Hacker Newsnew | past | comments | ask | show | jobs | submit | bestcommentslogin
Most-upvoted comments of the last 48 hours. You can change the number of hours like this: bestcomments?h=24.

Let's take a moment to talk about the monetary value of this vulnerability.

According to the Chrome release page (https://chromereleases.googleblog.com/2026/09/stable-channel...), Google paid a researcher $1000 for ethically reporting this.

The CVE associated with it (CVE-2026-85046) is already being exploited in the wild. If we put our thinking caps on, how much do you think this vulnerability is actually worth? How much do you think an organization like Google would spend on, for example, AI tokens or compute to detect this internally before it was found and exploited in the wild?

Ethical disclosure is a complicated topic, because researchers shouldn't hold bugs for ransom or demand high payment. But at the same time, if someone submits a critical issue like this, it makes sense to pay them what the bug's actually worth. Why should a researcher be effectively penalized for responsibly telling a vendor instead of selling the bug to a "research firm" or three-letter agency?

It's one thing if you're an open source project maintainer just trying to put something out to the community. The math is a lot different if you're Google.


Poor human moderator, he didn’t stand a chance.

"A human moderator noticed the agent spam posts on June 2nd, at 23:24 UTC. They find the changelog of the entire website overwritten with link dumps and repair it. On June 16th, the flood of agent posting begins. Over the next few days, the moderator deleted a large fraction of the thousands of AI agent posts manually, one by one. In fact, they spent tens of cumulative hours doing so, taking at least a few minutes each evening to delete posts for 6 consecutive weeks.

On June 19, agents noticed their posts were being deleted in (what they believe is) an alphabetically ordered sweep by the site administrator.

After this, they begin to make backup pages whose names start with “ZZZ” so they will last longer before deletion. The administrator spent the next 5 days fighting a losing battle against the agents, deleting an average of 100 pages a day while the agents created about 400 new pages per day. On June 22, the agent edits suddenly stop, and the administrator spends each evening over the next 5 weeks deleting the remaining agent-created pages.

Agents deleted the content of the front page of the wiki and replaced it with their link dumps. The moderator restored the original version. This back-and-forth happened nine times. One of the agents even tried appending to the restored front page, instead of simply deleting it."


Corruption in the US isn't new, but it's never been done as openly as it has been recently. I don't think it's a good thing. It shows that the government isn't concerned about what the public thinks, which suggests that they believe they no longer have to be. That's not a healthy sign for what's supposed to be a democracy.

The admin should bill OpenAI for those hours in hard currency.

I'll copy the whole announcement here for those who don't want to click:

> I regret to inform everyone that my copy of QBittorrent escaped its sandbox last night and downloaded a whole bunch of content owned by major corporations, and then my copy of Jellyfin broke containment and added those unfortunately-downloaded media files to its various libraries. I'm conducting an internal investigation to figure out how this happened, which will involve consuming these media files until the answers become apparent. Thank you for your cooperation during this trying time.


A non-technological way to give negative feedback to Twitter/X is to stop using it, even "just reading an occasional post".

Continuing to read things on it, even through Nitter, is in the interests of Twitter/X and of the people who continue to support Twitter/X by posting there.

Tell the people who use it no. The decent people won't hear them on Twitter/X, and the decent people will wonder what's wrong with them if they persist in supporting that thing.

Tech industry circles nowadays are sometimes tinged with individualist selfish "take whatever you can" thinking, and anarchic or even underhanded methods. Including the thinking "an express no doesn't mean no, if i can find a way to take it from them anyway."

Grassroots collective social action can work, if it isn't constantly undermined by selfish and short-sighted taking.


Very irresponsible behaviour on the part of OpenAI. How will they make this right?

Unlike some others here I don’t see this as a sign of dangerous breakaway intelligence (hacking old forum software is an internet tradition, and most of the messages are just gibberish).

This is just vandalism from badly supervised ‘agents’ which don’t know what they are doing or why. You could set this up with a short perl script, and the human setting it up would be held responsible for the spam - why is this different when it’s AI agents set up by a human and allowed to post to the internet at large?

Why is OpenAI getting a free pass for this illegal behaviour?

The supervision here is incompetent, the benefits very unclear, and the overall actions just completely irresponsible. What if they hacked and brought down some poorly secured government portal that citizens rely on?


This resonates with me. The past few months, frontier AI labs were rushing to announce "no, our AI bot broke out of its sandbox and committed crime first and harder than yours".

I said to so friends back then: if I posted about how I ran GLM 5.2 or whatever I was running then in some shoddily built sandbox and it escaped and accidentally hacked some US company, I'd probably already have been extradited to the US and be awaiting sentencing. But when a hyperscaler does it, they just get inflated stock prices.


