// stories

671 stories · editorial analysis with viewpoints and sources

Healthcare.gov Shared Citizenship and Race Data With Ad Tech Giants

May 10

▸ US healthcare marketplace websites embedded tracking pixels that transmitted applicants' citizenship status, race, and income data to advertising plat...

Security / Privacy Politics / Regulation clear_take

Cloudflare Hands AI Agents the Keys to Infrastructure Provisioning

May 10

▸ Cloudflare now lets AI agents programmatically create accounts, purchase domains via Stripe, and deploy full applications — no human in the loop requi...

Cloud / Infrastructure AI / ML DevOps / Platform Engineering clear_take

LLMs Prefer Their Own Resumes — And That Breaks AI Hiring

May 10

▸ When LLMs screen resumes, they systematically prefer resumes generated by LLMs over equivalent human-written ones — even when qualifications are ident...

AI / ML Career / Industry clear_take

Mercury's 2M-Line Haskell Codebase Is a Stress Test for Typed FP at Scale

May 10

▸ Mercury, the fintech startup handling billions in deposits, runs one of the largest known production Haskell codebases at roughly 2 million lines.

Startups / Launches Backend / APIs Career / Industry explainer

Your AI Agent Doesn't Need a Better Prompt. It Needs an If Statement.

May 10

▸ The most reliable AI agents use traditional control flow (loops, conditionals, state machines) to orchestrate LLM calls — not longer or cleverer promp...

Backend / APIs AI / ML clear_take

EU Wants to Close the VPN 'Loophole' — Privacy Tools Are the Target

May 10

▸ The EU is framing VPN usage as a bypass mechanism that undermines its age verification mandates, signaling potential regulatory action against privacy...

Politics / Regulation Security / Privacy clear_take

Edge Keeps Every Saved Password in Cleartext RAM — Even Idle Ones

May 10

▸ Security researcher demonstrated that Microsoft Edge holds all saved passwords in plaintext in process memory, not just the one you're actively using.

Security / Privacy clear_take

AI Broke the Social Contract Behind Vulnerability Disclosure

May 10

▸ The two established vulnerability cultures — coordinated disclosure (report privately, wait for patch) and full disclosure (publish immediately to for...

AI / ML Security / Privacy multiple_viewpoints

Bun Is Ditching Zig for Rust — Here's Why It Was Inevitable

May 9

▸ Bun has begun porting its core from Zig to Rust, as evidenced by a commit in oven-sh/bun that's drawn 400+ upvotes on Hacker News.

Backend / APIs Open Source clear_take

Dirtyfrag: Another Universal Linux LPE Joins the Dirty Family

May 9

▸ A new universal Linux local privilege escalation vulnerability dubbed 'Dirtyfrag' was publicly disclosed on the oss-security mailing list on May 7, 20...

Cloud / Infrastructure DevOps / Platform Engineering Open Source breaking

VS Code Was Tagging Every Commit as Co-Authored by Copilot — Even Without It

May 9

▸ A merged VS Code PR changed the default setting to insert 'Co-Authored-By: GitHub Copilot' into every git commit, regardless of whether Copilot actual...

AI / ML Open Source DevOps / Platform Engineering clear_take

Apple Left Their AI Prompt Instructions in a Production App

May 9

▸ Apple accidentally shipped CLAUDE.md instruction files inside the Apple Support app, exposing how they integrate Anthropic's Claude into internal tool...

Security / Privacy AI / ML DevOps / Platform Engineering clear_take

A Central Bank Just Chose a Grocery Chain's Cloud Over AWS

May 9

▸ De Nederlandsche Bank (DNB) is migrating off AWS to STACKIT, a cloud platform built by Schwarz Group — the parent company of Lidl and Kaufland.

Cloud / Infrastructure Politics / Regulation Security / Privacy clear_take

PostgreSQL RCE via COPY FAIL: What CVE-2026-31431 Means for Your Stack

May 9

▸ CVE-2026-31431 exploits a flaw in PostgreSQL's COPY sub-protocol, where a malformed CopyFail message triggers memory corruption during the COPY state ...

Security / Privacy Open Source Backend / APIs breaking

Cloudflare Is Eating Itself: Why They're Rebuilding on Workers

May 9

▸ Cloudflare is migrating its own core services onto the Workers platform — dogfooding at infrastructure scale.

Cloud / Infrastructure Backend / APIs explainer

Google Is Quietly Bricking the 'Open' in Open Source Android

May 9

▸ The Keep Android Open campaign is rallying developers against Google's accelerating lockdown of Android via Play Integrity API enforcement and sideloa...

Security / Privacy Open Source Politics / Regulation clear_take

GitHub Copilot Kills Flat-Rate Pricing — What Your Bill Actually Looks Like Now

May 9

▸ GitHub is replacing Copilot's $10/month individual and $19/month business flat-rate plans with a usage-based model that meters premium model requests ...

Career / Industry AI / ML DevOps / Platform Engineering clear_take

Ghostty Leaves GitHub: When 25K Stars Aren't Enough to Stay

May 9

▸ Mitchell Hashimoto is migrating Ghostty — one of the most-starred terminal emulators on GitHub — to a self-hosted forge, citing platform limitations t...

Open Source DevOps / Platform Engineering clear_take

Async Rust at 6: The Code Patterns That Still Break

May 8

▸ Tweede Golf's viral post (352 HN points) catalogs the async features Rust still hasn't shipped — but the real story is in the workarounds production t...

Backend / APIs Open Source multiple_viewpoints

Malicious 'Shai-Hulud' Package Found Hiding in PyTorch Lightning's Dependency Tree

May 8

▸ Semgrep researchers discovered a malicious dependency in the PyTorch Lightning AI training library, themed after Dune's sandworms ('Shai-Hulud').

Open Source AI / ML Security / Privacy breaking
← newer page 6 of 34 older →