Top 29 stories from Hacker News. Top 10 include comment highlights. Compiled at 20:10 UTC.
1041 points by varunsharma07 · 433 comments
On 2026-05-11, an attacker chained a pull_request_target Pwn Request, GitHub Actions cache poisoning across the fork↔base trust boundary, and OIDC token extraction from runner memory to publish 84 malicious versions across 42 @tanstack/* packages on npm. Full postmortem.
What HN said:
cube00: Please be careful when revoking tokens. It looks like the payload installs a dead-man's switch at ~/.local/bin/gh-token-monitor.sh as a systemd user service (Linux) / LaunchAgent com.user.gh-token-monitor(macOS). It polls api.github.
Ciantic: What I want to focus on is mental model of your CI pipeline, and problem with too much YAML, consider this quote: > Cache scope is per-repo, shared across pull_request_target runs (which use the base repo's cache scope) and pushes to main.
jonchurch_: It is unfortunate, but this is evidence (IMO) that Trusted Publishing is still
not securenot enough by itself to securely publish from CI, as an attacker inside your CI pipeline or with stolen repo admin creds can easily publish.
chrisweekly: Postinstall scripts are deadly. Everyone should be using pnpm. Crazy that an "orphan" commit pushed to a FORK(!) could trigger this (in npm clients). IMO GitHub deserves much of the blame here.
860 points by rubenbe · 298 comments
What HN said:
kn100: Full disclosure: I've never owned a Bambu because I've never loved the idea of a "closed" ecosystem 3D printer, however I have used them, and am very familiar with the 3d printing space beyond Bambu.
9cb14c1ec0: This sentence in Bambu Lab's blog post is wild: > We have documented incidents of service outages caused precisely by spikes in unauthorized traffic - overwhelming the servers, causing service disruptions affecting everyone. The cost was instability felt by all users.
syntaxing: Funny how fast people forget. LAN mode was NOT part of their original plan until outrage like this happened last time. They shifted their course and changed their blog post after. Putting pressure as a customer is how you steer company’s direction.
danielrmay: "It pretended to be the official client" is not a security argument if the mechanism was client-supplied metadata. That’s not impersonation. That’s Bambu discovering that user agents are not authentication.
823 points by indigodaddy · 873 comments
What HN said:
bryanrasmussen: One obvious reason is Python's extreme readability, it has often been described as being as close to executable pseudo-code as one can get. If you're using an LLM to write code I think the rules would be 1.
pshirshov: No reason, unless the project is simple. The more you can offload onto your compiler/typer - the shorter is the feedback loop, the better agents work. Lack of strictly enforced static typing make agents fail much sooner with Python.
boffin: Read the first few comments and surprised I didn’t see it, but training data. The voluminous amount of Python in the training data. I could write in brainfuck with ai, but I presume, wouldn’t get the same results than if going with python.
luodaint: But under this frame, it appears that the developer's task involves prompt engineering. This is not the case. Even if an agent generates 90% of the code, each and every diff is going to be in my review queue.
591 points by adunk · 307 comments
What HN said:
Quitschquat: You might be looking at these old Unix GUIs thinking they're shit compared to now, but actually, at the time, they were shit too.
vessenes: Amazing walk through memory lane, and super useful. One big omission though - starting in the early 1990s, we should be seeing some Linux desktops in there, but I didn’t see any through 1995 or so when I stopped browsing.
hermitcrab: Invisible scroll bars are a source of constant annoyance. And it sometimes takes me several attempts to move a window, because of all the various clickable things without visible boundaries. Frustrating.
giamma: No mention of GeOS! https://en.wikipedia.org/wiki/GEOS_(8-bit_operating_system) https://en.wikipedia.org/wiki/Berkeley_Softworks
513 points by tokenburner · 167 comments
Replace Ads with They Live style slogans. Contribute to davmlaw/they_live_adblocker development by creating an account on GitHub.
What HN said:
AdmiralAsshat: Misread the title to mean that They Live inspired the concept of adblocking in general. Which would have been an interesting coincidence, since it did inspire one of the early Mozilla logos. [0] [0] https://www.jwz.org/blog/2016/10/they-live-and-the-secret-hi...
EvanAnderson: Back in the late 90s I stood up a webserver in my office that returned fake banner ads for 404's. I used the in-house DNS server to vector "*.doubleclick.net" over to it.
bloke_zero: I wish I could upvote this 10 times! I love the film - blew my mind when I saw it on cable just after it came out.
riedel: Replacing ads reminds me of the eye tap AR stuff by Steve Mann https://news.ycombinator.com/item?id=44406552
465 points by surprisetalk · 94 comments
In reply to an email asking about learning software design skills as a researcher physicist:
What HN said:
CSMastermind: I'll give you the cheat sheet: - Good design is a single idea pervaded throughout. - More generally, your goal should be to minimize surprise. - If your system allows it, people will do it. - Everyone will not just. If your solution starts with "if everyone will just...
mpweiher: The recommendations are often very good, for example Ousterhouts A Philosophy of Software Design, but seem to be on software development in general, not actually software architecture in particular.
miki123211: In this vein, I really recommend "Architecture of Open Source Applications."[1] It's a book series where you learn architecture by example, with each chapter written by a maintainer of the project in question.
ah1508: I think that words like "clean code" or "beautiful code" does help juniors to learn best practices of software architecture. - Junior asks to senior: what did you we use an ORM ? - senior answers: because it's cleaner.
