Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. F-Droid 2.0 (f-droid.org)
    240comments
  2. Show HN: Koi.rest – watch some fish and regain your balance (koi.rest)
    19comments
  3. Show HN: Make cursed fonts like Times New Bastard (mitpit.com)
    57comments
  4. California is chasing wealth that has feet (landeconomics.org)
    234comments
  5. GitLab Outage (status.gitlab.com)
    9comments
  6. Show HN: Whiteboard (YC W26) – An open-source IDE for thoughtful software design (github.com/devdotfast)
    72comments
  7. Back and shoulder surgery is often worse than useless (economist.com)
    8comments
  8. Why is the liver so weirdly regenerative? (dynomight.substack.com)
    130comments
  9. 2DWillNeverDie (2dwillneverdie.com)
    4comments
  10. Fearless SIMD v1.0 (linebender.org)
    27comments
  11. Rails World 2026 Opening Keynote [video] (youtube.com)
    219comments
  12. My weird new hobby: Wandering around Tokyo on Google Maps (ahmedhossamdev.com)
    76comments
  13. Using LLMs to trace alchemical knowledge and decode 17th century letters (resobscura.substack.com)
    9comments
  14. Toyota is taking the Corolla electric (electrek.co)
    245comments
  15. Google’s Project Suncatcher to put ML infrastructure in space (blog.google)
    154comments
  16. Stable (YC W20) Is Hiring Product Engineers (usestable.com)
    —discuss
  17. Book review: Is parallel programming hard, and, if so, what can you do about it? (ahelwer.ca)
    22comments
  18. The Board Game of the Alpha Nerds (2014) (grantland.com)
    17comments
  19. Sourcehut account takeover via build logs (XSS in ansi2html) (blog.arusekk.pl)
    8comments
  20. Two-tier encryption in the UK (macanorak.com)
    370comments
  21. Security auditing in the age of (good enough) AI (trailofbits.com)
    2comments
  22. International observers to investigate Swedish election fraud (tv4.se)
    9comments
  23. The forgotten battle of East Lansing (eastlansinginfo.news)
    12comments
  24. Forging 1024-bit RSA signatures in nearly SNFS time [pdf] (iacr.org)
    6comments
  25. Geothermal heat map of US hot springs (soakingsprings.com)
    30comments
  26. Opus 5.5 is good at explainer videos (launchvideo.io)
    75comments
  27. Early rogue AI agent activity and attempts to hack found on urlquery.net (transluce.org)
    217comments
  28. WaveDigger: Dig into wireless signals to discover their physical locations (github.com/christianrowlands)
    14comments
  29. Tutoring company tells parents to save their money and 'use AI instead' (afr.com)
    112comments
  30. Nokia Design Archive (2025) (aalto.fi)
    114comments

Sourcehut account takeover via build logs (XSS in ansi2html)

49 pointsby 3h agoblog.arusekk.pl
8 comments
2h agoHN ↗

Really commendable work fixing up the upstream python project. I don't think there's anything to be embarrassed about in the timeline.

34m agoHN ↗

I would prefer to do a super proper disclosure with coordinated release dates and everything. My first submitting to SourceHut security ML ended up making the vuln existence somewhat public before upstream ever knew.

32m agoHN ↗

That might have been DNS, the website itself is on sourcehut pages. Should be fine now for a while.

2h agoHN ↗

I love sourcehut, and I can't really think anything to replace it. But here's my shot. It's a popular myth that independently from the project size, someone should always take the main stream product in the field than small projects because most of the people would use the main stream product and there's an higher chance that vulnerabilities get already exploited/recognized/fixed. Is that true or not? TL;DR: in the evaluation of such products (sourcehut but even self hosted stuff), should we also take account about the project history and the exposition to threats?

1h agoHN ↗

haven’t been properly rickrolled in years, wasn’t expecting that!

19m agoHN ↗

Oh my God, it's OSC 8 again. Because copy-pasting an URI from the terminal window is so 2003, and goodness gracious, having to look at an actual URL instead of an arbitrarily inaccurate description of it? That's, like, 1993. When I wrote my variant of ansi2html, I aggressively stripped out every C0 and C1, and all of the possible ASC/DSC/OSC sequences.

Meanwhile, internal links between different parts of a man page still don't exist (unless you use GNU Info but seriously, I'd rather use lynx on a folder of HTML files instead).