HN Brief: 2026-07-28

Today on HN, two big threads wrestled with the same anxiety: who gets to control the AI ecosystem, and at what cost. Anthropic’s defense of its open-weights stance sparked a furious debate about rent-seeking and de facto bans, while a deep-dive into Bun’s AI-driven Zig-to-Rust rewrite revealed a messy reality of un-idiomatic code and ballooning PRs that undercut the triumphant narrative. A surprising pattern emerged around AI companies literally shredding rare books for training data, and the mood was rounded out by a judge telling Google it can’t DMCA its way out of being scraped—a ruling that had everyone pointing out the irony. The vibe was one of skeptical watchfulness, with a strong undercurrent that the promised returns on AI investment aren’t materializing the way the hype suggests.

The threads most worth clicking into: the Anthropic open-weights post, for the sharpest split all day on whether mandatory safety testing is just regulation or a backdoor ban; the Bun Rust rewrite investigation, because the gap between the $165,000 claim and the 2,475 open AI-generated PRs is the year’s best case study in engineering reality versus AI hype; the rare books shredding story, for the unexpected legal twist that destroying the physical copy is fair use because only one copy exists at a time; and the SlopCodeBench benchmark on Opus 5, which confirms what practitioners have long suspected about models systematically degrading codebases over multiple edit rounds.

Our position on open-weights models [comments]

830 points · 1195 comments · www.anthropic.com · 9h ago

Anthropic CEO Dario Amodei published a blog post pushing back against accusations that the company wants to ban open-weights models, arguing instead for three targeted measures: keeping chips out of China, cracking down on industrial-scale distillation, and requiring safety testing for all capable models regardless of origin. The comment section immediately split into two camps: one side dismissed the whole thing as transparent rent-seeking, pointing out that Anthropic trained on everyone else's IP and now wants to block others from doing the same, while another group found the position internally consistent and noted that at least Anthropic isn't flip-flopping like OpenAI. A vigorous sub-debate erupted over whether mandatory safety testing amounts to a de facto ban on open models, with the anti-regulation side insisting that failing a test equals being banned, while others countered that we safety-test cars and drugs without calling it censorship. Several commenters took aim at the China-bad framing, arguing the US under its current administration is itself an authoritarian threat, and that handing control of dangerous technology to any set of national gatekeepers—whether Anthropic or the Pentagon—is a terrible idea.

AI companies are shredding rare books [comments]

767 points · 480 comments · x.com · 19h ago

AI companies are paying to have rare books—some the last surviving copies of 18th-century texts—fed through high-speed scanners that cut the spines off and then shred the originals, all facilitated by a service called ISBNdb that offers NDAs and keeps buyers anonymous. The Hacker News thread immediately latched onto the legal angle: a federal judge already ruled this is fair use because destroying the original means only one copy exists at a time, and commenters pointed out the real driver isn't copyright but cost—destructive scanning is cheaper and faster, and after that there's no reason to keep the physical pages. Several people pushed back hard on the framing of "rare books," noting the 404 Media article at the center of this story cited specific titles and all had ISBNs, meaning they're from 1967 or later and still under copyright, not irreplaceable antiques, and that the real issue is that destroying the physical copy prevents competitors from re-scanning the same book. Others steered the conversation toward Vernor Vinge's "Rainbows End," which predicted this exact "shred and scan" factory process as a villainous stepping stone toward non-destructive scanning, and a long side-debate erupted over whether breaking DRM on digital copies would actually be easier than destroying physical books.

