1
Security Exploit 🛡️
The Newest Instagram "Exploit" is the Goofiest I've Seen | Sid's Blog Yesterday, a slew of Instagram accounts, including some high profile ones like the Obama White House account, seemingly got hacked. I’ve spent almost a decade and a half identifying vulnerabilities and exploits at unicorn scale, but this is hands down the most unserious, "almost too stupid to be true" of them all. Step 01: Faking the Location & Initiating Support All the attacker needs to kick this off is your account username. Then, they hop on a VPN or proxy close to your city so Instagram's security algorithms don't suspect a thing.
Actionable Insight
This "goofiest" exploit, leveraging simple social engineering tactics like faking location and initiating support with just a username, exposes a critical flaw in Instagram's account recovery processes. It underscores how major platforms can still be vulnerable to surprisingly low-tech attacks that exploit procedural gaps rather than complex code, bypassing seemingly sophisticated security algorithms.
0xsid.com
·
2151 pts
·
474 comments
·
by ssiddharth
2
🤖 AI & User Experience
Gmail Thinks I'm Stupid, So I Left | moddedbear.com I go to check my email in Gmail’s web UI. I see a few new messages regarding feedback on a project I’m working on. I click through to read one of them and the first thing I’m greeted with is a message summary I didn’t ask for generated by a language model. I focus the message box to draft a reply, but there’s already one there.
Actionable Insight
This post highlights a growing tension between intrusive AI features and user autonomy, where unsolicited AI summaries and reply drafts are perceived as presumptuous rather than helpful. It underscores a critical challenge for product designers to balance innovation with user control, as aggressive default AI integration can alienate users and drive them away from established services.
moddedbear.com
·
957 pts
·
631 comments
·
by speckx
3
🔒 Security Vulnerability
1-Click GitHub Token Stealing via a VSCode Bug – Ammar's Blog Just by clicking a link, it’s possible for an attacker to steal a GitHub
token that can read and write to your repos, including private ones . Did you know GitHub has this really cool feature called github.dev ? On any repository you have access to, if you can change the url from github.com to github.dev or you click this little menu item: You’ll be launched into a little light-weight version of VSCode that runs
entirely in your browser (I guess that’s one advantage of having your app
written with electron).
Actionable Insight
This critical "1-click" exploit leverages a flaw in the `github.dev` browser-based VSCode environment to steal GitHub tokens, granting an attacker full read/write access to a user's repositories, private ones included. This vulnerability poses a significant supply chain risk and highlights the inherent dangers of integrating powerful developer tools and sensitive credentials within a web browser context. It underscores the urgent need for robust security-by-design in modern development workflows and rigorous input validation across interconnected services.
blog.ammaraskar.com
·
402 pts
·
60 comments
·
by ammar2
4
⚖️ **Legal Dispute**
Adafruit Industries – Makers, hackers, artists, designers and engineers!
Actionable Insight
This demand letter from Fenwick legal counsel on behalf of Flux.ai signifies a serious legal challenge for Adafruit, a prominent open-source hardware company. It likely involves intellectual property or competitive practices, posing a direct threat to Adafruit's operational freedom and highlighting the growing tensions between open-source principles and proprietary commercial interests in the tech hardware sector.
blog.adafruit.com
·
648 pts
·
267 comments
·
by semanser
5
Observability
Hi HN, I'm one of the founders of s2.dev. RePlaya ( https://github.com/s2-streamstore/replaya ) is a self-hosted browser session replay tool using rrweb ( https://github.com/rrweb-io/rrweb ). It occurred to me that a durable stream per session would be a much neater architectural foundation for much of what you'd want from such a tool. As a unique feature, it also made live tailing straightforward because the player can read from the same stream the recorder is appending to. The alternative architecture is likely an ingest firehose which is then indexed, with associated complexity and latency.
Actionable Insight
🔎 RePlaya offers a clever architectural shift for browser session replay by leveraging durable streams per session, which naturally facilitates live tailing and bypasses the complexity of traditional ingest firehose designs. This self-hosted solution provides a more efficient and real-time approach to understanding user interactions, a critical component for debugging and enhancing web applications. Its unique streaming foundation could set a new standard for performance and simplicity in session replay tools.
github.com
·
43 pts
·
7 comments
·
by shikhar
6
🤖 AI Development
Introducing MAI-Code-1-Flash | Microsoft AI Skip to main content Source Signal blog Official Microsoft Blog Microsoft On The Issues Asia Canada Europe, Middle East and Africa Latin America The Code of Us Conexiones What's new today AI Innovation Digital Transformation Sustainability Security Work & Life Diversity & Inclusion Unlocked Microsoft 365 Azure Copilot Windows Surface XBOX Deals Small Business Support Windows Apps Outlook OneDrive Microsoft Teams OneNote Microsoft Edge Moving from Skype to Teams Computers Shop XBOX Accessories VR & mixed reality Certified Refurbished Trade-in for cash XBOX Game Pass Ultimate PC Game Pass XBOX games PC games Microsoft AI Microsoft Security Dynamics 365 Microsoft 365 for business Microsoft Power Platform Windows 365 Small Business Digital Sovereignty Azure Microsoft Developer Microsoft Learn Support for AI marketplace apps Microsoft Tech Community Microsoft Marketplace Software companies Visual Studio Microsoft Rewards Free downloads & security Education Gift cards Licensing Unlocked stories View Sitemap Today we’re introducing MAI-Code-1-Flash, a new Microsoft coding model built for fast, efficient assistance in everyday developer workflows. It is built end-to-end by Microsoft using clean and appropriately licensed data. The model is rolling out to GitHub Copilot individual users in Visual Studio Code in the model picker and under the default auto picker.
