// stories

671 stories · editorial analysis with viewpoints and sources

TanStack Supply-Chain Attack Hit 42 npm Packages via GitHub Actions Exploit

May 18

▸ An attacker chained a pull_request_target exploit, GitHub Actions cache poisoning, and OIDC token extraction to publish 84 malicious versions across 4...

Security / Privacy Open Source DevOps / Platform Engineering breaking

Bun's Rust Rewrite Has Undefined Behavior in Safe Code. That's a Problem.

May 18

▸ A GitHub issue (oven-sh/bun#30719, 317+ HN points) documents that Bun's new Rust codebase fails basic miri checks and contains undefined behavior in c...

Security / Privacy Open Source Backend / APIs clear_take

The Hand-Written Code Backlash: Why Some Devs Are Ditching AI

May 18

▸ A blog post arguing for abandoning AI coding tools hit 737 points on HN, signaling growing practitioner disillusionment with AI-assisted development.

Career / Industry AI / ML multiple_viewpoints

A Suicide Prevention Site Was Leaking Visitor Data to Ad Tech

May 18

▸ Dutch suicide prevention service 113 Zelfmoordpreventie was found sharing website visitor data with tech companies without user consent.

Politics / Regulation Security / Privacy clear_take

Nvidia Just Made Rust a First-Class GPU Language

May 18

▸ Nvidia's cuda-oxide compiles standard Rust directly to PTX — no DSLs, no C++ bindings, no CUDA C required.

Hardware / Chips Open Source explainer

Debian Just Made Reproducible Builds Mandatory. Here's What Breaks.

May 18

▸ Debian's debian-devel-announce post formally requires all packages to be reproducibly buildable — upgrading from 'should' to 'must' in Debian Policy.

Security / Privacy DevOps / Platform Engineering Open Source clear_take

DOJ Wants Names of 100K Car Tuners — Your App Store Data Is the Warrant

May 18

▸ The U.S. Department of Justice has demanded Apple and Google identify over 100,000 users who downloaded a car-tuning app suspected of enabling emissio...

Security / Privacy Politics / Regulation clear_take

Bambu Lab Sues an Open-Source Slicer Dev. The 3D Printing Community Is Done.

May 18

▸ Bambu Lab is pursuing legal action against an OrcaSlicer developer, prompting right-to-repair advocate Louis Rossmann to publicly denounce the company...

Politics / Regulation Hardware / Chips Open Source clear_take

Canada's Bill C-22: Same Surveillance Bill, New Number

May 18

▸ Canada's Bill C-22 reintroduces the core surveillance powers from the failed Bill C-26, granting the government authority to secretly order telecom pr...

Politics / Regulation Security / Privacy clear_take

The SWE Career Contraction Is Already Measurable — Here's What the Numbers Say

May 18

▸ Software engineering job postings have dropped ~33% from their 2022 peak, junior roles hit hardest — this isn't a prediction, it's a trend with receip...

Career / Industry AI / ML multiple_viewpoints

France Wants Backdoors in Signal and WhatsApp. Here's Why It Won't Work.

May 17

▸ France is advancing legislation that would require messaging platforms to provide law enforcement access to encrypted communications, effectively mand...

Politics / Regulation Security / Privacy clear_take

Bambu Lab Took From Open Source, Then Locked the Door Behind Them

May 17

▸ Jeff Geerling documents how Bambu Lab built its 3D printer empire on GPL-licensed projects like Klipper, Marlin, and PrusaSlicer — then systematically...

Politics / Regulation Hardware / Chips Open Source clear_take

MIT Loses 20% of Incoming Grad Students. The Talent Pipeline Is Breaking.

May 17

▸ MIT President Sally Kornbluth disclosed a 20% decline in incoming graduate students, driven by federal funding cuts and chilling effects on internatio...

AI / ML Politics / Regulation Career / Industry clear_take

A Security Researcher Ripped the Modem Out of His RAV4. Here's How.

May 17

▸ Security researcher arkadiyt published a step-by-step guide to physically removing the cellular modem (DCM) and GPS module from a 2024 Toyota RAV4 Hyb...

Security / Privacy Hardware / Chips explainer

Meta Kills Instagram DM Encryption — What It Means for Your App's E2EE Strategy

May 17

▸ Meta is removing end-to-end encryption from Instagram direct messages, reversing a feature it spent years building and rolling out.

Security / Privacy Politics / Regulation clear_take

Europe's Gov Sites Are a Security Disaster: The Numbers Are Brutal

May 17

▸ The Internet Cleanup Foundation scanned European government domains and found ~3,000 sites with third-party trackers, ~1,000 exposed phpMyAdmin panels...

Politics / Regulation Security / Privacy Defense / GovTech clear_take

Six New CVEs Hit dnsmasq — Patch Your DNS Infrastructure Now

May 17

▸ CERT/CC is coordinating disclosure of six CVEs targeting dnsmasq, the lightweight DNS/DHCP server embedded in millions of routers, containers, and Lin...

DevOps / Platform Engineering Security / Privacy Cloud / Infrastructure breaking

What Gowers' ChatGPT 5.5 Pro Test Actually Reveals About LLM Reasoning

May 17

▸ Fields Medalist Timothy Gowers published a detailed account of testing ChatGPT 5.5 Pro on mathematical problems, finding the model impressive on surfa...

Career / Industry AI / ML clear_take

The Wayback Machine Is Under Threat. Developers Should Care.

May 17

▸ A grassroots campaign at savethearchive.com is pressuring the NYT, The Atlantic, and USA Today to stop legal actions that threaten the Wayback Machine...

Politics / Regulation Open Source clear_take

The Curl Maintainer Who Called AI Bug Reports Garbage Just Got Proven Wrong

May 17

▸ Mythos, an AI vulnerability-hunting tool, found a legitimate security flaw in curl — notable because curl maintainer Daniel Stenberg has been one of t...

Security / Privacy AI / ML Open Source clear_take
← newer page 2 of 34 older →