frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Whistle: Speech to Text in 16.9 MB

https://cactuscompute.com/blog/whistle
310•gmays•3h ago•73 comments

Theranos.World

https://www.theranos.world/
75•kbyatnal•2h ago•27 comments

The value of not getting to the point (2015)

https://ken.arneson.name/2015/11/the-value-of-not-getting-to-the-point/
46•NaOH•1h ago•15 comments

Why isn't the industry freaking out about DeepSeek 4.1 Flash?

https://www.dgt.is/blog/2026-10-07-deepseek-freek-out/
106•jonotime•20h ago•83 comments

Show HN: K10s – A Clickable Kubernetes TUI (Go, Bubble Tea)

https://github.com/p10node/k10s
49•pierreneter•2h ago•30 comments

A Terminal Protocol for Program Status (OSC 7501)

https://mitchellh.com/writing/program-status-osc7501
26•mfiguiere•1d ago•4 comments

Step 5 Preview, a 1M-context MoE from StepFun, shows up on OpenRouter

https://openrouter.ai/stepfun/step-5-preview
60•AnneWodell•4h ago•20 comments

Man discovers his parents' coffee machine used 1TB of data in 10 days

https://www.dexerto.com/entertainment/man-discovers-his-parents-coffee-machine-used-1tb-of-data-i...
156•ck2•1d ago•75 comments

I hired an illustrator to draw my house. Now it's my Home Assistant dashboard

https://antonfrolov.substack.com/p/i-hired-an-illustrator-to-draw-my
139•soheilpro•1d ago•10 comments

A 5.3M-year-old deep-sea whale necropolis in the Diamantina Zone

https://www.nature.com/articles/s41586-026-10546-z
32•bryanrasmussen•1d ago•0 comments

Beauty in DVD Menus

https://vale.rocks/posts/dvd-menus
209•speckx•7h ago•133 comments

Show HN: Making a flexible "neon" t-shirt with LED filaments

http://scottbezek.blogspot.com/2026/10/making-flexible-neon-t-shirt-with-leds.html
45•scottbez1•4h ago•8 comments

OpenAI annualised revenues $20B less than previously signalled

https://www.cnbc.com/2026/10/08/open-ai-revenue-nvidia-oracle-coreweave.html
283•mfiguiere•3h ago•171 comments

The dawn of the age of the exoskeleton

https://theconversation.com/the-dawn-of-the-age-of-the-exoskeleton-281804
24•speckx•1d ago•4 comments

ETH-68: Ethernet Audio Interface for Linux

https://naturalsystems.io/eth68
24•chabad360•1d ago•6 comments

OLED burn-in test: 30-month update

https://www.techspot.com/article/3178-oled-burn-in-test/
51•baal80spam•10h ago•31 comments

DuckDB Ducklake

https://github.com/duckdb/ducklake
69•saikatsg•1d ago•6 comments

“Math 2.0” will need to value mathematical progress more holistically

https://mathstodon.xyz/@tao/117395269325940185
578•ent101•15h ago•602 comments

Trump administration is suspending Microsoft from a green card program

https://apnews.com/article/h1b-visa-program-vance-microsoft-e7b3a407f822702b269ee277d21343ea
715•alephnerd•5h ago•1222 comments

I gave Opus 5.5 one prompt and six hours to visualize Invisible Cities

https://quesma.com/blog/invisible-cities-one-shot/
312•stared•8h ago•159 comments

Show HN: Rgpu – a PyTorch device whose tensors live on a remote GPU

https://github.com/ymcrcat/rgpu
15•boxstream•1d ago•1 comments

Archaeologists Are Reconstructing the 'Invisible' Technologies of the Stone Age

https://www.smithsonianmag.com/science-nature/archaeologists-are-reconstructing-the-invisible-tec...
82•Hooke•23h ago•39 comments

Vanillin provides a sweet solution for chronic wound healing

https://news.flinders.edu.au/blog/2026/10/06/vanillin-provides-a-sweet-solution-for-chronic-wound...
18•geox•9h ago•1 comments

Show HN: I Put an AI Agent on a Nokia 110

https://github.com/anupray95/AI-Agent-on-a-NOKIA
22•anupray•6h ago•5 comments

Yes, and

https://htmx.org/essays/yes-and/
17•Michelangelo11•10h ago•3 comments

Orkut.com

https://orkut.com/
103•andreynering•6h ago•72 comments

Vitalik Buterin backs crypto ‘bunker mode’ amid rapid AI math advances

https://cointelegraph.com/news/justin-drake-urges-crypto-bunker-mode-as-ai-could-break-wallet-sec...
35•firstcomm•1h ago•20 comments