How is the Bun rewrite in Rust going? [comments]

465 points · 368 comments · lockwood.dev · 20h ago

The article investigates Bun creator Jarred Summner's claim that Anthropic's AI rewrote Bun from Zig to Rust in 11 days for $165,000, digging into the repo to check whether the rewrite was actually finished or just hyped up for AI valuation purposes. HN immediately spotted the gap between the triumphant narrative and the messy reality—there's still no release tag 11 weeks after the "merge," the number of open Claude-generated PRs has ballooned from 1,277 to 2,475 in three weeks, and Anthropic employees are actively committing to the repo, making the real cost look much closer to $800,000 if you include ongoing CI/CD and API bills. The conversation split into two camps: one arguing the dollar figure is still cheaper than a team of humans (while conceding the resulting Rust is un-idiomatic, packed with `unsafe` blocks, and actually less safe than the Zig it replaced), and another pushing back hard that a human engineering team would have produced maintainable, idiomatic Rust rather than a transpiled mess that needs indefinite AI-driven patching. A recurring thread mocked the "centering a div with CSS" flex as a measure of how much AI hype has distorted actual engineering judgment, and several commenters noted that the entire exercise mirrors the tech industry's vicious cycle of under-investing in engineers while expecting AI to paper over the resulting brain drain.

Kimi-K3 Technical Report [pdf] [comments]

382 points · 168 comments · github.com · 16h ago

The article is the technical report for Kimi-K3, a new open-weight model from Moonshot AI. The thread quickly split into two main conversations: a practical one about how to actually use the model for agentic tasks (with the consensus that you should wait for a fine-tuning API rather than trying LoRA or DPO yourself) and a much larger, more heated debate about whether open-source models like this are actually "decelerationist" or not. People arguing for decel claimed that open weights undercut the profitability of big labs, reducing their incentive to invest in training, while the accel side pointed out that Chinese labs like DeepSeek and Moonshot have been making genuine frontier innovations—like ultra-sparse MoEs and GRPO—that closed labs then copied, making it impossible to claim open research is just fast-following. A few people also pushed back on the whole decel/accel framing itself, calling it reductive and noting that open infrastructure contributions (Moonshot released training tools alongside the paper) move the entire field forward regardless.

Decathlon Germany adds Wero payment option to decathlon.de website [comments]

318 points · 212 comments · www.sgieurope.com · 15h ago

Decathlon Germany turned on Wero, the European bank-backed instant payment system, on its website, making it the first big-box retailer to test whether a direct account-to-account scheme can cut into Visa and Mastercard’s share of checkout. The HN crowd immediately recognized Wero as a scaled-up version of the Netherlands’ iDeal system, which is already the dominant e-commerce payment method in the Benelux, and a lot of the thread was people from different countries comparing their local equivalents—Bizum in Spain, Vipps in Norway, Pix in Brazil—and arguing about which UX pattern actually works best. There’s a split between people who love the QR-code-and-bank-app flow (fast, no card details floating around) and people who insist NFC is superior if only Apple would open it up, with the China-vs-US-vs-EU payments ecosystem comparison running as a constant backdrop. A few commenters pushed back hard on the idea that Wero is anything new, pointing out that it’s just a branded instant bank transfer with merchant fees tacked on, and that the EPC QR standard has existed for years without banks bothering to support it properly. The underlying argument that kept surfacing is whether this is actually a threat to the dollar’s reserve currency status or just a bank-led lobbying effort to kill the digital euro before it could compete.

Judge Rejects Google's Attempt to DMCA Its Way Out of Being Scraped [comments]

296 points · 118 comments · www.techdirt.com · 13h ago

A federal judge dismissed Google's attempt to sue SerpAPI for scraping search results under the DMCA's anti-circumvention clause, ruling that the "SearchGuard" CAPTCHA system doesn't protect copyrighted material in any meaningful way. The thread zeroed in on the glaring hypocrisy—everyone pointed out that Google's entire business was built on scraping the open web, and now they're trying to pull up the ladder. A significant split emerged: some argued that SerpAPI is no saint, relying on shady proxy networks and malware-distributed endpoints to bypass sites that explicitly block scraping, while defenders countered that Google's monopoly power lets them force sites to allow their own crawling while suing anyone else who tries. Others celebrated the ruling as a win for keeping public search data accessible, especially for fighting advertising scams like fake ETA/ESTA sites, but one cynical take warned that this decision also formally validates Google's own massive scraping operation as perfectly legal.