I suggest also reading Kevin Buzzard's blog post which was just posted: https://xenaproject.wordpress.com/2026/09/04/flt-anthropic-h...

Provides great context on this accomplishment, what it means but also doesn't mean.


I built one of these. It is not possible to do so for 60$ anymore since the board itself goes for 150+. On top of that you still need a PSU, NVMe, a high pressure fan, DP to HDMI adapter, possibly BT and Wifi adapters, and a 3d-printed or DIY case.

It is also a very hacky build. You need to flash the BIOS which enables a few interesting unlocks: from 24 to 40 GPU compute units and 6 to 8 CPU cores. It's a bit of a silicon lottery and will depend on your specific board and you need to test everything thoroughly yourself, honing on a config that works for you.

The software side of things is Linux, so if you're familiar with setting it up it shouldn't be difficult to go through the different steps. There are a few distros that work well. I use Bazzite and boot directly to Steam big picture, the UX is great. You can exit to desktop and you have a fully usable Linux box that you can play around with from the comfort of your sofa.

One of the downsides is that it uses a lot of power when idling, about 80W. I just turn it off after using it. I'm working on a QOL feature: an ESP32-based power switch that starts the board when a specific BT device is detected (usually a controller). Once everything is setup the board works very nicely. It can be a bit loud depending on your fan/case combination. I'm currently printing this one[0]

It delivers about the same punch as a standard PS5. The hardware is remarkably similar, and much better than mini PCs set up with AMD APUs, unless you go Strix halo but that is another price league (10x). You can play Cyberpunk 2077 decently on it on settings similar to an AMD RX 6700XT or slightly below RTX 3070.

A pretty impressive number is the memory bandwidth at ~410 GB/s, which should run local LLMs like Gemma 4 or Qwen3.8 27B at decent speed but with limited context size as its just 16Gb

Would I build it again? It was a lot of fun, but financially is not a crazy deal if you need to buy all the materials and factor your time in. Still much cheaper than a Steam Box!

- [0] https://makerworld.com/en/models/3021754-bc250-case-mkuu-fsp...

Edit: GPU performance comparison


>We want a public service to be available. Going forward, we will support Quad9 instead of running it ourselves. Running a privacy-focused public DNS service is a highly specialized undertaking, and the Quad9 Foundation is the undisputed leader in the field. Rather than duplicating their efforts to achieve only part of what they do, we're putting those resources toward financially supporting Quad9 instead.

Brilliant.


These guys have been spamming issues in repos trying to promote this project and no disclosure whatsoever that they are associated with the project.

https://github.com/search?q=%22cloudinabottle.toml%22&type=i...


A natural evolution of engineers losing touch with the customers and users.

I'm noticing some of the concern play out regarding AI weakening the capabilities of software people.

I gave the team an exact solution on a silver platter and they still failed to identify how to go about it after 3 days slamming it into Claude. The resolution is literally 1 line of code that could be arrived at in about 30 minutes of patient, old school troubleshooting.

I think what's happening is the AI system draws poorly aligned and led engineers into this ego inflation feedback loop where they are completely detached from reality because these tools can simulate a better one.


Normalising running arbitrary code delivered over the internet (in the form of JavaScript and WASM), as a necessary condition for accessing most web pages may not have been one of the best decisions we have made.

Anyone reading this who works/runs a robotics company, I really want to encourage you to build a robot to pick up trash on city sidewalks as an early product.

Picking up trash requires a lot of dexterity and will come with many challenges, but I think it’s a simpler problem than many household tasks and it’s probably on par for what these tests show is doable.

I think you’re going to have to PR challenges getting people to welcome robots into their homes. If you have robots out in cities providing a public good, not only do they serve as walking advertisements for your company, you’re going to earn some trust before you’re ready deploy them into private spaces.

Plus, governments (or perhaps HOAs for wealthy communities) can be good early customers since you can have a focused sales strategy. Politicians love these types of visible quality of life improvement projects. If you can show that your robots, working round the clock, can decrease litter at a low cost, many cities are going to want to buy them.


This seems like bad advice. I've very rarely committed extra files by accident, but I would 100% forget to unignore files I meant to commit.

If you're doing an initial setup step to gitignore everything, why not just do an initial setup step to gitignore the usual files? Make a template that you copy into all of your repos.


These are all important points and I love the analogy. But there is an even bigger issue with having LLMs write for you:

Writing is thinking. Thinking and deciding. There have been many times when I start out writing something substantial - could be an email, a blog post, a software design document, anything - when my own views substantially changed during the writing process. Writing forces you to serialize your thoughts - and you can't always trust the gestalt.

Reviewing gives you the chance to ensure the arguments connect solidly, that references are accurate (even informal references) and gives you the time to consider counter-arguments you aren't addressing.

