Top 27 stories from Hacker News. Top 10 include comment highlights. Compiled at 20:00 UTC.
894 points by bumbledraven · 449 comments
What HN said:
dajonker: > Making Kubernetes good is inherently impossible, a project in putting (admittedly high quality) lipstick on a pig. So well put, my good sir, this describes exactly my feelings with k8s. It always starts off all good with just managing a couple of containers to run your web app.
stingraycharles: Potentially useful context: OP is one of the cofounders of Tailscale. > Traditional Cloud 1.0 companies sell you a VM with a default of 3000 IOPS, while your laptop has 500k.
aliasxneo: There's a common conversation that goes on around AI: some people swear its a complete waste of time and total boondoggle, some that its a good tool when used correctly, and others that its the future and nothing else matters. I see the same thing happen with Kubernetes.
sahil-shubham: The point about VMs being the wrong shape because they’re tied to CPU/memory resonates hard. The abstraction forces you to pay for time, not work. I ended up buying a cheap auctioned Hetzner server and using my self-hostable Firecracker orchestrator on top of it (https://github.
806 points by cdrnsf · 180 comments
The iPhone and iPad bug allowed law enforcement using forensic tools to read messages that had long been deleted by the Signal app.
What HN said:
dlcarrier: This was a bug that left it cached on the device. Apple and Google have put themselves in the middle of most notifications, causing the contents to pass through their servers, which means that they are subject to all the standard warrantless wiretapping directly from governments...
6thbit: The "bug" discussed in the article is only part of the problem. The main problem, which is notifications text is stored on a DB in the phone outside of signal, is not addressed. To avoid that you have to change your settings.
modeless: Oh, I was originally confused about this because I had thought the push notifications were end-to-end encrypted, so they couldn't be cached in readable form by the push notification service, and only decrypted by the app on device upon receiving the notification.
nxobject: Note that Signal offers the option to use generic “You’ve received messages” notifications - it’s good practice in general.
604 points by rd · 257 comments
What HN said:
tedsanders: Just as a heads up, even though GPT-5.5 is releasing today, the rollout in ChatGPT and Codex will be gradual over many hours so that we can make sure service remains stable for everyone (same as our previous launches).
simonw: This doesn't have API access yet, but OpenAI seem to approve of the Codex API backdoor used by OpenClaw these days... https://twitter.com/steipete/status/2046775849769148838 And that backdoor API has GPT-5.5. So here's a pelican: https://gist.github.
Someone1234: I'd like to draw people's attention to this section of this page: https://developers.openai.com/codex/pricing?codex-usage-limi... Note the Local Messages between 5.3, 5.4, and 5.5. And, yes, I did read the linked article and know they're claiming that 5.
astlouis44: A playable 3D dungeon arena prototype built with Codex and GPT models. Codex handled the game architecture, TypeScript/Three.js implementation, combat systems, enemy encounters, HUD feedback, and GPT‑generated environment textures.
463 points by tosh · 223 comments
Bitwarden CLI 2026.4.0 was compromised in the Checkmarx supply chain campaign after attackers abused a GitHub Action in Bitwarden’s CI/CD pipeline.
What HN said:
lxgr: What's particularly impressive about this attack is that the attackers must have precisely coordinated it with Github not being down.
ef2k: The issue was a compromised build pipeline that shipped a poisoned package. But PSA: If something is critical to the business and you’re using npm, pin your dependencies.
eranation: Anyone know of a better way to protect yourself than setting a min release age on npm/pnpm/yarn/bun/uv (and anything else that supports it)? Setting min-release-age=7 in .npmrc (needs npm 11.
ruuda: https://github.com/doy/rbw is a Rust alternative to the Bitwarden CLI. Although the Rust ecosystem is moving in NPM's direction (very large and very deep dependency trees), you still need to trust far fewer authors in your dependency tree than what is common for Javascript.
425 points by tobr · 124 comments
What HN said:
dspillett: Everything should try do some basic syntax highlighting IMO. Not too much, or it just becomes a sea of formatting that doesn't help at all. It is surprising how much difference just a little splash of colour can make if it isn't overdone.
cuechan: For anyone who regularly has to look at/analyze binary files, i highly recommend ImHex [1]. Its a hex editor built with imgui and has a lot of built in tools. Imo the best feature is the data structure editor.
roelschroeven: When you're going to color-code bytes in a hex dump, I would expect each ASCII character in the right column to have the same color as the hex byte in the left column, making it easier to pair them. I wonder why that wasn't done here.
Findecanor: If you're making a hex editor and going to have colour coding, I'd think you expend some effort to make the colouring schemes configurable — and easy to configure and change. Maybe load and save as separate files. Different colouring schemes for different types of data.
352 points by mentalgear · 122 comments
The Citizen Lab found two separate surveillance vendors abusing the backbone of cellular networks to spy on several victims across the world.