Netflix employee fired for sharing personal details in retreat trust exercise [comments]

280 points · 241 comments · nypost.com · 8h ago

A Netflix VP was fired after he disclosed during a company retreat’s “vulnerability-trust” exercise that he’d undergone doctor-supervised ketamine therapy for depression following his mother’s death. The HN thread landed hard on the idea that these trust exercises are traps — several people argued you should never share anything real at work, and that the whole “bring your whole self to work” line comes with a giant asterisk. Others pointed out the legal mess Netflix walked into by admitting the ketamine therapy factored into the termination, predicting a big payout. A recurring gripe was that companies erased work-life boundaries to boost unpaid overtime, only to punish people for being human. A side tangent debated whether drinking a Guinness while standing on your head qualifies as a party trick or just normal Friday behavior.

A missing underscore sent innocent man to prison for 18 months [comments]

269 points · 151 comments · arstechnica.com · 9h ago

An Ars Technica piece details how a single missing underscore in a Skyrim-themed Kik username—"fus_ro_dah" instead of "fus__ro_dah"—led police to the wrong man, who was convicted and served 18 months in prison before the error was caught on appeal. The thread zeroes in on how the hell a conviction happened with zero evidence tying the guy to the actual crime: no messages on his device, no history of using Kik during the period, just an IP address that matched his home. Commenters are furious that a judge convicted based solely on chat logs attributed to a username the defendant himself used, with no technical expert in the room to flag the underscore mismatch, and they're pointing fingers at his private lawyer, who resigned shortly after sentencing. Some are pushing back on the article itself, arguing it skips the full trial logic and leaves huge gaps—like why his own Kik account didn’t show the incriminating messages—while others veer off into a comparison to the film *Brazil* and a broader critique of how courts just rubber-stamp police technical evidence without independent scrutiny.

AI companies spend record sums on Washington lobbying [comments]

266 points · 141 comments · www.ft.com · 17h ago

The article reports that AI companies like OpenAI and Anthropic have nearly doubled or tripled their federal lobbying spending, now in the low millions. The thread immediately seized on how absurdly cheap that is—pocket change for these firms—and argued that the real influence comes from promises of lucrative post-government jobs, not the official lobbying line items. Several commenters drove home that the numbers are just the tip of the iceberg: politicians are bought by the threat of Super PAC opposition and the prospect of a cushy board seat, not by a few million in disclosed spending. This sparked a wider argument over whether lobbying is honest policy expertise or thinly veiled bribery, with one side insisting it’s just hiring smart people to explain issues, while the other countered that no politician needs to be paid millions to get free expert advice from any company.

Benchmarking Opus 5 on SlopCodeBench [comments]

257 points · 58 comments · github.com · 9h ago

The post benchmarks Anthropic’s newest Opus 5 against older models on SlopCodeBench, a coding benchmark that reveals requirements incrementally rather than dumping the whole problem upfront, forcing models to evolve a codebase across multiple checkpoints without breaking earlier work. The headline result is grim: Opus 5 passed only 4 out of 17 checkpoints, barely beating Opus 4.6’s 17% from the original paper, and no model—including Sonnet 5 and Opus 4.8—finished a single problem with all tests green, even on the “easy” challenge. The real signal in the comments is that the benchmark confirms a long-held suspicion from practitioners: these models are fine at one-shot tasks but systematically degrade a codebase over time, ballooning complexity and verbosity with Opus 5 writing five times as many functions as Opus 4.8 without improvement in outcomes. The thread pivots hard to debating whether this “slop” is a model flaw or a harness/prompting problem—several people argue that constraining agents to narrow seams of the codebase and forcing them to add alongside rather than edit in place matters more than model choice, while others point out that the labs are optimizing for flashy zero-to-one demos, not long-term maintainability. A side argument breaks out about whether models degrade over time due to quantization or inference cost tuning, with people trading anecdotes about Fable losing its edge after an initial golden period.