Actionable Insight
Microsoft's MAI-Code-1-Flash reinforces its commitment to AI-powered developer tools, offering fast coding assistance directly within GitHub Copilot and VS Code. Crucially, the model's development using "clean and appropriately licensed data" addresses pressing industry concerns about data provenance and intellectual property. This strategic move aims to build trust among developers while significantly enhancing productivity within Microsoft's vast ecosystem.
microsoft.ai
·
470 pts
·
209 comments
·
by EvanZhouDev
7
Construction Tech 🏗️
Hi HN, we’re Rishi and Sahil. We’ve developed Rudus ( https://www.rudus.ai/ ), an AI-powered takeoff and estimation platform built for concrete subcontractors. Takeoff is the process of measuring and quantifying materials from concrete plan sheets. Rudus identifies every concrete structure (footings, walls, columns, slabs), pulls in related details, and eliminates hours of manual quantity calculation. Here’s a demo: https://www.youtube.com/watch?v=PAMNDRWEdlI . The problem: Concrete subcontractors are the backbone of every building, but their estimating workflow hasn't changed in 20 years. Rig
Actionable Insight
This Launch HN strategically targets a specific, historically underserved niche within the massive construction industry – concrete estimation. By applying AI to automate the tedious "takeoff" process, Rudus promises significant time savings and accuracy improvements for subcontractors, addressing a workflow that has remained largely unchanged for decades. This exemplifies the growing trend of specialized AI solutions bringing crucial digital transformation to 'legacy' industries with high-value, manual tasks.
news.ycombinator.com
·
35 pts
·
16 comments
·
by rishipankhaniya
8
⚛️ Quantum Computing Controversy
Community discussion highlights: It really looks like they are trying hard to scale a system that is simply explained away by a simpler model... From TFA: The switching behavior they see could just be an electron hopping on and off a quantum dot, perhaps one formed incidentally by part of the wirelike region, Legg says. “This is exactly what you could get from a quantum dot.” I won't pretend I have a deep understanding of any of this, so the only parameters I can judge is the consensus of people that do, and these people aren't
Actionable Insight
Microsoft's continued push for controversial quantum computing claims, despite the scientific community offering simpler, classical explanations for observed phenomena, underscores the immense pressure and speculative nature surrounding frontier technologies. This situation highlights the critical importance of rigorous peer review and independent validation in distinguishing genuine breakthroughs from potential misinterpretations or overhyped assertions in high-stakes scientific endeavors.
science.org
·
28 pts
·
27 comments
·
by igortru
9
🔧 Hardware Hacking
Community discussion highlights: This awesome! I actually had no idea I could ssh into my Remarkable and do neat stuff like this! > Why do it? It's so impractical! Because you can and it's fun is always a perfectly valid answer here!
Actionable Insight
This project perfectly embodies the hacker ethos of "because you can," transforming a specialized e-ink tablet into an unconventional handwritten Clojure REPL. It highlights the often-underestimated potential of devices like the reMarkable 2 as platforms for creative software development and unique user interfaces, defying standard usage models for the joy of exploration.
handwritten.danieljanus.pl
·
20 pts
·
2 comments
·
by nathell
10
💻 Architecture & Assembly
Writing portable ARM64 assembly · Ariadne's Space An unfortunate side effect of the rising popularity of Apple’s ARM-based
computers is an increase in unportable assembly code which targets the
64-bit ARM ISA. This is because developers are writing these bits of
assembly code to speed up their programs when run on Apple’s ARM-based
computers, without considering the other 64-bit ARM devices out there,
such as SBCs and servers running Linux or BSD. The good news is that it is very easy to write assembly which targets
Apple’s computers as well as the other 64-bit ARM devices running
operating systems other than Darwin. It just requires being aware of
a few differences between the Mach-O and ELF ABIs, as well as knowing
what Apple-specific syntax extensions to avoid.
Actionable Insight
The increasing adoption of Apple Silicon has inadvertently fostered a generation of ARM64 assembly code optimized solely for Apple's ecosystem, neglecting broader portability. This article highlights the critical differences between Mach-O and ELF ABIs and Apple-specific syntax, offering practical guidance to write assembly that performs efficiently across diverse ARM64 platforms like Linux servers and SBCs, preventing vendor lock-in and maximizing code reuse.
ariadne.space
·
18 pts
·
2 comments
·
by luu