Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. F-Droid 2.0 (f-droid.org)
    250comments
  2. Show HN: Make cursed fonts like Times New Bastard (mitpit.com)
    58comments
  3. Show HN: Whiteboard (YC W26) – An open-source IDE for thoughtful software design (github.com/devdotfast)
    76comments
  4. Why is the liver so weirdly regenerative? (dynomight.substack.com)
    139comments
  5. Fearless SIMD v1.0 (linebender.org)
    28comments
  6. 2DWillNeverDie (2dwillneverdie.com)
    7comments
  7. Rails World 2026 Opening Keynote [video] (youtube.com)
    227comments
  8. My weird new hobby: Wandering around Tokyo on Google Maps (ahmedhossamdev.com)
    82comments
  9. Show HN: Koi.rest – watch some fish and regain your balance (koi.rest)
    25comments
  10. Toyota is taking the Corolla electric (electrek.co)
    271comments
  11. Using LLMs to trace alchemical knowledge and decode 17th century letters (resobscura.substack.com)
    9comments
  12. Back and shoulder surgery is often worse than useless (economist.com)
    27comments
  13. GitLab Outage (status.gitlab.com)
    11comments
  14. California is chasing wealth that has feet (landeconomics.org)
    288comments
  15. Google’s Project Suncatcher to put ML infrastructure in space (blog.google)
    173comments
  16. Sourcehut account takeover via build logs (XSS in ansi2html) (blog.arusekk.pl)
    9comments
  17. Stable (YC W20) Is Hiring Product Engineers (usestable.com)
    —discuss
  18. Book review: Is parallel programming hard, and, if so, what can you do about it? (ahelwer.ca)
    23comments
  19. The Board Game of the Alpha Nerds (2014) (grantland.com)
    17comments
  20. Two-tier encryption in the UK (macanorak.com)
    362comments
  21. Motor Characterization for Small Running Robots (2016) (robot-daycare.com)
    —discuss
  22. Security auditing in the age of (good enough) AI (trailofbits.com)
    2comments
  23. The forgotten battle of East Lansing (eastlansinginfo.news)
    12comments
  24. Geothermal heat map of US hot springs (soakingsprings.com)
    32comments
  25. Forging 1024-bit RSA signatures in nearly SNFS time [pdf] (iacr.org)
    5comments
  26. Early rogue AI agent activity and attempts to hack found on urlquery.net (transluce.org)
    225comments
  27. WaveDigger: Dig into wireless signals to discover their physical locations (github.com/christianrowlands)
    14comments
  28. Tutoring company tells parents to save their money and 'use AI instead' (afr.com)
    117comments
  29. Opus 5.5 is good at explainer videos (launchvideo.io)
    81comments
  30. Nokia Design Archive (2025) (aalto.fi)
    115comments

Sourcehut account takeover via build logs (XSS in ansi2html)

52 pointsby 4h agoblog.arusekk.pl
9 comments
3h agoHN ↗

Really commendable work fixing up the upstream python project. I don't think there's anything to be embarrassed about in the timeline.

1h agoHN ↗

I would prefer to do a super proper disclosure with coordinated release dates and everything. My first submitting to SourceHut security ML ended up making the vuln existence somewhat public before upstream ever knew.

1h agoHN ↗

That might have been DNS, the website itself is on sourcehut pages. Should be fine now for a while.

2h agoHN ↗

I love sourcehut, and I can't really think anything to replace it. But here's my shot. It's a popular myth that independently from the project size, someone should always take the main stream product in the field than small projects because most of the people would use the main stream product and there's an higher chance that vulnerabilities get already exploited/recognized/fixed. Is that true or not? TL;DR: in the evaluation of such products (sourcehut but even self hosted stuff), should we also take account about the project history and the exposition to threats?

1h agoHN ↗

haven’t been properly rickrolled in years, wasn’t expecting that!

1h agoHN ↗

Oh my God, it's OSC 8 again. Because copy-pasting an URI from the terminal window is so 2003, and goodness gracious, having to look at an actual URL instead of an arbitrarily inaccurate description of it? That's, like, 1993. When I wrote my variant of ansi2html, I aggressively stripped out every C0 and C1, and all of the possible APC/DCS/OSC/PM sequences.

Meanwhile, internal links between different parts of a man page still don't exist (unless you use GNU Info but seriously, I'd rather use lynx on a folder of HTML files instead).