Canceling "Hey" [comments]

251 points · 207 comments · chadnauseam.com · 14h ago

The article is a personal blog post from a former Hey subscriber explaining why they canceled their $99/year account after DHH, the creator of Hey, published a blog post comparing Romani people to wolves and advocating for their mass deportation. The thread largely sidestepped the original author's extended philosophical argument about "mistake theory" versus "conflict theory" and instead zeroed in on whether DHH's rhetoric was racist or just a blunt policy take about a specific homeless encampment in Copenhagen. A split emerged: some argued DHH was drawing a straightforward analogy about law enforcement failures and that critics were twisting his words, while others pointed to his long history of far-right-aligned writing and the dehumanizing structure of the wolf comparison itself—you shoot all wolves, but you don't deport an entire ethnic group for a dozen people camping. Several people familiar with Nordic politics pushed back against framing the issue as "socialist" vs. "non-socialist," noting that the Roma are EU citizens legally present, making mass deportation not just morally wrong but legally impossible. A smaller contingent criticized the blog's broken navigation on 16:9 screens.

Using an open model feels surprisingly good [comments]

251 points · 75 comments · matthewsaltz.com · 5h ago

The article is a personal blog post where Matthew Saltz describes the oddly liberating feeling of using an open model (specifically Kimi K3 on Modal's infrastructure) instead of Claude or ChatGPT, framing it as a moment of cutting ties with proprietary providers. The HN thread immediately split into two camps: one side called it a thinly veiled advertisement for Modal, pointing out that running models on leased cloud hardware doesn't really make you "free," while the other side pushed back hard, arguing that the cost complaints are a red herring and that running smaller open models on cheap hardware is just classic hacking for fun. A major tangent emerged arguing that open models already match closed models if you stop doing one-shot "build me a SaaS" prompts and instead iterate on small, targeted functions—several people claimed DeepSeek V4 Flash or similar models cost them under $2 a month and outperformed Claude for their actual workflows. The commenters who actually built DIY agent systems (hooked into Home Assistant, calendar, email, baby monitors) argued that the real win is total control and privacy, not just cost, and that open models are commoditizing the frontier so fast that Anthropic and OpenAI's business models look shaky.

Removing React.js from the codebase and adapting Htmx for UI interactivity (2023) [comments]

241 points · 176 comments · misago-project.org · 22h ago

A Django forum software author detailed their decision to rip out React.js and replace it with HTMX, arguing that the React codebase was causing duplicate work, slow JSON serialization, and a painful flash-of-wrong-HTML for customizers. The HN thread immediately split into a bitter ideological war over whether HTMX is a refreshing return to hypermedia simplicity or a naive regression that ignores two decades of frontend lessons. One veteran developer insisted HTMX is just "Angular 1.0 again" and will choke on complex state, while defenders shot back that anyone making that comparison hasn't actually used HTMX at scale. The debate kept circling back to a concrete performance claim: a developer on a $1.6M/month ad budget said cutting React for cached HTML drastically cut bounce rates on slow phones, which the React camp dismissed as incompetence, not a framework problem.

Apple Will 'Watch Everything Burn' When the AI Bubble Bursts [comments]

239 points · 317 comments · www.macrumors.com · 17h ago

Ed Zitron, an outspoken AI critic, argues in this MacRumors interview that the AI buildout is an unsustainable bubble where companies like OpenAI burn billions more than they make, and that this speculation is driving up hardware costs for everyone—including Apple users, who are seeing price hikes on Macs, iPads, and iPhones because hyperscalers have hoovered up the world's memory supply. The HN thread split hard between people who found Zitron's financial analysis refreshing and those who dismissed him as a brand-building contrarian who doesn't code and oversimplifies technical nuances. The biggest pushback came from developers who insisted that LLMs *do* work well for software development—especially in 2026, with newer models—and that skeptics are either working in niche environments or refusing to update their opinions. A significant portion of the thread devolved into meta-debate over whether it’s even worth arguing with AI skeptics anymore, with one side accusing the other of bad-faith personal experience claims and the other retorting that the "AI boosters" have been promising a step change every few months for years. Ultimately, the conversation landed on a split that mirrored Zitron's own thesis: whether you see the tech as the future or a financial mirage depends mostly on whether you think the underlying science will eventually justify the trillion-dollar capex, or whether that capex is just a pension-fund-backed gamble that will crater when the enterprise demand doesn't materialize.

