Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Claude Code now reads AGENTS.md if there is no Claude.md(claude.com ↗)
    169comments
  2. Android 17 is the first since 3.x to add new APIs without releasing to the AOSP(grapheneos.social ↗)
    213comments
  3. How OpenAI Used Its Own LLMs to Design Its Jalapeño Chip(ieee.org ↗)
    26comments
  4. Cloudflare Quick Tunnels(cloudflare.com ↗)
    237comments
  5. Saving another 100TB of RAM(cloudflare.com ↗)
    38comments
  6. A 1542 papal cipher cracked with simulated annealing(simonklee.dk ↗)
    1comments
  7. Xcode 27.1 Beta Release Notes(developer.apple.com ↗)
    63comments
  8. How to Write with an LLM(sockpuppet.org ↗)
    259comments
  9. Cache-to-Cache: Direct Semantic Communication Between LLMs (2025)(arxiv.org ↗)
    12comments
  10. Photon-Emission-Guided Laser Fault Injection Enables RP2350 Secure Debug(ledger.com ↗)
    49comments
  11. Show HN: Cactus Needle 3: 8-29MB automation models can match DeepSeek V4 Flash(cactuscompute.com ↗)
    74comments
  12. The first new cat species discovered in 100 years(nationalgeographic.com ↗)
    49comments
  13. OpenJev(openjev.com ↗)
    240comments
  14. US troop deaths during Iran war exceed Pentagon count by at least four(reuters.com ↗)
    87comments
  15. Cyclomatic Complexity in C#(ndepend.com ↗)
    12comments
  16. Two parallel neural ectoderm progenitors contribute to the developing brain(newscientist.com ↗)
    51comments
  17. The Implications of Linguistic Illegibility for LLM Security(arxiv.org ↗)
    17comments
  18. C++26: Trivial infinite loops are no longer undefined behaviour(sandordargo.com ↗)
    177comments
  19. Warez: The Infrastructure and Aesthetics of Piracy (2021)(archive.org ↗)
    15comments
  20. Minimal Phone 2(minimalcompany.com ↗)
    163comments
  21. Inside ZCode: Silently uploading your Git history to the cloud(ferstar.org ↗)
    89comments
  22. Size-Specialized Memory Allocation(go.dev ↗)
    3comments
  23. How SpaceX streamlined the Raptor engine(construction-physics.com ↗)
    29comments
  24. I vibed a proof of Conway's conjecture(overreacted.io ↗)
    180comments
  25. A search-and-inference database from scratch in pure Zig(antfly.io ↗)
    16comments
  26. From Geometry to Algebra and Back Again: 4000 Years of Papers (2023) [video](youtube.com ↗)
    discuss
  27. North Korean nuclear test sets off years of earthquakes(science.org ↗)
    151comments
  28. US Military had close call after using AI for hallucinated intelligence report(cnn.com ↗)
    291comments
  29. Mathematicians Build Long-Awaited Graph Sandwich(quantamagazine.org ↗)
    18comments
  30. Cekura (YC F24) Is Hiring(ycombinator.com ↗)
    discuss

Ask HN: What are the best books for learning information security?

15 pointsby 10y ago
2 comments
For topics like: common vulnerabilities and mitigations, secure programming techniques, static analysis, reverse engineering, fuzzing, cryptography, and so on.

Looking for some good tomes to expand my mind and bookshelf.

10y agoHN ↗

Glad you asked. This is a list I like to call, "how to become an extremely effective and formidable security engineer."

1. The Web Application Hacker's Handbook

Probably the first book you want to read; this will teach you the core mindset you need for finding security flaws in web applications as well as give a very strong foundation for the different classes of vulnerabilities.

2. The Mobile Application Hacker's Handbook

Good supplement to #1 for application security, obviously focused on mobile apps.

3. The Art of Software Security Assessment

The bible of the security industry. Especially instructive for source code review.

4. Security Engineering (Ron Anderson)

Supplements #3. Very instructive for injecting security into the overall SDLC and designing secure software.

5. The Tangled Web

Excellent historical background and good high level overview of many information security topics. Every engineer should read this, even if they don't work in security.

6. Gray Hat Python

Very hands on, good introduction to aspects of reverse engineering and the typical work an e.g. security consultant will do at a top firm.

7. Practical Malware Analysis

Very good introduction to malware analysis.

8. Practical Reverse Engineering

This book, along with #9 will teach you everything you need to know to effectively reverse engineer software for security-focused analysis.

9. Reversing: Secrets of Reverse Engineering

10. The IDA Pro Book

You'll want this if you have any plan to work with IDA Pro at all, which is the gold standard for decompiling and reversing software.

11. The Shellcoder's Handbook

If you'd like to write exploits after you're done reversing software to find an exploitable bug, this is a good book to pick up.

12. Cryptography Engineering

Very solid and broad introduction to cryptography. Every engineer should read this, even if they don't work in security.

13. Introduction to Modern Cryptography

This book, along with #14 is what you want to read if you're going to work as a cryptographer or cryptanalyst professionally.

14. Handbook of Applied Cryptography

--------------------------------------

Theoretically, these books should resolve your known-unknowns and your unknown-unknowns. Anyone who reads and works through the list should be capable of designing secure software, finding errors in white and black box source code reviews and finding errors in white and black box penetration tests.

If you're looking to get into this professionally, feel free to contact me if you have any questions and I'll do my best to help.