What HN said:
DrewADesign: I was training to be a 911 dispatcher a while ago. When they told us about getting someone’s location from the cell company outside of what was available automatically from e911 or whatever— which required them to be on the phone with you, so not useful if you get a text saying t...
areoform: One of the biggest lies about the surveillance state is that it'll be professional. NSA employees have used multi-billion dollar American surveillance assets to spy on women they're infatuated with. There's even a cute term for it, LOVEINT. https://www.nbcnews.
aetherspawn: Yeah, a friend of mine was tracked by a stalker ex boyfriend who worked at a Telco. It was irritatingly difficult to avoid because it seemed he could look up her SIM card by name and then get her location no matter what (new SIM, new phone) Anyone who reports this kind of thing t...
Anonyneko: This is just par for the course in Russia. Government has telcos track people, and that data ends up available on the black market for anyone to purchase, for a fairly modest fee.
317 points by mfiguiere · 193 comments
What HN said:
6keZbCECT2uB: "On March 26, we shipped a change to clear Claude's older thinking from sessions that had been idle for over an hour, to reduce latency when users resumed those sessions.
bityard: My hypothesis is that some of this a perceived quality drop due to "luck of the draw" where it comes to the non-deterministic nature of VM output. A couple weeks ago, I wanted Claude to write a low-stakes personal productivity app for me.
arkariarn: I see some anthropic claude code people are reading the comments. A day or two ago I watched a video by theo t3.gg on whether claude got dumber. Even though he was really harsh on anthropic and said some mean stuff.
podnami: They lost me at Opus 4.7 Anecdotally OpenAI is trying to get into our enterprise tooth and nail, and have offered unlimited tokens until summer. Gave GPT5.4 a try because of this and honestly I don’t know if we are getting some extra treatment, but running it at extra high effort...
314 points by robtherobber · 105 comments
France Titres, the government agency in France for issuing and managing administrative documents has disclosed a data breach after a threat actor claimed the attack and stealing citizen data.
What HN said:
hk__2: > the data stolen in the breach could include full names, dates and places of birth, mailing and email addresses, and phone numbers on an undisclosed number of citizens Nothing really new here sadly, this information about me have leaked half a dozen of times in the past 2-3 year...
loupol: I received the email telling me I am impacted today. Ironically it changes nothing for me as that same data had already been leaked by the French government agency that handles unemployment benefits a couple years ago.
rawgabbit: It seems to me we must move away from worrying about ransomware, data breach, data protection as that ship has already sailed and everyone's PII has already been stolen. We should think of how to verify people's identities online (for things like government benefits etc).
kleene_op: I find it especially ironic that they would leak all my data, given the fact that they would ask of me to forward them every piece of id imaginable whenever I needed to forge or amend a new one (when adding a mention on my driver's license for instance).
285 points by pavel_lishin · 195 comments
Interviews with current and former Palantir employees, along with internal Slack messages obtained by WIRED, suggest a workforce in turmoil.
What HN said:
Ritewut: Everyone in this industry should be required to read Careless People by Sara Wynn-Williams about her tenure at Facebook. Not because the book is about how evil Meta/Facebook is as a company but because you get to see the lengths people go to mentally convince themselves they are...
leonidasrup: Palantir employees should understand that they are not regular employees at a regular company. They are U.S. defense contractors at an U.S. defense company. Also Palantir customers should understand that by buying Palantir services/products they are doing business with U.S.
hn_user82179: > “I’m curious why this had to be posted. Especially on the company account. On the practical level every time stuff like that gets posted it gets harder for us to sell the software outside of the US (for sure in the current political climate), and I doubt we need this in the US?...
HaloZero: If you haven't listened/read it, I think the Ezra Klein interview with Alex Bores (who formerly worked at Palantir) and how he talks about how it was in 2014 vs now. It's also insane that a PAC campaigning against Bores is funded by current Palantir employee Lonsdale.
261 points by maxloh · 90 comments
As a follow-up to the similar milestone reached for our WSL image a few months ago, I’m happy to share that Arch Linux now has a bit-for-bit reproducible Docker image! This bit-for-bit reproducible image is distributed under a new “repro” tag.
What HN said:
nickjj: It is nice to have this confidence. I ran Arch Linux for almost a year in WSL 2, it was really good. Then I ran Arch natively for ~5 months, it's really good. Now I still run Arch natively, but I also use the Arch Docker image to test my dotfiles[0] with a fresh file system.
red-iron-pine: Presumably there is something you can plug into the CI/CD pipeline that informs everyone one you use Arch (and, also presumably, that you do Crossfit, etc.)
dev_l1x_be: All docker containers should have been like that. apt-get update in a docker build step is an anti pattern.
kippinsula: reproducible images are one of those features where the payoff is mostly emotional until the day it isn't. we had an incident where two supposedly identical images on two machines had a three byte delta in a timestamp and it cost us an afternoon to bisect from the wrong end.
AI/ML
Business/Tech
Other
Programming
Stories and comments sourced from Hacker News public API. Not affiliated with Y Combinator or Hacker News.