Hacker News

New stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Douglas Davis: The First Collaborative Sentence(whitney.org)
    discuss
  2. Goose Robot(twitter.com/robotworksgoose)
    discuss
  3. Morpion Solitaire(morpionsolitaire.com)
    discuss
  4. High-mileage electric cars are more reliable than petrol ones, study finds(theguardian.com)
    discuss
  5. A Call for Control of Frontier AI Models(government.nl)
    discuss
  6. Why banning AI in the classroom will not be enough(theconversation.com)
    discuss
  7. Show HN: Cookbook – a workspace for your team and agents(cookbook.team)
    1comments
  8. Does an open-weight decision model beat a hosted one? Jev vs. Laya(astgl.com)
    discuss
  9. Zero-downtime Linux kernel zero-day mitigation via eBPF and SECCOMP(github.com/mc493)
    discuss
  10. Show HN: a0flow — paid micro-APIs for AI agents, x402/USDC, no signup(a0flow.com)
    discuss
  11. International Conference on Functional Programming (ICFP) 2026 talks released(youtube.com)
    discuss
  12. What does this assembly code do?(pagetable.com)
    1comments
  13. AgentsView(agentsview.io)
    discuss
  14. Playing with Jev for Daily Questions(yesno.fyi)
    discuss
  15. MiMo-v2.6-Flash(mi.com)
    discuss
  16. HTTP QUERY Method: The Grey Zone Between Get and Post(sans.edu)
    discuss
  17. The Apple Watch Has a Problem(YouTube – Marques Brownlee) [video](youtube.com)
    discuss
  18. Tell HN: Substack obfuscating text to break reading mode
    discuss
  19. DoorDash Agrees to $131.5M Settlement for Shortchanging Workers(nytimes.com)
    1comments
  20. Claude Opus 5.5 (High Effort) Intelligence, Performance and Price Analysis(artificialanalysis.ai)
    discuss
  21. Faster and local Jev like model for Mac(github.com/mizorewww)
    discuss
  22. Show HN: Botzilla – Web automation using visual scripting(botzilla.dev)
    discuss
  23. Show HN: Notes on Agentic AI – A text-first guide for practicing engineers(github.com/mrsachindixit)
    discuss
  24. Enjoy Every Sandwich(bradmontague.substack.com)
    discuss
  25. Shipping our game to twelve platforms on day one(m2h.nl)
    discuss
  26. Show HN: Last Internet Connection(github.com/rubinoslaw)
    discuss
  27. Harper Lee first edition novel found in Oxfam shop(bbc.com)
    discuss
  28. Meta Tests Muse AI Agent Calls That Are Made by Humans in a Call Center(404media.co)
    discuss
  29. Unreal Agent(github.com/unreallabsai)
    1comments
  30. Show HN: Parametric, low-poly assets for BIM/CAD(3dassetstudio.com)
    discuss

Meta’s Muse has a serious 0-day

92 pointsby 4h agoarstechnica.com
37 comments
3h agoHN ↗

Who in their right mind would install a Meta AI with near admin privileges?

3h agoHN ↗

We all fear the true answer to that question.

3h agoHN ↗

Normally I’m not one to blame the victims but, uh, yeah who in the world is dumb enough to trust Meta at this point?

2h agoHN ↗

And before this gets flagged or downvoted or "he was young" or "he was joking" or "he was making a point: he was saying 'I could be anyone', not that he can't be trusted" answer me what other tech people say this, ever, along with all the other charges ("I'm going to fuck them [the Winklevoss twins] in the ear", "You can be unethical and legal and that's how i live my life haha", hacking Crimson reporters, and that's just at Harvard, let alone when Facebook became available to the public

1h agoHN ↗

Honestly, a lot of people start using this line of humor when their peers do. Add in that he was young, and this was before people’s private messages being released easily to the masses was common, Im not really surprised.

1h agoHN ↗

Yeah - I just went from +1 to -2

It is clear some of you are brigading. And I don't care if my comment 'breaks site rules'. It happens a lot here. I know you're from industry and you're brigading to protect your industry

2h agoHN ↗

most people don't know or care what "admin privileges" even means, or why they wouldn't want ai to have them

2h agoHN ↗

Almost everyone who is struggling with AI insecurity and is afraid of being left behind

2h agoHN ↗

No, most workers don't really say this in surveys and polling. They tend to hate LLM tools because it makes their jobs worse, nothing about being left behind.