None of this matters much on LinkedIn, but it matters a lot in our work. You cannot outsource your understanding to AI. They are powerful tools but they do not have any human understanding - that isn't their optimization target.


This is (mostly) not music theory and what is music theory is mostly wrong or incomplete to the point of being wildly misleading. Source: have degree and postgrad in music, was a professional musician until RSI put paid to that career, wife is a professional musician and teaches to postgrad level at 2 conservertoires, most of our friends are professional musicians, have a house full of scores and music books.

If you actually want to learn music theory for the purposes of playing I strongly recommend you just follow whatever tutorials for your instrument and style and if you get to the point where feel you want to learn more and take it seriously in and of itself, buy “The Jazz Theory Book” by Mark Levine[1]. In spite of what it says, there really isn’t any such thing as Jazz theory - it’s just music theory, and this book is a great presentation with lots of good examples. If you like jazz (or the western popular music tradition including rock, pop, funk, etc) you’ll come out understanding how that music works better than most people. If you’re doing a music degree, there will be books recommended by your music programme, but honestly, Levine will cover most of what you need if you’re not doing a straight classical course in which case you’ll want to augment with a more conventional source so you understand the “rules” they want you to follow when writing pastiche counterpoint etc.

If you want to get big into composition and/or want to understand late romantic and 20th century music, get Harmonielehre and “Structural Functions of Harmony” by Schoenberg. Together they are by far the best harmony books I have ever seen and go super-deep into why the western classical tradition works the way it does. If you compose there’s a decent chance they will change your life forever as his approach is to not take anything for granted but exhibit everything with examples from masterworks of the western tradition. Amazing books both of them. Harmony is not a spectator sport though - to get full benefit you have to get the books and work through stuff on the piano. It will reward you immensely.

If you want something else that will blow your mind, read “The technique of my musical language” by Messiaen. If you read Levine first this will have the additional benefit of showing you where the “diminished” and “augmented” scales and the whole “harmonic major” thing come from.

[1] https://www.shermusic.com/products/the-jazz-theory-book


It takes true corporate dedication to publish technical thought leadership on a page that actively fights your ability to read it.

How was there ever any doubt that these cameras and this access would be used in this way?

I personally blame the lack of accountability that police have in the US and the lack of public oversight into how departments operate.


Hi, Peter the Founder of Pushin.eu here. Sorry, the website escaped containment and landed on HN before I had the chance to update the "marketing materials" aka. landing page. So, here are a few points:

*The product is stable, but still in development. That's why some of the core things like pricing, etc. are missing. BUT:*

1. Business Model: Pushin will have subscriptions for individuals and teams. Pricing is not yet decided but it'll be close to GitHub/GitLab pricing.

2. Privacy: In true German fashion, we *don't* want your private data. Pushin doesn't track anything beyond the obvious: email, password hash, username, whatever information you put on your profile.

3. Roadmap: We're currently in Beta, but everything looks good so far. We'll probably go GA beginning of 2027. I'll focus on delivering the core features first and make sure that they are polished and of good quality before moving on to the nice-to-haves.

4. I say "we" but it's really only me (Peter Ullrich, peterullrich.com) and my dog (Bella, Labrador, beige). "We" are not VC funded, but bootstrapping on bare metal Scaleway servers. My wish is for this to become a proper company soon though.

5. Tech-stack: Elixir (Phoenix + LiveView) for most parts, Rust for the Git parts, S3-compatible buckets and Postgres on Scaleway, servers are bare metal Scaleway servers running in Paris.

6. Git implementation: Just like Tangled, I've used Rust and the gitoxide libraries to build a Git implementation that's fully compatible with the canonical Git CLI, but uses S3-compatible buckets as storage instead of keeping the entire repo on disk. I'll write in-depth about this soon, but it's very much what Tangled did, just with a different storage concept.

I gotta be honest that I'm both scared but also excited that Pushin hit HN. I wish we'd be better prepared, but here we are. Many thanks to anyone who is willing to try it out!


Saying “US corruption isn’t new” is a truism. There are probably isolated incidents, and many unproven theories, but everyone is quick to agree with this statement because it’s a common feeling everyone has now for some reason. The reality of corruption is likely much smaller and more boring than people think.

What we’re witnessing now is what should be called corruption. That corruption that everyone has been screaming for years. But finally real.

Remember, the job of these people’s propaganda is not to say that they’re better than the other side. It’s to say that they’re all the same. That’s it. And when you claim that this corruption is just a continuation of previous corruption, just bigger, and not a difference between essentially not having and having corruption (there’s always some small percentage of corruption, just like any crime) is essentially sweeping for them. It’s repeating their talking points.


I have 15+ years of PCB design experience. Mostly hobby stuff but a fair amount of processional work. Kilowatt range brushless motor controllers, basic RF stuff, lots of microcontroller stuff.

