HN ReaderReader

Roundcube Webmail: SVG feImage bypasses image blocking to track email opens
nullcathedral.com

_NULL - Roundcube's HTML sanitizer doesn't treat SVG feImage href as an image source. Attackers can bypass remote image blocking to track email opens.

The Little Bool of Doom (2025)
blog.svgames.pl

A short story about debugging and how sometimes what's true is false. Starring everyone's favourite uncle, Undefined Behaviour.

Bun v1.3.9
bun.com

Fixes 23 issues (addressing 13 👍). Run multiple scripts in --parallel or --sequential. bun:test mock & spyOn get Symbol.dispose support. ESM bytecode compilation. Faster Bun.markdown. Faster RegExp, String.prototype.trim, String.prototype.startsWith.

The First Sodium-Ion Battery EV Is a Winter Range Monster
insideevs.com
Let's compile Quake like it's 1997
fabiensanglard.net
Show HN: I created a Mars colony RPG based on Kim Stanley Robinson's Mars books
underhillgame.com
show
Billing can be bypassed using a combo of subagents with an agent definition
github.com/microsoft

Summary It's possible in Copilot to bypass any billing / 'premium request' usage by taking advantage of: Subagents and tool calls not consuming any 'requests'. Request cost being calculated on the ...

Omega-3 is inversely related to risk of early-onset dementia
pubmed.ncbi.nlm.nih.gov

This study expands the evidence of a beneficial association of omega-3 and LOD to EOD as well. These findings suggest that an increased intake of omega-3 fatty acids earlier in life may slow the development of EOD. Additional research is needed to confirm our findings, particularly in more diverse p …

Vouch
github.com/mitchellh

A contributor trust management system based on explicit vouches to participate. - mitchellh/vouch

I put a real-time 3D shader on the Game Boy Color
blog.otterstack.com
Five disciplines discovered the same math independently
freethemath.org

Bruce Stephenson - The same math predicts market crashes, power grid blackouts, and cardiac failures. At least six fields discovered it independently. Most didn't know about each other.

Noam Chomsky's wife responds to Epstein controversy
aaronmate.net

Aaron Maté - "Noam’s overly trusting nature, in this specific case, led to severe poor judgment on both our parts... we express our unrestricted solidarity with the victims."

Washington imposes 'terrorist-grade sanctions' on Francesca Albanese, ICC judges
thecradle.co

US tech companies requested that Washington impose sanctions after the UN rights official sent 'threatening letters' warning them of complicity in the genocide in Gaza

Exploiting signed bootloaders to circumvent UEFI Secure Boot
habr.com

Русская версия этой статьи. Modern PC motherboards' firmware follow UEFI specification since 2010. In 2013, a new technology called Secure Boot appeared, intended to prevent bootkits from being...

RFC 3092 – Etymology of "Foo" (2001)
datatracker.ietf.org

Approximately 212 RFCs so far, starting with RFC 269, contain the terms `foo', `bar', or `foobar' as metasyntactic variables without any proper explanation or definition. This document rectifies that deficiency. This memo provides information for the Internet community.

AI fatigue is real and nobody talks about it
siddhantkhare.com

Siddhant Khare - You're using AI to be more productive. So why are you more exhausted than ever? The paradox every engineer needs to confront.

I am happier writing code by hand
abhinavomprakash.com

Abhinav Omprakash - I felt the familiar feeling of depression and lethargy creep in while my eyes darted from watching claude-code work and my phone. “What’s the point of it all?” I thought, LLMs can generate decent-ish and correct-ish looking code while I have more time to do what? doomscroll? This was the third time I gave claude-code a try. I felt the same feelings every single time and ended up deleting claude-code after 2-3 weeks,

Running Your Own As: BGP on FreeBSD with FRR, GRE Tunnels, and Policy Routing
blog.hofstede.it
Bitcoin tumbles below $70K, heavy losses in cryptocurrencies in last three weeks
bloomberg.com

Bitcoin tumbled below $61,000, as the unwinding of leveraged bets and broader market turbulence deepened a selloff that has wiped out all of the gains since President Donald Trump’s election set off a speculative rush into cryptocurrencies.

GitHub Agentic Workflows
github.github.io

Automated repository agents running in GitHub Actions.