The only people pushing the "left behind" narrative is SV + SF + VC since their previous narratives have failed to persuade the public (thank fuck).

2h agoHN ↗

I’m pretty sure you misread the comment you responded to

2h agoHN ↗

"Normies" aka the average user on Meta. They have no concept of what "admin privileges" means and don't really care. I still have a hard time convincing my clients to use secure passwords. I have clients who were phished for substantial amounts of money and STILL don't implement proper security measures.

2h agoHN ↗

Who in their right mind would install a Meta AI

I fixed it for ya

17m agoHN ↗

This is kinda the reason why the Meta stock might be pumping and Muse might leap ahead other AI solutions as far as market share goes. Quoted from Prof G Markets podcast: "meta has been molesting your privacy for 10 years".

It stands to reason their daily active users just don't care, they are already sharing so much on Meta's platforms it won't matter to them.

3h agoHN ↗

I'm confused what the vulnerability is. Does macOS have some specific function for protecting key material, that it's unexpected that if you execute user-privileged code locally, outside of a sandbox, it gets full read access?

3h agoHN ↗

Yeah macOS security is capability based rather than purely identity based. So if you don't pass the required entitlements to an application then it cannot do stuff like read from the system keychain even if its running as your user.

3h agoHN ↗

A zero day? Of course it does. It likely has many. Given the history of software, it's impossible to think it wouldn't.

2h agoHN ↗

You would think a website dedicated to talking about software engineering would agree with this sentiment wholeheartedly.

2h agoHN ↗

A zero day generally means a vulnerability and associated exploit have been identified and the vendor didn’t yet provide a patch. It doesn’t just mean “there is a vulnerability”. To say that every software has vulnerabilities is just not a useful comment

1h agoHN ↗

The difference between

"We found aliens!"

And

"Aliens are out there!"

3h agoHN ↗

Maybe they should have spent the money used to buy its stupid name from a band on additional testing instead.

2h agoHN ↗

Presumably. They changed their handle on non-Meta social networks to match at around the same time as the Meta handle change.

55m agoHN ↗

Why would they pay Muse? Muse the band doesn't have a monopoly on the word muse

36m agoHN ↗

because they had control of the handles used on Meta's apps. Why is that hard to understand. I was shocked they paid them instead of just taking it.

3h agoHN ↗

macOS has long provided a simple means for apps to handle dictation and transcription in processes that stay securely on the device

Not sure these guys realize that the quality and latency of those Apple services in MacOS is way lower than SOTA and not too many people use them because of that…

2h agoHN ↗

How is this a serious zero day if it requires local code execution to run?

2h agoHN ↗

The "zero day" is something they call a "ClickFix Attack"

Upon Googling "ClickFix":

  > "A ClickFix attack is a social engineering technique... It typically compromises devices by manipulating victims into copying and pasting malicious commands directly into system-level tools"

I'm sorry, that's not a zero-day, that's idiocy that's as old as time.

2h agoHN ↗

We filed a bug report but the original maintainer seems to have dropped offline. The community's had some success in correcting bugs with low-level hacking, but it's hard to make progress without the source code.

1h agoHN ↗

words don't seem to mean anything anymore.

clickbait headline should be changed, not a 0-day.

2h agoHN ↗

Is 12 hours to deliver a local privilege escalation fix not a good response time?

1h agoHN ↗

I love that when you open a web inspection console on facebook, it says "Stop! This is a browser feature intended for developers. If someone told you to copy-paste something here to enable a Facebook feature or "hack" someone's account, it's a scam and will give them access to your Facebook account. See https://www.facebook.com/selfxss for more information."

32m agoHN ↗

I've used the devtools for years now, but for whatever reason, it never occurred to me to try and format the text like that. Too bad that that message is not clean as there were plenty of other things in the console so that I actually had to scroll around to find it. Had someone asked me to open the console and do something, I would not have seen the message.

12m agoHN ↗

People are giving Meta access to their emails, messages and calendars and other apps? Are they out of their mind or what am I missing?