Should you wash your solar panels? [comments]

233 points · 231 comments · incoherency.co.uk · 18h ago

The linked article is a detailed personal experiment where a solar panel owner washes one bank of his 16-panel array to measure the power output difference. He found a 2-5% improvement, worth roughly £60-150 per year, but the real action in the discussion wasn't about the cleaning math—it was the electric shock he mentioned in passing. Several commenters immediately jumped on his casual mention of getting a "tingle" from a wet panel and asking ChatGPT about it, warning that 300-600V DC from panels can cause serious burns and that his grounding setup is almost certainly inadequate. A split emerged between those arguing that a transformerless inverter doesn't require a separate ground rod versus those insisting the panel frames must be bonded to protective earth to prevent dangerous touch potentials, with one electrical engineer explaining that while DC lets you "untouch" a live wire, the arc flash risk is real. The thread also largely dismissed the idea of cleaning roof-mounted panels at all, calling it a dangerous ladder-and-tool exercise that degrades equipment and is often illegal for hire in many countries, while another faction argued that rain does a poor job cleaning panels anyway, especially in arid regions where dust accumulates during peak generation months.

MAI-Cyber-1-Flash inside MDASH [comments]

231 points · 109 comments · microsoft.ai · 15h ago

Microsoft announced MAI-Cyber-1-Flash, a compact cybersecurity model that they claim beats Mythos, Gemini, and GPT on the CyberGym benchmark while cutting costs by 50%. The thread immediately zeroed in on access: the model is locked inside MDASH, a private-preview Microsoft product, so practically no one outside a handful of enterprise customers can actually use it—and several people pointed out that this is exactly the same pattern as every other US "cyber" model, leaving Chinese open-weight models as the only real option for anyone else. A vocal contingent dismissed the whole thing as marketing slop, mocking the overuse of "cyber," the AI-generated blog prose, and the semicolon abuse, while others brought up Microsoft's long history of broken products (Windows 11 hibernate failures, Tay, the Phi naming chaos) as evidence that they can't be trusted to ship something reliable. There was a split on whether the "trillions of daily signals" advantage is real or just means the model is good at finding bugs in Microsoft's own software—a skeptical take given the company's track record of not fixing basic OS issues.

Paged Out #9 [pdf] [comments]

220 points · 25 comments · pagedout.institute · 17h ago

The linked article is the free PDF release of issue #9 of *Paged Out*, a hacker-curious zine packed with over 70 short technical articles and artwork. The thread immediately lit up comparing it to a modern 2600 or Phrack, with particular love for Michał Zalewski's "Baby Steps in C" — a straight-faced collection of obfuscated C examples that triggered both laughter and PTSD. One commenter called out the "Computiles" piece as an uncredited rediscovery of Wang's tiles from the 1960s, but was quickly corrected: it's actually credited in section 3. The editor also chimed in to apologize for moving an article to a different page, which prompted a perfect joke about the borrow checker preventing that kind of mutation when you're holding an immutable reference.

Chinese chipmaker shares surge 470% [comments]

208 points · 178 comments · www.bbc.com · 22h ago

ChangXin Memory Technologies (CXMT), a Chinese DRAM chipmaker, debuted on the Shanghai exchange and saw its shares surge nearly 470%, giving it a market valuation of about $487 billion despite a broader tech selloff. The Hacker News thread quickly pivoted from the company’s prospects to questioning whether the spike was purely hype, government-backed mania, or genuine demand—especially since only 7% of shares are tradable. A split emerged: some argued the Chinese government will prop up CXMT like it did with Alibaba and Tencent, while others pointed to the DRAM market’s brutal cyclicality and noted that Samsung, SK Hynix, and Micron still dominate 90% of global production. A long tangent lit into the EU’s chip industry as “eating glue in the corner,” though several people pushed back, reminding everyone that ASML—the monopoly on advanced lithography machines—is European, which undercut the doom narrative. The conversation also drifted into broader fears about retail investor mania, drawing parallels to South Korea’s SK Hynix frenzy and Tesla’s valuation, with one side insisting that a 470% IPO pop tells you nothing about the company’s long-term ability to ship competitive chips.