Show HN: Fine-tuned Qwen2.5-7B on 100 films for probabilistic story graphs
cinegraphs.ai
show
Dave Farber has died
lists.nanog.org
Why E cores make Apple silicon fast
eclecticlight.co

Apple silicon architecture is designed to get background processes out of the way of our apps running in the foreground, by using the E cores.

OpenAI exec becomes top Trump donor with $25M gift
finance.yahoo.com
Slop Terrifies Me
ezhik.jp

What if this is as good as software is ever going to be? What if AI stops getting better and what if people stop caring?

Curating a Show on My Ineffable Mother, Ursula K. Le Guin
hyperallergic.com

I would never have proposed this exhibition in her lifetime. This is, after all, a writer who said in an interview, “Don’t shove me into your damn pigeonhole, where I don’t fit, because I’m all over.”

In the Australian outback, we're listening for nuclear tests
abc.net.au

As the New START treaty curbing the US and Russian nuclear weapons programs expires, the work we do here in the red centre has become more important than ever before.

Reverse Engineering Raiders of the Lost Ark for the Atari 2600
github.com/joshuanwalker

Reverse Engineering Raiders of the Lost Ark for the Atari 2600 - joshuanwalker/Raiders2600

Matchlock – Secures AI agent workloads with a Linux-based sandbox
github.com/jingkaihe

Matchlock secures AI agent workloads with a Linux-based sandbox. - jingkaihe/matchlock

DoNotNotify is now Open Source
donotnotify.com
The world heard JD Vance being booed at the Olympics. Except for viewers in USA
theguardian.com

The real risk for American broadcasters is not that dissent will be visible. It is that audiences will start assuming anything they do not show is being hidden

OpenClaw is changing my life
reorx.com

Reorx - I want to share some thoughts on my recent experience with OpenClaw. Over the past year, I’ve been actively using Claude Code for development. Many people believed AI could already assist with programming—seemingly replacing programmers—but I never felt it brought any revolutionary change to the way I work. Sure, agentic coding tools like Claude Code and Cursor have made writing code easier, but at the end of the day

LineageOS 23.2
lineageos.org

LineageOS - Material Expressive is here!

Roger Ebert Reviews "The Shawshank Redemption" (1999)
rogerebert.com
Substack confirms data breach affects users’ email addresses and phone numbers
techcrunch.com

Ivan Mehta - Substack said that customer data was accessed in October 2025 but wasn't discovered until early February.

Homeland Security Spying on Reddit Users
kenklippenstein.com

Ken Klippenstein - Leak show feds tracking anti-ICE Reddit users like "Budget-Chicken-2425"

Bye Bye Humanity: The Potential AMOC Collapse
thatjoescott.com

Jeff Espiritu - It’s been talked about for a while (in fact I covered this 6 years ago), but a lot of things have been said about the potential collapse of the Atlantic Gulf Stream, also known as the Atlantic Meridional Overturning Circulation or AMOC. This global current that keeps Europe and North America (but especially Europe) from being covered in ice is increasingly under threat of slowing or even stopping. The results would b

Vouch
github.com/mitchellh
Beyond agentic coding
haskellforall.com

AI dev tooling can do better than chat interfaces

Show HN: LocalGPT – A local-first AI assistant in Rust with persistent memory
github.com/localgpt-app
show

Contribute to localgpt-app/localgpt development by creating an account on GitHub.

Washington Post CEO Will Lewis Steps Down After Stormy Tenure
nytimes.com
The silent death of good code
amit.prasad.me
FDA intends to take action against non-FDA-approved GLP-1 drugs
fda.gov
You Are Here
brooker.co.za
Tiny C Compiler
bellard.org
Italy Railways Sabotaged
bbc.co.uk

Police say they are investigating three incidents targeting rail infrastructure that caused travel delays.

Microsoft account bugs locked me out of Notepad – Are thin clients ruining PCs?
windowscentral.com

Could a 'Thin Client' era of Windows 11 ruin my 27 blissful years of using PCs? Losing access to basic apps definitely made it feel that way.

