Top 29 stories from Hacker News. Top 10 include comment highlights. Compiled at 20:10 UTC.
1254 points by CliffStoll · 195 comments
What HN said:
hoppyhoppy2: Thank you for the update, Cliff. I will update your Wikipedia page to show that your death is currently under dispute.
SneakyMission: Dear Cliff, I'm terribly sorry to hear of your passing, but am pleased that you have since gotten better. Cheers!
jmuguy: Hmm, I don't believe you. In order to prove you're alive please make an updated Youtube video with a tour of your crawlspace warehouse.
hananova: Hi Cliff! Your book the Cuckoo's Egg got me both (more) into IT, as well as helped my English proficiency go from basic to proficient. Back when I was 12, I was checked out in school, and my English teacher noticed here in Belgium.
1224 points by PriorityLeft · 867 comments
What HN said:
AloysB: This is awkward. Exhibit A - September 2025 - "Help build the future" - Cloudflare hires 1111 interns to "help build the future" [https://blog.cloudflare.com/cloudflare-1111-intern-program/] Exhibit B - May 2026 - "Building for the future" - Cloudflare lays off 1100 people, about...
ggoo: > The packages for departing employees will include the equivalent of their full base pay through the end of 2026. Healthcare coverage is different across the globe, and if you’re in the United States, we’ll continue to provide support through the end of the year.
Snoozle: "We are our own most demanding customer. Cloudflare’s usage of AI has increased by more than 600% in the last three months alone. Employees across the company from engineering to HR to finance to marketing run thousands of AI agent sessions each day to get their work done.
piperswe: Welp, looks like I’m affected. If anyone is looking to hire a systems engineer with distributed systems and load balancing experience, shoot me an email at @piperswe.me :/ I’ll update this with a resume link tonight…
885 points by stefanpie · 589 comments
Instructure’s learning management platform Canvas is down, after recently confirming a data breach and a ransom message from the ShinyHunters hacking group.
What HN said:
blahedo: Perspective from the trenches: I teach at a university that uses Canvas. We are in our final exams period right now. We got our first email (from Academic Affairs) notifying us that it was down at 5:17pm EDT this afternoon, with little info; followup emails were sent at 6:24 and...
Gabriel54: I'm surprised how few comments there are on this thread. This is probably affecting millions of students at the most stressful time of the year. Incidentally I've always hated Canvas and probably every other LMS provider, but what is particularly amusing about this current outag...
myrandomcomment: 1. It should be illegal for any company to pay ransomware attacks. Period. No pay out ever. 2. The penalty for being the attacker should be linked to the system they violated. If you do this to a hospital and someone dies you are life in prison / chair.
kelnos: A friend who teaches at MIT said they were hit by this. I found it ironic and a little sad that a place like MIT doesn't have an IT staff that can maintain their own on-prem solutions for things like this.
790 points by psxuaw · 410 comments
Oh boy yet more linux kernel vulns
What HN said:
marcus_holmes: This was always a nightmare waiting to happen. The sheer mass of packages and the consequent vast attack surface for supply chain attacks was always a problem that was eventually going to blow up in everyone's face. But it was too convenient.
CriticalRegion: This is a baffling take.. These exploits are local privilege escalations for linux systems. They'll allow an attacker with a foothold in a shared environment or with low privilege access to a system to affect the rest of the system.
0xbadcafebee: "Wait a week to install software" does not work. Just a few months ago a massive exploit hit the web, which was a timed attack which sat for more than a month before executing. If everyone starts waiting a week, their exploits will wait 2 weeks.
XCabbage: Sorry, I don't get it. What's the chain of reasoning that connects "there are a couple of new Linux local privilege escalation exploits" to "don't install any new software"? Is the threat we're supposed to be concerned about here just a package maintainer publishing malware that...
783 points by surprisetalk · 670 comments
Poland once was in economic ruins when communism fell more than three decades ago. Now it's the 20th largest economy in the world.
What HN said:
jakozaur: The story is longer: Poland was the first country to make a remarkable peaceful transition from a bankrupt, failed Soviet satellite state. The shock therapy, plus NATO and EU aspirations, paved the way.
VimEscapeArtist: I live in Poland. This headline is misleading. Poland didn't build a top-20 economy. Western Europe and the US built their economy in Poland, because the labor is educated and cheap. There are almost no globally competitive Polish companies.
steve_adams_86: Years ago I bought some really nice brushless motors and was surprised to see they were made in Poland. I had no idea they were manufacturers of things like that. Later I bought even nicer motors, meant to provide exceptional control and feedback for tactile/haptic behaviours, an...
niemandhier: I love the polish, but credit where credit is due: „Poland is the largest beneficiary of EU funds 2014-2020, with one in four euro going to Poland“ https://www.gov.pl/web/funds-regional-policy/poland-at-the-f... Update: The comments below this are strange.