Why I Left Google DeepMind [comments]

190 points · 54 comments · www.lesswrong.com · 22h ago

The linked article is a detailed personal account from a Google DeepMind research scientist who quit after failing to get the company to stop selling cloud and AI services to DHS and to refuse a military deal with the Pentagon that lacked restrictions on killer robots or mass surveillance. The thread split sharply: many commenters backed the author as principled and desperate, arguing he took tangible, costly action by organizing petitions and directly confronting executives like Jeff Dean, while a vocal chunk dismissed him as naïve about Google’s profit motives, calling the entire effort moral grandstanding. A side argument erupted over the fire-versus-nuclear-bomb analogy for AI responsibility, with one side insisting governance must evolve after harm is seen and the other countering that you don’t hand out a bomb to everyone and ask for guardrails later. A few commenters also noted the author’s outrage focused on two U.S. deaths while appearing silent on Gaza, which another user argued missed the point about his chosen leverage points. The consensus in the room was that the author was either a genuine actor who saw the game for what it is, or a symbol of a tech worker bubble that believed "don't be evil" meant anything at all.

Libsm64: Mario 64 as a library for use in external game engines [comments]

189 points · 24 comments · github.com · 21h ago

Libsm64 is a project that extracts Super Mario 64’s movement and rendering code into a shared library, letting you drop Mario into other game engines by loading an official ROM for assets. The thread immediately latched onto the real-world mods this enables: someone built a Quest 3 AR sandbox where Mario jumps on your couch, and there’s a Blender addon, a Half-Life 2 mod, and even a Minecraft version where you press M and F5 to become Mario. A few people clarified that the library isn’t just a model swap—it runs the actual SM64 physics in the background, with Mario’s hitbox and swimming intact, so mods like the GMod one are effectively running the original game invisibly. The inevitable Nintendo joke came up, with one reply noting the company’s pattern is more “malfunctioning ED-209” than a polite cease-and-desist.

Modern email can be built from borrowed parts [comments]

185 points · 112 comments · en.andros.dev · 23h ago

The article proposes HMTP, a modern email replacement built entirely on HTTP, borrowing existing standards like WebFinger and ActivityPub to fix SMTP's decades-old flaws. The HN thread immediately zeroed in on the network-effect problem: email is too entrenched, and big providers like Google and Microsoft have no incentive to adopt anything incompatible, so the proposal is essentially a toy that can't talk to the real world. Several people pushed back hard on the domain-as-identity anchor, pointing out that domains are rented, not owned, so key rotation and security still rely on a system that can be squatted—Bluesky's DID approach is better but adds infrastructure. The "first-contact consent" idea (a requests folder like Signal) got a split: some love it and already use similar systems (Hey.com, self-hosted greylisting), but others argued it just moves the spam problem to a new folder and that users historically hate it when banks or no-reply addresses get stuck. A few commenters noted that incremental improvements to SMTP (MTA-STS, web key directories) are more realistic than a clean-slate replacement, and that the real challenge isn't technical but political—the big players control reputation and won't let you self-host without pain.

Astronauts describe persistent 'observer' sensation after 6 month missions [comments]

176 points · 93 comments · spacedaily.com · 8h ago

The linked article describes how astronauts returning from six-month ISS rotations report a persistent "observer sensation"—feeling like they're watching their own lives from outside their bodies for weeks after landing. HN latched onto the similarity to clinical depersonalization and derealization, with several people pointing out that submariners and VR users describe the exact same phenomenon, and one commenter noted it's already in the DSM under dissociation. Others took it into weird territory: a bunch of commenters compared the astronauts' hyper-vigilant self-monitoring in space to Mahasi-style Vipassana noting meditation, while another thread debated whether a Mars mission would inevitably trigger psychosis or just needs the right selection and environment. The strongest pushback came from someone who argued the whole piece is a journalist inventing a neologism—that there's no formal study behind "observer sensation," just anecdotes and subjective journalism—which sparked a side squabble about semantics and scientific rigor.

