// stories

671 stories · editorial analysis with viewpoints and sources

GitHub: 3,800 repos exfiltrated by a single malicious VSCode extension

May 21

▸ GitHub confirmed that a single malicious VSCode extension exfiltrated source code and tokens from 3,800 repositories before being pulled.

Security / Privacy DevOps / Platform Engineering clear_take

SpaceX's S-1: Starlink is the business, rockets are the marketing

May 21

▸ SpaceX filed its S-1 with the SEC, the first time outsiders get audited numbers instead of leaked decks.

Startups / Launches Cloud / Infrastructure clear_take

OpenAI's model just killed a 40-year geometry conjecture

May 21

▸ An OpenAI reasoning model produced a constructive counterexample to a long-standing conjecture in discrete geometry, not just a proof sketch.

AI / ML Open Source clear_take

Bun's Rust Rewrite Fails Miri: Undefined Behavior Found in Safe Code

May 21

▸ Bun's ongoing Rust rewrite has been flagged for failing basic Miri checks, meaning the codebase contains undefined behavior even in code marked as saf...

Backend / APIs Open Source multiple_viewpoints

GitLab Kills Its CREDIT Values and Cuts Staff. Culture Debt Comes Due.

May 21

▸ GitLab announced a workforce reduction alongside the retirement of its CREDIT values — the six cultural pillars (Collaboration, Results, Efficiency, D...

Career / Industry DevOps / Platform Engineering clear_take

Mitchell Hashimoto: Entire Companies Are Now Under 'AI Psychosis'

May 21

▸ HashiCorp co-founder Mitchell Hashimoto claims entire companies are now operating under 'AI psychosis' — making irrational organizational decisions dr...

AI / ML Career / Industry clear_take

Every App Wants to Be Emacs Now. That's Not a Compliment.

May 21

▸ Thomas Ptacek argues that modern software is converging on the Emacs pattern: extensible platforms that absorb adjacent functionality until they becom...

DevOps / Platform Engineering Career / Industry Open Source clear_take

MIT Loses 20% of Incoming Grad Students. The Talent Pipeline Is Breaking.

May 21

▸ MIT President Sally Kornbluth disclosed a 20% drop in incoming graduate students, driven by federal research funding cuts and an increasingly hostile ...

AI / ML Career / Industry Politics / Regulation clear_take

Flipper One specs land: it's a pocket Kali box, not a Zero upgrade

May 21

▸ Flipper Devices published the Flipper One tech specs — a Linux-based SBC with integrated WiFi monitor mode, Sub-GHz, NFC, and an FPGA, in a Game Boy f...

Hardware / Chips Security / Privacy clear_take

SpiderMonkey is killing the asm.js optimizer. WebAssembly won.

May 21

▸ Mozilla is removing SpiderMonkey's dedicated asm.js AOT compiler — the code that proved JS could be a compile target and birthed WebAssembly.

Frontend / UI Open Source explainer

Your Mullvad Exit IP Is More Unique Than You Think

May 20

▸ A researcher found that many Mullvad VPN servers have small enough anonymity sets that exit IPs alone can re-identify returning users across sessions.

Security / Privacy Open Source explainer

Antirez Unveils DS4: What Comes After You Build Redis

May 20

▸ Antirez, the creator of Redis, has published his first detailed look at DS4 — a new data structure server that rethinks the ideas Redis was built on.

Open Source Backend / APIs explainer

A Fields Medalist Stress-Tests ChatGPT 5.5 Pro — and the Results Are Complicated

May 20

▸ Timothy Gowers, Fields Medal winner, published a detailed evaluation of ChatGPT 5.5 Pro on research-level mathematical problems — drawing massive atte...

AI / ML Career / Industry clear_take

Debian Finally Makes Reproducible Builds Non-Negotiable

May 20

▸ Debian's debian-devel-announce post declares that all packages must be reproducible — elevating a decade-old 'should' to a hard 'must' for release inc...

Security / Privacy DevOps / Platform Engineering Open Source clear_take

npm's Supply Chain Problem Isn't a Mystery. It's a Choice.

May 20

▸ npm averages roughly one high-profile supply chain compromise per quarter — a cadence no other major package ecosystem matches.

Security / Privacy Open Source clear_take

DOJ Wants 100K App Users Doxxed Over Car Mods. App Stores Are the Weak Link.

May 20

▸ The U.S. Department of Justice issued legal demands to Apple and Google to identify over 100,000 users who downloaded a car ECU-tuning app, as part of...

Politics / Regulation Security / Privacy clear_take

AI Is a Technology, Not a Product — and That Changes Everything

May 20

▸ John Gruber argues that AI, like the internet before it, is a technology layer that enhances existing products — not a product category you sell direc...

AI / ML Startups / Launches Career / Industry clear_take

Hardware Attestation Doesn't Verify Security. It Verifies Obedience.

May 20

▸ Hardware attestation on Android checks whether your OS is Google-approved, not whether it's actually secure — a fully-patched GrapheneOS device fails ...

Security / Privacy Politics / Regulation Open Source clear_take

A Security Engineer Ripped the Modem Out of His RAV4. Here's Why.

May 20

▸ Security engineer Arkadiy Tetelman documented the full teardown process for removing the DCM (Data Communication Module) and GPS antenna from a 2024 R...

Hardware / Chips Security / Privacy explainer

Pixel 10 Hit by Full 0-Click Exploit Chain — What Devs Need to Know

May 20

▸ Google Project Zero published a full 0-click exploit chain targeting the Pixel 10, requiring zero user interaction to achieve remote code execution.

Security / Privacy Hardware / Chips explainer
page 1 of 34 older →