Brookhaven Lab's RHIC concludes 25-year run with final collisions
hpcwire.com

Milestone caps a quarter century of groundbreaking discoveries — with more to come from final run’s largest-ever dataset — plus technological advances in accelerators, detectors, and computing UPTON, N.Y., Feb. 6, 2026 — Just after 9 a.m. on Friday, Feb. 6, 2026, final beams of oxygen ions — oxygen atoms stripped of their electrons — […]

We mourn our craft
nolanlawson.com

I didn’t ask for this and neither did you. I didn’t ask for a robot to consume every blog post and piece of code I ever wrote and parrot it back so that some hack could make money off o…

NSA detected phone call between foreign intelligence and person close to Trump
theguardian.com

Whistleblower says that Tulsi Gabbard blocked agency from sharing report and delivered it to White House chief of staff

Speed up responses with fast mode
code.claude.com

Get faster Opus 4.6 responses in Claude Code by toggling fast mode.

MS-DOS game copy protection and cracks
dosdays.co.uk
Epstein took a photo of his 2015 dinner with Zuckerberg and Musk
xcancel.com
Reverse-Engineering Raiders of the Lost Ark for the Atari 2600
github.com/joshuanwalker

Reverse Engineering Raiders of the Lost Ark for the Atari 2600 - joshuanwalker/Raiders2600

Show HN: I saw this cool navigation reveal, so I made a simple HTML+CSS version
github.com/Momciloo
show

Contribute to Momciloo/fun-with-clip-path development by creating an account on GitHub.

I write games in C (yes, C) (2016)
jonathanwhiting.com
SectorC: A C Compiler in 512 bytes (2023)
xorvoid.com
U.S. jobs disappear at fastest January pace since great recession
forbes.com
Google Translate apparently vulnerable to prompt injection
lesswrong.com

tl;dr Argumate on Tumblr found you can sometimes access the base model behind Google Translate via prompt injection. The result replicates for me, an…

British drivers over 70 to face eye tests every three years
bbc.com

The move is part of the government's new road safety strategy, which plans to reform driving laws in Britain.

Al Lowe on model trains, funny deaths and working with Disney
spillhistorie.no

Roar Granevang - You know he did other things than Larry, right?

StrongDM's AI team build serious software without even looking at the code
simonwillison.net

Simon Willison - Last week I hinted at a demo I had seen from a team implementing what Dan Shapiro called the Dark Factory level of AI adoption, where no human even looks …

First Proof
arxiv.org

To assess the ability of current AI systems to correctly answer research-level mathematics questions, we share a set of ten math questions which have arisen naturally in the research process of the authors. The questions had not been shared publicly until now; the answers are known to the authors of the questions but will remain encrypted for a short time.

Google staff call for firm to cut ties with ICE
bbc.com

More than 900 Google employees signed a letter opposing company links to federal immigration actions.

Software factories and the agentic moment
factory.strongdm.ai

StrongDM's field notes on non-interactive agentic development: specs + scenarios, validation harnesses, feedback loops, and the supporting components.

Stories from 25 Years of Software Development
susam.net
France's homegrown open source online office suite
github.com/suitenumerique

La Suite numérique is a set of open-source applications for digital collaboration and teamwork. It offers modern solutions for the digital workplace. - La Suite numérique

Coding agents have replaced every framework I used
blog.alaindichiappari.dev

Alain - Coding agents have replaced every framework I used

Reinforcement Learning from Human Feedback
rlhfbook.com

Reinforcement learning from human feedback (RLHF) has become an important technical and storytelling tool to deploy the latest machine learning systems. In this book, we hope to give a gentle introduction to the core methods for people with some level of quantitative background. The book starts with the origins of RLHF -- both in recent literature and in a convergence of disparate fields of science in economics, phil

Hoot: Scheme on WebAssembly
spritely.institute
Big Tech's AI Push Is Costing More Than the Moon Landing
wsj.com
The AI boom is causing shortages everywhere else
washingtonpost.com
Claude Code Is the Inflection Point
newsletter.semianalysis.com

Doug O'Laughlin - What It Is, How We Use It, Industry Repercussions, Microsoft's Dilemma, Why Anthropic Is Winning

UK infants ill after drinking contaminated baby formula of Nestle and Danone
bbc.com

It comes after some batches made by Nestle and Danone were recalled after being contaminated with a toxin.

Vocal Guide – belt sing without killing yourself
jesperordrup.github.io

Jesper Ordrup - A vocal technique reference covering 21 techniques: registers, styles, effects, embellish, and dynamics.