Forth [comments]

172 points · 38 comments · xkcd.com · 11h ago

The xkcd comic plays on Forth's reverse Polish notation to spell out "I ♥ Forth" as "I Forth ♥" — a syntax joke that lands best if you already know arguments come before the operator. The thread quickly turned into a mini-tutorial on stack machines, with people nitpicking whether the heart operator pops two arguments and pushes a result or just prints a side effect, and a deep dive into the difference between the operand stack and the return stack, complete with links to PostScript's dictionary stack and Self's dynamic deoptimization. Someone predicted an RPN-to-Claude skill would inevitably spawn a startup, and a long-time HN character posted links to his own meticulously formatted Forth assembly code and a "return-stack skill" for LLMs. The meta-commentary landed hard: there's a split between those who find Forth write-only and those who insist commercial Forth is perfectly readable, with the usual lament that the language will die when HN dies—and the usual counter that the community will just hop to the next platform.

VLC for Unity now supported on Linux [comments]

163 points · 50 comments · code.videolan.org · 22h ago

The submission is about the Videolan project adding Linux support to their VLC-for-Unity plugin, which lets game developers embed hardware-accelerated video playback directly into Unity engine projects. The developer behind the port confirmed it uses OpenGL with DMA-BUF texture sharing for efficiency, though some in the thread pushed back hard on the approach—arguing that building an in-process decoder from scratch would be more efficient, with others speculating the current design is dictated by GPL licensing constraints. A sizable chunk of the discussion zoomed out to Unity’s broader ecosystem problems: people brought up the Unity Runtime Fee fiasco, pointed to Godot’s competing VLC plugin as a natural escape route, and ripped into Unity’s own video player for being buggy and underperforming on Windows, even on beefy hardware. The thread also got snagged on a tangential rant about the project’s Anubis anti-scraper challenge page, which blocked some readers entirely and prompted the usual complaints about proof-of-work captchas.

Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles [comments]

148 points · 49 comments · eaton-works.com · 16h ago

The article details a security researcher who found a critical vulnerability in Volvo/Eicher's "My Eicher" fleet management platform, allowing full account takeover of any user by exploiting unauthenticated APIs that exposed customer lists, OTPs, and password reset endpoints — affecting over 676,000 vehicles and 115,000 customers in India. HN largely praised the researcher’s patience after VECV took over two weeks to even respond to the disclosure, with several people arguing that companies like this don't actually want responsible disclosures and that researchers should instead sell vulnerabilities to brokers for actual money. A common point of confusion emerged when someone incorrectly called Volvo Chinese (confusing Volvo Cars, owned by Geely, with Volvo Group, the Swedish truck manufacturer that owns the joint venture). The thread pivoted hard into a broader argument about modern vehicles requiring cloud connectivity to function, with multiple people sharing horror stories of cars being bricked by poor reception, and a strong consensus that this kind of always-online dependency is a security and safety disaster waiting to happen.

A $500 RL fine-tune of a 9B open model beat frontier models on catalog review [comments]

146 points · 43 comments · fermisense.com · 5h ago

The article walks through three real-world deployments — Bridgewater, Harvey, and Intercom — where each company fine-tuned a small open model with reinforcement learning against its own proprietary scoring function, beating frontier models on narrow, high-volume tasks at a fraction of the cost. The HN crowd immediately pushed back on the benchmark's validity, noting that the tests were custom-built and trained directly against the scoring rubric, so the comparison to general-purpose frontier models is essentially apples-to-oranges. A solid split emerged: one side argues this is a genuine economic threat to the big labs, because most use cases don't need a model that can do everything, and the "open-weight commodity" wave will crater their pricing power and debt-funded infrastructure buildout. The other side retorts that frontier models are a floodlight, not a laser pointer, and that the fine-tuned specialist's narrow win says nothing about general capability — the labs keep making novel research breakthroughs while these custom models just overfit to one test. There was also pointed debate over whether the big labs actually get this dynamic or are willfully ignoring it to protect their cloud-style narrative, and some technical skepticism about how the scorer itself was implemented (was it another frontier model grading the episodes, and what happens when the fine-tuned model surpasses that grader?).