Tell HN: I've been paying for a rural Tanzanian's education for 10 years

607•lukehandcool•6h ago•169 comments

New CRAM method offers giant boost to compressed memory reads

https://www.tomshardware.com/software/linux/new-linux-tech-compresses-memory-in-ram-as-ram-for-45...
38•danny00•7h ago•18 comments

Show HN: TerrainSR – fast, realistic heightmap upscaling model

https://huggingface.co/joe-gibbs/terrainsr
12•joegibbs•1d ago•2 comments
Open in hackernews

Man discovers his parents' coffee machine used 1TB of data in 10 days

https://www.dexerto.com/entertainment/man-discovers-his-parents-coffee-machine-used-1tb-of-data-in-10-days-3416399/
153•ck2•1d ago

Comments

ck2•1d ago
it took me a month to notice my Midea A/C was absolutely hammering my router

I didn't even know it had wifi capability but it was trying to connect

I use mac whitelist so it wasn't even getting in but that didn't stop it from trying every seond

Fortunately it was just a usb dongle so yanked it out

ars•1d ago
I have two of them, and I just checked and both are quiet. Mine don't connect to WiFi unless you go through an entire process first with an android phone and Matter.

It's great having them on WiFi - you can turn on the AC before getting home to pre-cool, without having to leave it on all day.

sillyfluke•1d ago
Boy: So, how it get this bad grandpa?

Man: Well, before you couldn't turn on the AC before you got home

ars•1d ago
Realistically people would just leave their AC on. So this saves energy, rather than changing comfort.
Cpoll•23h ago
Realistically ACs have timers, so you're really only optimizing for days where you go off-schedule.
sillyfluke•21h ago
I have a friend who diy'ed a button on single webpage that he presses on his phone while at work in order to open the gate to the building that he lives so delivery people can get in. I also think Bret Victor diy'ed the AC as mentioned while he was a student quarter century or more ago[0]

I know this sounds like the famous "just do it this way in linux instead" criticism of Dropbox back in the day. But I do think we reached "life parodies fiction" with these smart devices where it makes sense to give diy another go. And with AI, there's less excuses this time around I would imagine.

But I would literally rather buy a cheap phone, a cheap SIM, hotspot it and connect it to a charger and have the AC connect to that and isolate it that way instead of letting it touch the network.

[0] https://worrydream.com/Electronics/

ttytty•21h ago
You can (and should) just segregate your network to have separate paths for IoT/"smart devices" and normal personal/family devices. Makes it all worry free and transparently observable.

I have my IoT on a separate VLAN and I can observe communications for any given device at any given time.. this seems like a much saner solution than outright not buying any IoT devices, though that is also a respectable decision!

altairprime•1d ago
Most Midea units can be swapped for an ESPhome USB dongle if you ever wish to have remote control on your own terms — note various countries’ shop links, and the various wiki and other outlines for DIY etc: https://smlight.tech/product/slwf-01
HankB99•22h ago
Ooo. I have a Midea dehumidifier. When it powers up it displays the WiFi symbol. I wonder if it is hammering away at my access point. Might it be better to bring it on line and then just block all traffic?

And I wonder how I would even tell if it was trying to associate with my WiFi.

pseudohadamard•6h ago
I have a Midea dehumidifier too. It moves around 200kB/hour which seems to be cloud polling about once a minute, so no big deal traffic-wise.
altairprime•1d ago
In the Twitter thread linked, the person confirms two things:

1. It saturated the local network with 1TB of metadata sniffing scans, not the network uplink to the outside world.

2. It does so because, as Keurig notes, it’s collecting data about your household in order to let Keurig sell it to advertisers.

lazide•1d ago
#1 - why? #2 - oh, because fucking yikes.
whycome•1d ago
Why is this allowed? There’s no way to consent to a coffee machine.
Neywiny•1d ago
Presumably during setup and connection to the AP it has a ToS. Doubtful they just unboxed, plugged in, and it connected to the right AP and went.
Citizen_Lame•21h ago
ToS can't trump the actual law.
preg_match•18h ago
The actual law is typically so weak and spineless that the ToS doesn't need to trump it. Particularly when it comes to data security or privacy.
advisedwang
tamimio•1d ago
Reminds me when couple years ago I plugged the TV to the internet (so my relatives kids can watch YT) and I forgot to unplug it for almost a week after, only to find the router dns resolved (and blocked) a million queries, all from that one TV!
altairprime•1d ago
The traffic generated here is network scans, not external traffic, and so blocking DNS wouldn’t have helped.
bombcar•19h ago
I love when it keeps checking some random DNS address, because who knows, with a TTL of 64000 it may just have changed in the last seven milliseconds!
rendall•1d ago
The GDPR consent form on this blog did not have a “Reject all” button. It required me to manually reject 16 instances of “legitimate interest,” then scroll through 1,746 vendors to make sure they were all set to reject.