333 points by ibobev · 30 comments
This article explores how to render realistic skies and atmospheres in real time in the browser with shaders, from simple sky domes, to entire planets using shaders, raymarching, Rayleigh and Mie scattering, and ozone absorption.
What HN said:
etra0: I saw this a while ago so it might not be totally related, but Sebastian Lague did a video on atmospheres for his planet generation experiment which was also very entertaining to watch [1].
rollulus: Incredible what mobile phones and browsers can do nowadays. I remember implementing this paper from 1993 (the absolutely OG for this topic and very readable): “Display of The Earth Taking into Account Atmospheric Scattering” by Nishita et al: https://www.researchgate.
mrsharpoblunto: Love a good graphics writeup - I've been working on similar things for my procedural space/planet generator. The cool thing with atmospheric scattering is you can combine it with volumetric cloud rendering and get amazing sunsets & sky scenes https://www.threads.
baliex: This is absolutely fantastic. I've thought before about trying to render skies on the web as a series of gradients overlaid on top of one another. I expect I could have had some level of success and gotten some mediocre results, but it would be nothing compared to what you've cre...
310 points by tambourine_man · 431 comments
Meet Googlebook: A new kind of laptop designed for Gemini Intelligence. Built with heavyweight power and perfectly in sync with your Android Phone. Sign up for updates and stay in the know.
What HN said:
Jzush: Gross. This is just more proof that corporations simply don't know how to market AI. Everything is an ad for an ad at this point. The very first thing they show this new machine doing is helping people shop for clothes using AI. No one is doing that, these people don't exist.
spiralcoaster: What's funny is that these days if I see a Google product that I'm even remotely interested in, I just immediately write it off because I know it's something they will kill in a very short time frame. It's just never worth the hassle of buying/using a Google product. Never.
arjie: I imagine they're going to do the same thing with this as with Chromebooks: i.e. do enterprise deals with schools and so on? Google's iteration-style structure where they kill products is fine for SaaS type offerings that are free and that you don't build your world around, but b...
jerojero: I think if I wanted a cheap laptop I'd probably get the macbook neo, and if i wanted a non-gaming expensive one i'd get a macbook pro. I really don't see the market fit for this, I guess the android integration.
192 points by nilirl · 85 comments
Why senior developers talk in terms of complexity while the rest of the business is worried about uncertainty — and what to do about it now that AI is in the picture.
What HN said:
hamstergene: Because the most important parts of the expertise are coming from their internal "world model" and are inseparable from it. An average unaware person believes that anything can be put in words and once the words are said, they mean to reader what the sayer meant, and the only dif...
lnenad: As a /senior/ developer I really dislike blanket statements. I've seen the same amount of failures caused by > “Do we really need that?” > “What happens if we don’t do this?” > “Can we make do for now? Maybe come back to this later when it becomes more important?” as with experim...
hirako2000: Most proof of concepts I've seen get traction turned into production. A rewrite? I recall a few times everyone promised, if this gets promoted then we will rewrite it from zero. Never happened. The article touches on responsability, accountability. There is none for risk taker.
nullorempty: What I found is that my willingness to communicate and share my expertise is usually not in demand with more junior developers. In general, I find developers uninterested in finding a mentor.
185 points by xz18r · 69 comments
Introducing the new Obsidian Community site and developer dashboard.
What HN said:
kepano: Obsidian CEO here. We've been working for nearly a year to launch this new Community site and review system. I'm very excited about this first version but there are many more improvements to come.
dtkav: For those not aware, it has basically been impossible to submit new plugins due to the manual review (and how easy/fun it is to write a plugin with AI). The developer community was becoming increasingly frustrated, and the team was burning out under the load.
sundarurfriend: I don't use Obsidian, and my assumption when I saw the title was I guess they're gonna be limiting it to a small set of corporate-blessed plugins. I've come to expect that "The Future Of XYZ" titles from software companies means severely limiting XYZ or preparing XYZ for a shut d...
varun_ch: I’m not convinced that automated checks will be able to reliably assess whether a plugin is malicious. I think the best (only?) way to solve the plugin security problem would be to properly sandbox them with an explicit API and permission system.
AI/ML
Other
Security
Stories and comments sourced from Hacker News public API. Not affiliated with Y Combinator or Hacker News.