Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. F-Droid 2.0 (f-droid.org)
    273comments
  2. Show HN: Make cursed fonts like Times New Bastard (mitpit.com)
    73comments
  3. Show HN: Whiteboard (YC W26) – An open-source IDE for thoughtful software design (github.com/devdotfast)
    85comments
  4. Why is the liver so weirdly regenerative? (dynomight.substack.com)
    164comments
  5. 2DWillNeverDie (2dwillneverdie.com)
    13comments
  6. Fearless SIMD v1.0 (linebender.org)
    32comments
  7. Rails World 2026 Opening Keynote [video] (youtube.com)
    279comments
  8. Toyota is taking the Corolla electric (electrek.co)
    418comments
  9. My weird new hobby: Wandering around Tokyo on Google Maps (ahmedhossamdev.com)
    105comments
  10. Using LLMs to trace alchemical knowledge and decode 17th century letters (resobscura.substack.com)
    14comments
  11. Writing Parquet files using Haskell (datahaskell.org)
    3comments
  12. Google’s Project Suncatcher to put ML infrastructure in space (blog.google)
    240comments
  13. Two-tier encryption in the UK (macanorak.com)
    380comments
  14. The Bayeux Tapestry: Woven by the Victors (historytoday.com)
    —discuss
  15. Show HN: Air-gapped file encryption as self-decrypting HTML page (apeleg.com)
    14comments
  16. Book review: Is parallel programming hard, and, if so, what can you do about it? (ahelwer.ca)
    28comments
  17. California is chasing wealth that has feet (landeconomics.org)
    452comments
  18. Show HN: Koi.rest – watch some fish and regain your balance (koi.rest)
    38comments
  19. The Board Game of the Alpha Nerds (2014) (grantland.com)
    24comments
  20. Sourcehut account takeover via build logs (XSS in ansi2html) (blog.arusekk.pl)
    12comments
  21. Security auditing in the age of (good enough) AI (trailofbits.com)
    7comments
  22. The forgotten battle of East Lansing (eastlansinginfo.news)
    14comments
  23. Stable (YC W20) Is Hiring Product Engineers (usestable.com)
    —discuss
  24. Geothermal heat map of US hot springs (soakingsprings.com)
    37comments
  25. Forging 1024-bit RSA signatures in nearly SNFS time [pdf] (iacr.org)
    9comments
  26. WaveDigger: Dig into wireless signals to discover their physical locations (github.com/christianrowlands)
    19comments
  27. Opus 5.5 is good at explainer videos (launchvideo.io)
    96comments
  28. Tutoring company tells parents to save their money and 'use AI instead' (afr.com)
    151comments
  29. Nokia Design Archive (2025) (aalto.fi)
    118comments
  30. Motor Characterization for Small Running Robots (2016) (robot-daycare.com)
    1comments

Sourcehut account takeover via build logs (XSS in ansi2html)

87 pointsby 7h agoblog.arusekk.pl
12 comments
6h agoHN ↗

Really commendable work fixing up the upstream python project. I don't think there's anything to be embarrassed about in the timeline.

4h agoHN ↗

I would prefer to do a super proper disclosure with coordinated release dates and everything. My first submitting to SourceHut security ML ended up making the vuln existence somewhat public before upstream ever knew.

4h agoHN ↗

That might have been DNS, the website itself is on sourcehut pages. Should be fine now for a while.

6h agoHN ↗

I love sourcehut, and I can't really think anything to replace it. But here's my shot. It's a popular myth that independently from the project size, someone should always take the main stream product in the field than small projects because most of the people would use the main stream product and there's an higher chance that vulnerabilities get already exploited/recognized/fixed. Is that true or not? TL;DR: in the evaluation of such products (sourcehut but even self hosted stuff), should we also take account about the project history and the exposition to threats?

5h agoHN ↗

haven’t been properly rickrolled in years, wasn’t expecting that!

4h agoHN ↗

Oh my God, it's OSC 8 again. Because copy-pasting an URI from the terminal window is so 2003, and goodness gracious, having to look at an actual URL instead of an arbitrarily inaccurate description of it? That's, like, 1993. When I wrote my variant of ansi2html, I aggressively stripped out every C0 and C1, and all of the possible APC/DCS/OSC/PM sequences.

Meanwhile, internal links between different parts of a man page still don't exist (unless you use GNU Info but seriously, I'd rather use lynx on a folder of HTML files instead).

3h agoHN ↗

OSC 8 hyperlinks are extremely useful for tables and other kinds of compact displays.

1h agoHN ↗

They're also extremely useful for introducing CVEs into terminal emulators; I think I've seen about 5 of those on HN — including one OSC sequence that would cause the terminal emulator to just straight up automatically launch the web browser with whatever URLs were sent its way, no prompts no nothing.

1h agoHN ↗

Build logs are such a tricky attack surface; sanitizing arbitrary build output is practically impossible without breaking useful formatting. Always assume untrusted input.