Seems worth mentioning in a post about excessive and intrusive collection of user data. The moral outrage rings hollow when opting out of tracking is so deliberately onerous.

wafflemaker•23h ago
And also illegal. It's illegal not to have one button. Companies didn't do it because they suddenly stopped being scum.
ButlerianJihad•23h ago
A year or two ago, I was using NextDNS in ad-blocking and logging mode, which very helpfully exposed malware sitting on my very router, which had been completely undetectable, except for the veritable flood of bizarre DNS queries it was routinely sending to the self-configured DNS servers.

Now that I have a new router and I've re-enabled NextDNS, I've ironically discovered that the chief abuser of DNS right now is the router's own legit security software, which is absolutely hammering on the same query, several times a second.

Of course, since I am currently on NextDNS free tier, this matters a lot, because they cut you off after about 300,000 queries in a month. So any hammering abuse will make me lose my privileges much earlier than I would otherwise. So, to stop the abuse, should I shut off my legit security software? It is absolutely rubbish at identifying malware on the device itself...

matteoraso•23h ago
I honestly hate the IoT so much. Why should a coffee machine of all things use data? Just make the coffee.
anigbrowl•36m ago
I love IoT. It's the greedy corporations I hate. Everyone who implements this kinda abusive stuff, from the CEO down to the people building and installing the firmware, are scum.
robotnikman•21m ago
The shareholders as well.
goatlover•16m ago
What is the need for a coffeemaker on the internet?
ttytty•22h ago
It's so important to have a dedicated VLAN (or 2.4g SSID) for IoT devices and block access to your regular VLAN/SSID or enforce some more granular rules on what devices can communicate with each other.

Most non-ancient routers/gateways support this. There are way too many IoT devices running code that's _worse_ than what older LLMs produce.

pseudohadamard•6h ago
I have a firewall that tells me how much data each device is uploading and downloading. One particular device pulled down 6GB a week and uploaded 1.5GB doing absolutely nothing. I mean literally nothing, I use the local API to communicate with it. Blocking the one domain it was doing this to dropped traffic to essentially zero with no loss in functionality.
mindslight•4h ago
Of course by VLAN, I presume you mean one that doesn't have access to the Internet.

FWIW preventing the harm that happened here would seem to require a second set of APs (radios) on a different channel.

Levitating•19m ago
This is good advice but a simpler solution is to just not buy these things? Coffee machines don't need internet. Your thermostat doesn't either.
pjmorris•13m ago
My Bialetti Moka pot doesn't attempt to acquire an IP address.
ButlerianJihad•16h ago
Last year I had a big dispute with my ISP that was refusing to support or provide proper WiFi on their router, even while they touted a trademarked brand-name to do it. I ended up turning their router into Bridge Mode and purchasing a real router that could do WiFi. I did this extremely reluctantly, because every other personally-owned router had contracted malware.

After installing the new router (Netgear) my HP LaserJet began printing error pages. Like, I had done nothing to send anything to it, but a blank error page or three would pop out of it at very random times.

It took awhile to narrow down and diagnose this. But it turned out that the Netgear system had a very... proactive network malware detection system. It was red-team scanning my LAN for "vulnerabilities" or exploits or the presence of malware (I think just known vulns). It was a known side-effect of these scans, where it would tickle an RTSP TCP port of some kind and the HP printer would respond with its error printout.

I was so livid that the router was scanning the LAN, basically unbidden and completely undocumented. Even worse, they were not sharing the logs or results of that scan with the consumer. No, they were being sent back to the Netgear mothership, and their cybersecurity vendor overlords. So the scans were not designed to benefit me; they were simply designed to spy on everyone from a privileged vantage point. Now I ask you, why is a piece of kit that is supposed to be "yours" compiling secrets about your network, hiding them from you, and turning them over to, I guess a big database for hackers to leak in due time? This is not a question of "well, devices hooked up to a network should not be vulnerable" if the devices were contained in a private network, and 100% inaccessible from outside, and only attackers inside my perimeter could do these exploits in the first place.