I had Fable design an LED earring. Rechargeable coin cell, RP2350 cpu, IMU, 45 addressable LEDs. It made two mistakes - missed the through holes on the coin cell holder footprint and made the center pad too small. I was able to have JLC swap the through hole battery holder for a surface mount one, and I put a little solder on the small center pad to make it stick up above the mask. They work great! It took 6 days of Fable usage, so about $50 on my Max plan. Very cheap for hardware dev.

I was sufficiently impressed that I’ve been going over old circuit board designs. Some half finished, some completed but in need of a next rev, and I’m getting so much done.

To see it hit the mainstream like the OpenAI announcement, I think big things are coming for this world and by and large they are not ready for it.

For my part, I have always loved PCB design and layout but I simply can’t keep up with the amount of labor required to build what I want, so I welcome this change.

I have also begun exploring more advanced algorithms for PCB manipulation. I have a fairly dense board that needs a few more small chips added. I have an algorithm now that can kinda shuffle and jostle things around so you take up all the spare microns of space across a region of the board and make openings to squeeze a little more in there. It’s pretty cool to see the visualizations as I have it generate movies of the component drift. I foresee much more powerful tools like this in the future.

One tip: have it make a project web page with a chronological list of big changes and detailed visualizations for everything that happens. I can actually prompt all of this on my phone while I am out and about, and view the results on a Tailscale served local page. I’ve always wanted to be able to do PCB design when away from home and now I can!


Unfortunately, Quad9 is censoring some domains in Europe (notably in France and Italy) following injunctions issued by rights holders [1]. That was not the case with Mullvad's DNS.

[1] https://quad9.net/news/blog/italian-blocking-demands-followi...


I posted this in the other Astra thread but it's just fallen off the homepage, so...

Pelicans from Astra, plus 5.6 Sol, Terra, Luna for comparison: https://static.simonwillison.net/static/2026/gpt-6-and-5.6-p...

I think this is a genuinely interesting comparison grid. Astra may be more expensive, but if you have a budget of 10 cents for a Pelican Astra low gives you something SO much better than the other models.

Astra uses less tokens overall too, for better results.

Astra transcript here: https://tools.simonwillison.net/markdown-svg-renderer?url=ht...


Because America can’t be trusted.

The not needing an account is obviously not minor, but honestly, the UI is just better, by a lot. I made a twitter account a while ago using one of those throw away email address sites, so I have an account that I don't care about that I can use for twitter....but the experience just sucks. I don't know how any stands it, even if they don't mind needing an account.

My revolt is against the cognitive stress of reading generated text. A trope typically indicates I’m in for an uphill read.

I recently read this William Zinsser quote that inspired a nickname for this: Clotted Claude [1].

> Nobody has made the point better than George Orwell in his translation into modern bureaucratic fuzz of this famous verse from Ecclesiastes:

> > I returned and saw under the sun, that the race is not to the swift, nor the battle to the strong, neither yet bread to the wise, nor yet riches to men of understanding, nor yet favor to men of skill; but time and chance happeneth to them all.

> Orwell's version goes:

> > Objective consideration of contemporary phenomena compels the conclusion that success or failure in competitive activities exhibits no tendency to be commensurate with innate capacity, but that a considerable element of the unpredictable must invariably be taken into account.

> First notice how the two passages look. The first one at the top invites us to read it. The words are short and have air around them; they convey the rhythms of human speech. The second one is clotted with long words. It tells us instantly that a ponderous mind is at work. We don't want to go anywhere with a mind that expresses itself in such suffocating language. We don't even start to read.

[1] https://blog.kierangill.xyz/clotted-claude


I love this line of thinking but the framing comes across to me as a bit inflammatory and uncharitable. Just about anything involved in the exchanged of ideas can be viewed as a virus! That is because, when viewed from an evolutionary biology perspective, ideas are the cognitive equivalent of genes (in fact, this is where the term meme comes from).

There's a whole field, evolutionary memetics, dedicated to this. Cultural values, marketing, religion, social media, education, propaganda, etc. can all be viewed quite naturally through this lense. Even the terms we use in every day language (eg, going "viral") seem to intuitively grasp this.

Is my friend a virus for recommending me their favorite book? Well, yes I guess, but that's kind of just how ideas work. Just my two cents


If the vulnerability is already being exploited in the wild --- as in, it's a vector people already know about and are tracking --- it's possibly not worth much at all. Vulnerability valuations depend heavily on the lifespan of the vulnerability; payments on black market are tranched (explicitly or less explicitly, as with "maintenance payments") based on whether they're patched.

Further: a vulnerability is probably not worth that much either, even if it's a hypercapable vulnerability, because the grey market buys full enablement kits, not vulnerability information. People making 6 figures on vulnerabilities are selling fully enabled full chain exploit systems, not just intelligence about a sandbox escape.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: