v=NnV_cWeoo5Q
40•usernomdeguerre•16h ago

Comments

usernomdeguerre•16h ago
Greatly appreciated the candor. I've included a few slides into text that i thought were eye-opening to me:

From his Kernel Recipes 2026 slide on Mythos

```

  Mythos's 79 vulnerabilities:
  24 - no detail at all "something crashed"
  14 - not a bug at all
  3 - totally made up data
  15 - already fixed in latest release
    - 11 by others
    - 4 by anthropic
  20 - fixes were needed
    - 7 "assume a malicious filesystem image"
    - 2 "assume you can inject a malicious network packet into the middle of the stack"
    - 2 "NOMMU"
    - 6 sctp networking issues for untrusted devices
    - 2 ipv6 minor network issues 
    - 1 gpu driver for local malicious user
```

GHK called this "10 'real' bugfixes", which to me sounds like there's a wild hype machine around these companies and uncritical parroting of every press release they make that falls apart when you engage the affected real experts.

p-o•27m ago
It also adds up to 76, which he made fun of in the video. LLM can't count, his words, not mine. Although, I tend to agree with him!
OtherShrezzing•21m ago
We’ve seen this in a few open source repos we voluntarily manage security on. They’re not massive repos, but big enough they get attention from security researchers.

Most of the real low hanging fruit was picked up by humans years ago. When doing automated scanning, the majority of stuff is overly-verbose nonsense which takes hours of expert human labour to understand, test, and discard.

Reading through a Claude generated false positive is absolutely excruciating, because it is absolutely determined that what it’s found is justified. Often you’ll receive very long accompanying “proof of concept” code which demonstrates absolutely wild scenarios. It’s especially frustrating when you’re volunteering your time for a project, and a well-meaning contributor submits the report without the technical nous to understand why you’re rejecting it.

blinkingled•18m ago
It's great to hear about $topic from someone no-nonsense and in-the-know like Greg KH. You can verify all of this too - since, well Linux kernel. (As opposed to what Microsoft or Apple claims to fix as far as LLM finds.)
sriram_sun•4m ago
He also said that it all boiled down to just one hour of kernel development work.