Thankfully I found a way to disable this. Their "security" shitware is still spamming DNS and I may be forced to disable that as well. Meanwhile, routers 100% cannot self-introspect or self-diagnose and find their own malware. I've said it once; I'll say it again: consumer routers are the Achilles Heel to your network. They are ideal points of compromise for any actor to gain a foothold and pivot, or simply gain persistence undetected. Your ISP doesn't care, and your vendors don't care. Perhaps you should.

AngryData•12h ago
Wow that seems bonkers to me. Basically scanning and cataloging known vulnerabilities on the sly, and when anyone notices they pretend it is for your benefit somehow.

It would be like finding out ring cameras are taking pictures of your keys and calculating the pin set to producing duplicates and sending that pin set data off somewhere and when caught them being like "Uh, we are uhhh... doing it to make sure your key isn't too worn down or to detect if someone made a crude hand filed key. Yeah that's it!"

landgenoot•16h ago
Never assume malicious intent when incompetence.

I have multiple devices that queries their update server every 15 seconds, which all shows up as the top 10 queried domain in my network.

kps•20m ago
Sufficiently advanced incompetence is indistinguishable from malice.
mjburgess•9m ago
https://en.wikipedia.org/wiki/Plausible_deniability
GuB-42•3m ago
There is no way it is not incompetence.

Considering the computing power of these kinds of devices, it is most likely stuck inside an infinite loop sending garbage at full speed, there is not enough power to process that much volume in any maliciously useful way.

jason_s•15h ago
`C0FFEEEEEEEEEEEEEEEEEEEEE...`
a96•8h ago
418 I'm a teapot
lifeisstillgood•39m ago
Holy moly - 1,747 “partners” to share my data with. I mean, how can you even find 1747 data brokers? Where do you get that list. What does the JavaScript look like - I mean … this is getting ridiculous.

But at least the EU did me a solid. I really wanted to read that but I think 2000 data scumbags is not worth the effort.

All I need know is to realise bottlecaps must be recycled and federalism is good. Repeat in the mirror each morning

bitwize•34m ago
As another sign of the enshittified world we live in, the thing probably wasn't even RFC 2324 compliant.

https://datatracker.ietf.org/doc/html/rfc2324

Bruh should have set his PiHole to return HTTP 418 in response to any outbound request this thing made.

jttnr•7m ago
Maybe the coffee machine is subsidized by a residential botnet?
seb1204•4m ago
Really? And then complain about the energy cost? People are nutz. Like it's so unbearable to come home, open windows to get peak hot air out, then turn on AC and get cool. Energy is too cheap it seems. Also even very old AC remotes show there is usually the option to set up times etc.
•
16h ago
Ok, but it can collect consent
anigbrowl•39m ago
LOL

Legislators are cheap to purchase

pjmorris•14m ago
It is one thing to make a law, it is another to enforce a law.
egorfine•8h ago
> Doubtful they just unboxed, plugged in, and it connected to the right AP and went

Why not? iirc some of the smart TVs have been shown to find open wifi networks on their own and upload data. (I'm not sure about that though. But it's plausible and undoubtedly will be implemented some day).

criddell•31m ago
Maybe they bought it used?
black6•20h ago
It's implied consent when you give it access to your WiFi.

Why you would give a coffee maker access to your WiFi is the real question,

pfannkuchen•20h ago
So in other words, they were asking for it?
K0balt•18h ago
Well, yeah sorta since the only reason appliances connect to the internet is to steal data. I mean, if you buy a connected x that normally would not be connected, it’s 99 percent there to do nefarious stuff for its real owners. It’s like having a pet lion. Sure, it’s horribly irresponsible that someone sold you a pet lion, but. Uuuh you bought at pet lion. What did you think it was going to do?