"The Stanford scam proves America is becoming a nation of grifters"
thetimes.com

Rob Henderson - Students at one of the country’s elite colleges are victimising themselves to get ahead. It’s a cautionary tale for our age

Hello world does not compile
github.com/anthropics

Tested inside fedora 43 container, ubuntu 26.04 container and on regular fedora 42 installation, same error Took example directly from README.md GCC is present and can compile code just fine: root:...

Female Asian Elephant Calf Born at the Smithsonian National Zoo
si.edu
Why I Joined OpenAI
brendangregg.com
Bash scripts are brittle – simple error handling in bash
notifox.com

Notifox - Most bash scripts are very brittle because error handling is an afterthought. In this blogpost you'll learn about the easiest ways to gracefully catch and handle errors. Best practices and common pitfalls.

WebView performance significantly slower than PWA
issues.chromium.org
I'm going to cure my girlfriend's brain tumor
andrewjrod.substack.com

Andrew - Launch of an experiment to use AI-Scientists to accelerate research of a "solved" disease.

Epstein arranged a meeting between highest-level Russian spy and Peter Thiel
bsky.app/profile/robertscotthorton.bsky.social

This is an immensely significant document that continues to get virtually no attention in US media—but lots abroad. In Jul 2015, Epstein arranged a meeting between a known highest-level Russian intel operative, Sergey Belyakov and Peter Thiel,

Introducing the Developer Knowledge API and MCP Server
developers.googleblog.com
Ask HN: Non AI-obsessed tech forums
news.ycombinator.com
ask
Show HN: R3forth, a ColorForth-inspired language with a tiny VM
github.com/phreda4
show

r3 programing language - ColorForth inspired. Contribute to phreda4/r3 development by creating an account on GitHub.

Early Christian Writings
earlychristianwritings.com
OpenCiv3: Open-source, cross-platform reimagining of Civilization III
openciv3.org

OpenCiv3 is an open-source, cross-platform, mod-oriented, modernized remake of Civilization III by the fan community built with the Godot Engine and C#, with capabilities inspired by the best of the 4X genre and lessons learned from modding Civ3.

Show HN: Look Ma, No Linux: Shell, App Installer, Vi, Cc on ESP32-S3 / BreezyBox
github.com/valdanylchuk
show

BreezyBox shell demo for esp32s3. Contribute to valdanylchuk/breezydemo development by creating an account on GitHub.

Oregon raised spending by 80%, math scores dropped
educationnext.org

Tim Daly - It was the worst of times

Monty: A minimal, secure Python interpreter written in Rust for use by AI
github.com/pydantic

A minimal, secure Python interpreter written in Rust for use by AI - pydantic/monty

Waymo exec admits remote operators in Philippines help guide US robotaxis
eletric-vehicles.com

Cláudio Afonso - Waymo’s Chief Safety Officer disclosed Wednesday that some of the remote operators who assist its self-driving vehicles in navigating difficult scenarios are based in the Philippines.

Tell HN: I'm a PM at a big system of record SaaS. We're cooked
news.ycombinator.com
ask
Show HN: I spent 4 years building a UI design tool with only the features I use
vecti.com
show
Man who videotaped himself BASE jumping in Yosemite arrested, says it was AI
latimes.com

A California man is facing a criminal charge for allegedly BASE jumping off Glacier Point in Yosemite National Park during the federal government shutdown last year.

Show HN: If you lose your memory, how to regain access to your computer?
eljojo.github.io
show

An offline tool that encrypts files and splits the decryption key among trusted friends using Shamir's Secret Sharing. Open source.

How to effectively write quality code with AI
heidenstedt.org

AI is rarely optional anymore, but how can you still be proud of your craft? Discover the workflow to effectively write high-quality, robust code using AI tools.

Uber Found Liable in Rape by Driver, Setting Stage for Cases
nytimes.com
Fraud investigation is believing your lying eyes
bitsaboutmoney.com

The financial industry has paid tens of billions of dollars in tuition on fraud detection. Here are some observations for investigators with badges, press cards, or GoPros.

Trump shares video with racist clip depicting Obamas as apes
bbc.co.uk

The White House defended the post at first, calling to "stop the fake outrage", as members of both parties condemned the video.

Preferences (coming soon)

Stories Count
100
total stories returned
Median
120
story points
Mean
167
avg story points