524 points by ribtoks · 254 comments
In May 2026, Google announced “Google Cloud Fraud Defense - the next evolution of reCAPTCHA.” The announcement described a QR code challenge where users scan a
What HN said:
jeroenhd: I saw this coming from miles away. Computers are better at solving CAPTCHAs than people are and people can be bribed or convinced to join botnets so IP whitelisting doesn't work either.
Havoc: Whether it's AMP or manifest 3 or android source shenanigan or attempts to replace cookies with their FLOC nonsense or this...Google is rapidly turning into a malicious force when it comes to the open internet
SwellJoe: From "Don't be evil" to building the largest, most invasive, surveillance operation the world has ever seen. That was true before this, but this indicates nothing will ever be enough.
jchw: Exactly my thoughts. I am unfathomably angry and I want to contribute to any effort to dismantle Google as a company.
417 points by mwheelz · 209 comments
A web page that tells you what your browser gave away the moment you arrived. No login, no form, no permission. Most pages do this. None of them tell you.
What HN said:
cortesoft: Maybe it's just because I am old, or have worked on internet software for almost 30 years, but none of this seems surprising or even concerning? Someone sets up a server that accepts connections to it and then someone sends a connection request to it.
mmh0000: Wow! Somebody with ChatGPT discovered the concept of browser headers, then for some odd reason made the verbiage really ... weird "We chose not to tell you"... okay... Anyway, if you really want to know what your browser is sending: https://browserleaks.
simonw: Cute detail: if you switch to another tab and then back again it shows a banner at the top: > You left for 6.3 seconds. We noticed.
card_zero: * I'm not in that city. * It's running a kind of Chrome on a kind of Linux, at a stretch. * Nobody can infer when I work and when I sleep. That includes me. * The recent, high-end display is the screen of a low-end tablet I bought in a supermarket five years ago.
308 points by ColinWright · 116 comments
Discover Meshtastic: a community-driven, open-source project using LoRa radios for long-range, off-grid communication.
What HN said:
Cyan488: I had never heard of this before, then last week I watched a video about it and was hooked. Now I'm seeing it everywhere! Meshtastic and Meshcore are both cool LoRa-based mesh text messaging that operate in an no-license-required band.
walrus01: For people who don't think they have an immediate use for either meshtastic or meshcore, it's fine to disregard it and just dig in further into the capabilities of the LoRA radios used.
moffers: I took a plunge into learning about mesh networks, specifically because I love the idea of p2p/decentralized systems of communication. To be honest, I was surprised to find that my expectations for “where we are at” with this type of technology was pretty off-base.
yardie: I've been using Meshtastic for years. Still have a few Heltec v2 nodes running. It's been a lot of fun. It also encouraged me to get my HAM license since most of the local meshtastic/meshcore users are also in the radio clubs. It reminds me of the early internet.
208 points by mittermayr · 195 comments
What HN said:
jandrewrogers: This is surprisingly common. The security of UUIDv4 is based on the assumption of a high-quality entropy source. This assumption is invalidated by hardware defects, normal software bugs, and developers not understanding what "high-quality entropy" actually means and that it is re...
throwaway_19sz: Funny story no one will believe, but it’s true. A good friend of mine joined a startup as CTO 10 years ago, high growth phase, maybe 200 devs… In his first week he discovered the company had a microservice for generating new UUIDs.
smokel: Multiple times have I blamed compilers, cosmic rays, quantum effects, or at the very least an obscure kernel bug, before realizing that I was the source of a bug. A collision at 15,000 records is so unlikely that I would first suspect something else.
kst: This reminds me of a passage from the book "Pro Git". https://git-scm.com/book/en/v2 "Here’s an example to give you an idea of what it would take to get a SHA-1 collision. If all 6.
200 points by sbt567 · 140 comments
What HN said:
coppsilgold: Python is basically the master glue language at this point. If more than a few percent of execution time is spent in Python you are probably doing it wrong. Personally I don't even understand why Cython is a thing, just write performance critical functions in other languages: <ht...
totalperspectiv: Having written a lot of Mojo over the last two year, just for fun, it's a really cool language. Ownership model adjacent to Rust, comptime that is more powerful than Zig, Rich type system, first class SIMD support, etc.
ainch: As someone in ML who's interested in performance, I'm keen for Mojo to succeed - especially the prospect of mixing GPU and CPU code in the same language. But I do wonder if the changes they're making will dissuade Python devs.
modeless: When I first heard about Mojo I somehow got the impression that they intended to make it compatible with existing Python code. But it seems like they are very far away from that for the foreseeable future.
AI/ML
Business/Tech
Other
Society
Stories and comments sourced from Hacker News public API. Not affiliated with Y Combinator or Hacker News.