Besides, did you see how he was dressed?

thatguy0900•6h ago
How does this analogy go when people buy a house kitten and it turns out they have been sold a lion cub? Most people simply do not have the tech literacy to understand that what they a are buying is actually a lion, they thought they were buying a coffeemaker with some cool features. It's difficult to blame the victim when they would need to spend hours trying to understand why the thing mapping out their local network is something that they should even care about
mindslight•6h ago
In the analogy, there is no such thing as a house kitten. They are all cute and cuddly lion cubs. Society needs to develop a deep awareness of this, in spite of the ocean of fraudulent advertising to the contrary. (individual-liberty-protecting regulation like the GDPR would be nice too, alas)
fwip•2h ago
Instead of a deep awareness, wouldn't it be easier to simply ban selling lions?
mindslight•2h ago
I think the two go hand in hand, unfortunately.
nicbou•18h ago
It's not allowed in the EU. Not without consent.
triceratops•27m ago
If you buy a Keurig machine you've already signalled you're a sucker. (sorry)
zikduruqe•18m ago
Laughs in Moccamaster.
spandrew•18m ago
This is the most Gilfoyle-coded comment of the day
triceratops•6m ago
I'll take that as a compliment!
AnimalMuppet•23h ago
To me, this is begging for a class-action lawsuit.

Yeah, sure, the terms of service probably say that they can do that. That's still in "unconscionable" territory. And courts do not like unconscionable contracts. If it's unconscionable, it's invalid (if I understand the law correctly).

Is this why everybody wants to make appliances with wireless?

altairprime•23h ago
Yes, this is why everybody wants to make vehicles and refrigerators and thermostats and ereaders with cellular and/or wireless: subscription revenue from bulk data purchasers of what their scans reveal. IIRC Amazon was an industry leader in this space by showing book authors what page you stopped reading on, and then bulk assessing that data at scale to estimate which sentence or word; of course, Google’s Android remains the most successful at-scale deployment of data collection for advertisers worldwide. See also, for recent context, the top comment (and others) of the LG Smart TV problem (30 days ago, 1012 comments) https://news.ycombinator.com/item?id=49592375
kotaKat•22h ago
Funny thing, that. Go into an electronics store now and pay attention to the TV boxes and the printer boxes. The amount of crazy fine print on both of them now is absurd. The printer boxes all now have lots of fine print about the various ink protection and DRM schemes and subscription services, the TV boxes have everything ranging from binding arbitration on the box (LG) to "(brand) accounts are REQUIRED to use this TV" (Visio).

Customers are gonna get lost in the sauce and skip right past all of that and toss the packaging.

seb1204•12m ago
Enshittyfication of everything
criddell•30m ago
You would have to show the judge how you have been harmed and the judge will want to know what the damages are.
rasz•21h ago
> as Keurig notes, it’s collecting data about your household in order to let Keurig sell it to advertisers.

its LGs glass in LG household, and now Keurigs kitchen

Grombobulous•19h ago
I don’t dispute the purpose of the data collection, but I can’t believe this quantity of data collection is intentional.

There’s no way Keurig is has the intention of paying the kind of costs required to collect a terabyte of data every two weeks for millions of people who own their coffee makers.

There must be some kind of bug here. I imagine if you unplugged it and plugged it in again the data usage would settle down.

mindslight•17h ago
Probes create much more traffic locally than it takes to backhaul a summary of their results.
sgillen•17h ago
1TB still smells like a bug
mindslight•4h ago
I was thinking that repeated small probes add up quicker than you'd expect. But this is ~1.1MB/sec, which still seems a few orders of magnitude off.

Now I'm left wondering what this traffic actually is - assuming probe (arp/icmp) packet size of 64 byte, that's 17kpps. I don't think an ESP32 class Internet-of-Trash chip can even do that. Even bulk transfers rather than small probes would be pushing it.

Perhaps this thing found some fellow-traveler device streaming video on a port it happened to connected to?

... the linked xit says it "broadcast 1TB of data". So maybe some protocol with a much larger packet than icmp, spammed in a hard loop without any delay?

didgetmaster•21m ago
As article says, the coffee machine didn't 'collect' or phone home a TB of data. It just saturated the local network looking for data to collect. This doesn't cost Keurig or any other IoT device company a single cent. It might have been a bug, or maybe not. Without some bad press, like this post; they have no incentive to change anything
MBCook•10m ago
Yeah but that can’t even be useful can it? What’s that going to find that only using 500 MB of probes wouldn’t have found?

Still seems buggy.

jimt1234•3m ago
One thing that confuses me is, well, at this point in the data collection game, is there still value in this 'local' data? I mean, everyone is doing it, collecting the same data - hasn't that decreased the value? Obviously not, but I still wonder.
KellyCriterion•10h ago
Reg 2:

But why do they need to collect 1 TB? Sounds like a lot of redundant/doublicated entries then for a small network?