Hacker News

New stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Twinkleplop – plop some twinkle in your code (ultrafast syntax highlighting)(twinkleplop.pngwn.at)
    discuss
  2. Grok 4.7 Scores 46 on AI Intelligence Index, Puts SpaceXAI in Top 4 Labs(artificialanalysis.ai)
    discuss
  3. There's a high chance of devices being sold with GrapheneOS preinstalled in 2027(grapheneos.social)
    discuss
  4. Moving from cash to credit cards, PayPal, etc. is an ongoing privacy disaster(grapheneos.social)
    discuss
  5. In 200-Page Report, Cornell Confronts the Crisis in American Higher Education(wsj.com)
    discuss
  6. Shall We Repeal the Laws of Economics – Part III(oaktreecapital.com)
    discuss
  7. Alzheimer's Is No Longer an Untreatable Disease(sciencealert.com)
    discuss
  8. A golden opportunity: Seattle's surveillance pricing ban(thenexusofprivacy.net)
    discuss
  9. ASML Executive Says It Has No Sales in Europe(bloomberg.com)
    discuss
  10. Bugcrowd is currently fundamentally broken(leonbecker.de)
    discuss
  11. Why is social media so humourless?(baldurbjarnason.com)
    discuss
  12. Ask HN: How do your teams share and distribute agent skills?
    discuss
  13. What drives BigQuery costs, and what doesn't(erathos.com)
    1comments
  14. Should TypeScript support runtime types instead of relying on Zod?(twitter.com/mykhailen)
    1comments
  15. We are the last generation of human psychiatrists(cambridge.org)
    discuss
  16. Grok bot is now in Tesla(twitter.com/elonmusk)
    1comments
  17. Implementing the Camera Mechanic from Viewfinder(ishamf.dev)
    discuss
  18. Show HN: Ttmux, a Modern and Fast Tmux(github.com/statico)
    1comments
  19. Anthropic launches Claude Opus 5.5 with stricter safeguards for cybersecurity(theverge.com)
    discuss
  20. Claude Opus 5.5 for code review: More catches, different misses(coderabbit.ai)
    discuss
  21. Claude Opus 5.5(claude.com)
    discuss
  22. Anthropic now offering limit resets like Codex(twitter.com/claudedevs)
    discuss
  23. Roundtables: The Deadly Failures of the Virtual Border Wall(technologyreview.com)
    discuss
  24. The Myth of AI Doom, with Cal Newport(youtube.com)
    discuss
  25. I open-sourced a small library for drawing SVGs progressively(npmjs.com)
    discuss
  26. I run a production AI app for €60 a month. Here is the actual bill.(tailstory-app.com)
    discuss
  27. Show HN: WebMCP Registry of Websites That Agents Can Use(wmcp.ai)
    discuss
  28. Show HN: Groupicorn directory of IOP group therapy programs
    discuss
  29. Ancient DNA reveals pervasive directional selection across West Eurasia(nature.com)
    discuss
  30. Code similarity detection using Tree-sitter(github.com/dsummersl)
    1comments

Meta’s Muse has a serious 0-day

75 pointsby 2h agoarstechnica.com
30 comments
2h agoHN ↗

Who in their right mind would install a Meta AI with near admin privileges?

1h agoHN ↗

We all fear the true answer to that question.

1h agoHN ↗

Normally I’m not one to blame the victims but, uh, yeah who in the world is dumb enough to trust Meta at this point?

1h agoHN ↗

And before this gets flagged or downvoted or "he was young" or "he was joking" or "he was making a point: he was saying 'I could be anyone', not that he can't be trusted" answer me what other tech people say this, ever, along with all the other charges ("I'm going to fuck them [the Winklevoss twins] in the ear", "You can be unethical and legal and that's how i live my life haha", hacking Crimson reporters, and that's just at Harvard, let alone when Facebook became available to the public

26m agoHN ↗

Honestly, a lot of people start using this line of humor when their peers do. Add in that he was young, and this was before people’s private messages being released easily to the masses was common, Im not really surprised.

14m agoHN ↗

Yeah - I just went from +1 to -2

It is clear some of you are brigading. And I don't care if my comment 'breaks site rules'. It happens a lot here. I know you're from industry and you're brigading to protect your industry

1h agoHN ↗

most people don't know or care what "admin privileges" even means, or why they wouldn't want ai to have them

1h agoHN ↗

Almost everyone who is struggling with AI insecurity and is afraid of being left behind

1h agoHN ↗

No, most workers don't really say this in surveys and polling. They tend to hate LLM tools because it makes their jobs worse, nothing about being left behind.

The only people pushing the "left behind" narrative is SV + SF + VC since their previous narratives have failed to persuade the public (thank fuck).

53m agoHN ↗

I’m pretty sure you misread the comment you responded to

1h agoHN ↗

"Normies" aka the average user on Meta. They have no concept of what "admin privileges" means and don't really care. I still have a hard time convincing my clients to use secure passwords. I have clients who were phished for substantial amounts of money and STILL don't implement proper security measures.

37m agoHN ↗

Who in their right mind would install a Meta AI

I fixed it for ya

1h agoHN ↗

I'm confused what the vulnerability is. Does macOS have some specific function for protecting key material, that it's unexpected that if you execute user-privileged code locally, outside of a sandbox, it gets full read access?

1h agoHN ↗

Yeah macOS security is capability based rather than purely identity based. So if you don't pass the required entitlements to an application then it cannot do stuff like read from the system keychain even if its running as your user.

1h agoHN ↗

A zero day? Of course it does. It likely has many. Given the history of software, it's impossible to think it wouldn't.

1h agoHN ↗

You would think a website dedicated to talking about software engineering would agree with this sentiment wholeheartedly.

49m agoHN ↗

A zero day generally means a vulnerability and associated exploit have been identified and the vendor didn’t yet provide a patch. It doesn’t just mean “there is a vulnerability”. To say that every software has vulnerabilities is just not a useful comment

1h agoHN ↗

Maybe they should have spent the money used to buy its stupid name from a band on additional testing instead.

1h agoHN ↗

Presumably. They changed their handle on non-Meta social networks to match at around the same time as the Meta handle change.

1h agoHN ↗

macOS has long provided a simple means for apps to handle dictation and transcription in processes that stay securely on the device

Not sure these guys realize that the quality and latency of those Apple services in MacOS is way lower than SOTA and not too many people use them because of that…

58m agoHN ↗

How is this a serious zero day if it requires local code execution to run?

47m agoHN ↗

The "zero day" is something they call a "ClickFix Attack"

Upon Googling "ClickFix":

  > "A ClickFix attack is a social engineering technique... It typically compromises devices by manipulating victims into copying and pasting malicious commands directly into system-level tools"

I'm sorry, that's not a zero-day, that's idiocy that's as old as time.

38m agoHN ↗

We filed a bug report but the original maintainer seems to have dropped offline. The community's had some success in correcting bugs with low-level hacking, but it's hard to make progress without the source code.

10m agoHN ↗

words don't seem to mean anything anymore.

clickbait headline should be changed, not a 0-day.

31m agoHN ↗

Is 12 hours to deliver a local privilege escalation fix not a good response time?