Self-contained highly-portable Python distributions [comments]

139 points · 31 comments · gregoryszorc.com · 13h ago

This article details self-contained, highly-portable Python distributions that bundle the interpreter, standard library, and most dependencies, aiming to run on any system for a given architecture. The HN discussion quickly zeroed in on the fact that Astral (now under OpenAI) took over maintenance of the project, and that tools like uv, pipx, and Hatch already use these binaries to install Python—a representative from Astral even chimed in to explain how their engineering effort has focused on keeping up with CPython and fixing quirks. Several people pushed back on the claim that python.org installers compile from source on macOS and Linux, pointing out that official binaries do exist but lack the portability of these builds. Others brought up the Cosmopolitan/APE project as a competing approach that delivers a truly single binary running across platforms, though the thread noted that self-contained doesn’t mean one binary for everything. There was also a sobering aside that PyOxidizer, the sister project for repackaging these distributions, appears abandoned—last release four years ago—so the standalone builds live on but the tooling around them has shifted.

The Artist Who Colored Ghibli [comments]

120 points · 14 comments · animationobsessive.substack.com · 13h ago

The article is a deep dive on Michiyo Yasuda, the color designer behind Studio Ghibli’s distinctive, muted palette—the person who made Totoro feel real and the Catbus not pink. The Hacker News thread largely took the piece as a wake-up call: several people admitted they’d previously found Ghibli-inspired AI art “okayish” but now see how much intentional, un-replicable craft they were glossing over. A few commenters pushed back on the implicit nostalgia, arguing that every artisan industry feels irreplaceable until it’s mechanized, and that hand-coloring cels was likely drudgery too. Others used the thread to swap links to Ghibli background artists’ process videos and to debate the surprisingly contentious history of Miyazaki’s departure from the *Anne of Green Gables* adaptation, where he reportedly clashed with Takahata over how to portray a girl protagonist. The consensus is that Yasuda was a master who never found a clear successor—but the split is over whether that loss is romantic or just the usual cost of efficiency.

Worse on Purpose [comments]

103 points · 79 comments · ledger.worseonpurpose.com · 19h ago

The site is a sprawling ledger rating hundreds of brands—from Pyrex to Lodge to Cutco—as “Approved,” “Watchlist,” or “Avoid” based on whether private equity, conglomerate ownership, or cost-cutting has degraded the product. The HN crowd immediately questioned whether the whole thing is AI-generated slop, noting the author works at Palantir in “AI Strategy” and that the methodology page dodges the question of how any human could credibly test every tool, mattress, and boot listed. Several people pushed back on specific ratings, pointing out that Cutco is Approved despite its predatory MLM sales model, and that Instant Pot is on Watchlist even though the product itself hasn’t gotten worse—the company just got gutted by private equity after a boom-bust cycle. A separate thread argued the whole premise is backwards: durable goods that last forever kill repeat purchases, so “worse on purpose” is the only way most brands can survive without charging luxury prices, which led to a broader argument about wealth inequality wiping out the market for reasonably priced quality.

Show HN: FeyNoBg – Automatic background removal model and training library [comments]

103 points · 25 comments · usefeyn.com · 15h ago

The article is a technical deep-dive from Feyn on releasing FeyNoBg, a state-of-the-art background removal model, alongside an open-source Python library called NoBg for training and running similar models. The HN discussion quickly zeroed in on a license controversy: the model was released under CC-BY-NC even though it's built on top of the MIT-licensed BiRefNet, which drew pushback from developers who said that non-commercial clause makes it legally risky and effectively unusable for most companies. After being called out for the licensing mismatch, one of the authors apologized and updated the model card to use the original MIT license, acknowledging they had the original author's blessing but failed to coordinate internally. Beyond licensing, the thread also explored practical questions about the model's resolution limits and how it handles ambiguous subjects (like a person on a couch), with the creators confirming it automatically grabs all foreground elements and is working on a prompt-based version for selective subjects.

30 threads · window 24h · article context usable 30/30 (unavailable 0, skipped 0, agent failed 0)
Generated 2026-07-28 08:04 UTC

Generated by Sauron from Hacker News discussions and linked articles.