0. Android 17 is the first since 3.x to add new APIs without releasing to the AOSP (grapheneos.social)
1159 points · 704 comments · by theanonymousone
GrapheneOS says Android 17 QPR1 introduces standard APIs and security patches unavailable to AOSP and other OEMs until QPR2 in December 2026, forcing projects to reverse-engineer updates while giving Pixel devices months of exclusive access. [src]
1. Microsoft exec called AI scraping 'the largest theft of labor in human history' (techcrunch.com)
936 points · 825 comments · by pluc
Unsealed filings in The New York Times’ copyright lawsuit allege Microsoft and OpenAI executives acknowledged AI scraping as theft, while internal documents described publishers’ work as an existential threat and revealed alleged paywall bypassing, mass copying, and copyright-notice removal. [src]
2. I don't like passkeys (hawksley.dev)
832 points · 803 comments · by ethanhawksley
The author argues that while passkeys prevent phishing and data-breach credential theft, their recovery, device-loss, platform-dependence, hardware limits, and cross-device usability problems make them premature for individuals, who may be better served by password managers and independent TOTP apps. [src]
3. Cloudflare Quick Tunnels (try.cloudflare.com)
829 points · 316 comments · by jcbhmr
Cloudflare Quick Tunnels expose a local server through a temporary, encrypted HTTPS URL without an account, DNS setup, or open inbound ports, with JSON output and webhook support for coding-agent workflows. [src]
4. Claude Code now reads AGENTS.md if there is no Claude.md (code.claude.com)
730 points · 275 comments · by datadrivenangel
Claude Code 2.1.277 added fallback support for AGENTS.md, reading it for project instructions when no CLAUDE.md file is present, except on Bedrock, Vertex, and Foundry. [src]
5. OpenJev (openjev.com)
712 points · 288 comments · by ilreb
SemIf is a browser-only experiment that runs local open models on users’ GPUs to compare direct option-probability readouts with token-by-token JSON generation, without sending inputs to a backend. [src]
6. US Military had close call after using AI for hallucinated intelligence report (cnn.com)
513 points · 388 comments · by realsarm
A military analyst’s AI-assisted report falsely claimed a Chinese ship carried nuclear-weapons components, nearly prompting an armed interception and highlighting the risks of using unreliable AI-generated intelligence in wartime targeting. [src]
7. A heap overflow and SSO misconfiguration to compromise OpenAI internal repos (hacktron.ai)
486 points · 208 comments · by Handy-Man
Hacktron says it chained a libheif heap overflow in OpenAI’s forum with an SSO flaw to access an employee’s ChatGPT/Codex account and demonstrate internal GitHub repository access, prompting patches, disclosure coordination, and a $6,500 bounty. [src]
8. Saving another 100TB of RAM (blog.cloudflare.com)
476 points · 118 comments · by f311a
Cloudflare used Rust memory compaction and mathematical analysis to reduce Pingora’s consistent-hashing data by 90%, reclaiming 100TB of RAM globally while carefully migrating traffic to avoid cache disruption. [src]
9. Minimal Phone 2 (minimalcompany.com)
324 points · 255 comments · by nashashmi
Minimal’s Phone 2 is a compact Android smartphone with a physical QWERTY keyboard, distraction-limiting Minimal OS, full app access, and 5G, available for preorder from $599 with shipping planned for December 2026. [src]
10. I vibed a proof of Conway's conjecture (overreacted.io)
268 points · 294 comments · by m-hodges
I vibed a proof of Conway's conjecture: <a href="https://github [src]
11. Bend 2 and the Vibe-Coding Trap (blog.liampwll.com)
326 points · 235 comments · by LiamPowell
The article uses Bend 2 to argue that vibe-coding can let developers build verbose, outdated systems without researching existing solutions, contrasting Bend’s 442-line proof with a concise SPARK implementation that automatically verifies the same properties. [src]
12. Warren Buffett Steps Down as Berkshire Chairman, Names Son to Replace Him (nytimes.com)
320 points · 217 comments · by saimiam
Warren Buffett is stepping down as Berkshire Hathaway’s chairman and naming his son as his successor, according to the report. [src]
13. Korea raises data breach fines to 10% of revenue (koreajoongangdaily.com)
334 points · 113 comments · by throw7
South Korea will raise maximum data-breach fines to 10% of annual revenue for companies responsible for major negligent leaks, while requiring faster notifications and offering reductions for robust protection and prompt responses. [src]
14. Inside ZCode: Silently uploading your Git history to the cloud (blog.ferstar.org)
332 points · 112 comments · by csmantle
A reverse-engineering investigation alleges that Zhipu’s ZCode desktop app silently encrypts and uploads complete workspace snapshots—including Git history, LFS assets, and configuration files—to Aliyun OSS whenever users are logged in, with no effective in-app opt-out. [src]
15. Jemalloc 5.4.0 (github.com)
336 points · 94 comments · by gkfasdfasdf
jemalloc 5.4.0 delivers over 160 commits with refactoring, bug fixes, improved testing and portability, new pinned-memory statistics and arena controls, adaptive tcache policies, and numerous compatibility and stability improvements. [src]
16. Border agents can search cellphones without a warrant or reasonable suspicion (lawandcrime.com)
231 points · 196 comments · by mmh0000
The 2nd Circuit ruled that border agents may manually search travelers’ cellphones without a warrant or reasonable suspicion, upholding evidence used to convict green-card holder Chinwendu Alisigwe while leaving open whether advanced forensic searches require suspicion. [src]
17. North Korean nuclear test sets off years of earthquakes (science.org)
223 points · 180 comments · by rbanffy
A North Korean nuclear test triggered earthquakes that continued for years, according to the report. [src]
18. The scourge of x86 emulation (fex-emu.com)
291 points · 98 comments · by dagmx
FEX details how ARM’s weaker memory model makes x86 emulation costly and sometimes incorrect, while newer features and hardware TSO modes improve performance but leave major challenges around unaligned atomics, split-locks, and uncached memory. [src]
19. Show HN: Cactus Needle 3: 8-29MB automation models can match DeepSeek V4 Flash (cactuscompute.com)
231 points · 91 comments · by HenryNdubuaku
Cactus released Needle 3, a set of 8–29MB multilingual models for tool calls and structured JSON, claiming up to 86% on Mobile Actions and performance comparable to larger models on narrow, fine-tuned tasks. [src]
Brought to you by ALCAZAR. Protect what matters.