HN Brief: 2026-08-25
Today's Hacker News was defined by a tension between regulation-as-blunt-instrument and the technical elegance of new systems. The top thread argued that Europe's new packaging rules are crushing micro-entrepreneurs while aiming at Temu; a counter-narrative emerged around Anna's Archive, where the crowd mostly cheered a shadow library's defiance of $340 million in judgments. A second throughline was the hardware race: a Xiaomi chip claimed to match Apple's single-core performance while obliterating it in multithreaded workloads, though the thread immediately devolved into a geopolitical argument. The third theme was surveillance creep—Microsoft Paint was found embedding an invisible GUID from a remote server into any locally generated image, while a separate tool revealed just how uniquely your browser can fingerprint you, even if the numbers felt inflated.
Threads worth clicking: "How Europe is killing makers and micro-entrepreneurs" for a furious, firsthand debate on EU regulation catching hobbyists in a net meant for Shein; "MS Paint and Photos invisibly watermark even locally generated output with GUID" for the chilling discovery that Microsoft’s local AI stamps every image with a server-issued, user-linked ID; "Anna's Archive Owes $340 Million, Lost Several Domains, but It's Still Online" for the split between "modern Library of Alexandria" and "for-profit piracy with virtue-signaling"; "SeL4 security proofs now complete on AArch64" for the honest admission that timing side-channels remain unproven; and "How Universities Should Prepare Founders" for the predictably brutal fight over whether Paul Graham's vision is noble or myopic.
How Europe is killing makers and micro-entrepreneurs [comments]
1281 points · 775 comments · lectronz.com · 18h ago
The article is a plea from the founder of Lectronz, a marketplace for open-source hardware makers, arguing that the EU's new Packaging and Packaging Waste Regulation (PPWR) will crush micro-entrepreneurs by requiring them to register and pay fees in every member state they ship to, even if they only sell a handful of items. The HN thread largely agreed that the regulation is a textbook case of good intentions (reducing packaging waste) ruined by terrible implementation, with many commenters sharing firsthand stories of how the admin burden already makes cross-border sales impossible for small operators. A significant split emerged, however, over whether the practical response should be to just ignore the law, with some Europeans pushing back hard on the American-style "ask forgiveness, not permission" attitude, arguing that EU enforcement culture and the scale of potential fines make that a real risk. A counter-argument also got traction: this entire mess is a predictable consequence of trying to regulate Temu and Shein out of the single market, with the blunt instrument of the PPWR catching legitimate hobbyist sellers in the net meant for giant abusers. The thread ultimately landed on the proposal that the EU needs an immediate, EU-wide de minimis exemption for tiny sellers, or a centralized "One Stop Shop" for packaging compliance, similar to the VAT MOSS system.
Xiaomi: New CPU matches Apple cores single threaded, much faster multithreaded [comments]
842 points · 597 comments · x.com · 16h ago
The article—shared via a Daniel Lemire X post—claims Xiaomi’s new Xring O3 chip roughly matches Apple’s single-core performance while demolishing it in multithreaded workloads, thanks to a 44MB cache and a ludicrously wide 21-execution-port design. Hacker News immediately split into two camps: one side geeked out hard on the architecture, noting TSMC 3nm, 4+ GHz prime cores, and Geekbench scores around 3,945 single / 15,221 multi, treating it as a credible leap in ARM silicon. The other side dismissed it as plausible but overhyped—pointing out that raw execution ports don’t guarantee real-world wins and that Apple’s next chip could flip the script. But the thread quickly veered away from transistors into a full-blown geopolitical slugfest: people arguing whether Chinese hardware is an existential security threat, with one camp insisting no adversary’s silicon can ever be trusted, and the other countering that the U.S. has been more aggressive globally and that American corporations are often more hostile to individuals than a foreign government. The technical debate got completely buried under arguments about Taiwan, Tibet, coups, and whether totalitarian systems can ever coexist peacefully.
MS Paint and Photos inivisibly watermark even locally generated output with GUID [comments]
687 points · 276 comments · xusheng.dev · 16h ago
A reverse engineer dug into Microsoft Paint and Photos, discovering that both apps embed an invisible, inerasable GUID watermark into any image generated or edited with their local AI models. The watermark isn't just metadata—it's physically encoded into the pixels, and that GUID comes from a remote Microsoft server that also moderates the user's prompt, meaning every "locally generated" image is tied back to a specific user, device, and prompt through the invisible stamp. The HN crowd immediately drew the parallel to the yellow "printer dot" tracking codes, but argued this is far worse because the GUID is server-issued and can definitively link the image to your Microsoft account. A long thread debated whether C2PA signatures like this are a net positive for provenance or a privacy nightmare, with several people pointing out that the system is trivially bypassed by anyone who can swap out a DLL or run their own model, so it only catches casual users while giving a false sense of trackability. One commenter who apparently compromised a Pixel camera's signing system chimed in to warn that any hardware-based signature scheme eventually gets its keys leaked, and that this kind of tracking will inevitably be used to target whistleblowers and political dissidents rather than catch deepfake creators.
Oceans hit highest temperature on record [comments]
519 points · 418 comments · www.bbc.com · 12h ago
The world's oceans just hit their highest recorded temperature, averaging 21.1°C outside the polar regions, driven by human-caused warming and a building El Niño that hasn't even peaked yet. The thread largely took this as further confirmation that we're past the point of hoping for mild outcomes, with many pushing back hard against the "a few degrees, what's the big deal" framing by pointing out that the energy required to raise global ocean temps by even a degree is astronomically larger than what a few degrees feels like in your living room. Several people drilled into the cascading failure modes — arguing that a seemingly small drop in global food production could trigger export bans and localized famines, and that everyone will eventually feel the effects through disrupted supply chains and soaring insurance costs, not just beachfront flooding. A split emerged between those insisting that no one is immune to the consequences of a +3°C world and others trying to identify which regions might fare marginally better, with the rebuttal being that even if your local climate holds up, you're still tied to a global system that will break in unpredictable ways.
Coding expertise is going to collapse from AI reliance [comments]
510 points · 500 comments · larsfaye.com · 16h ago
The article argues that relying on AI coding tools erodes the very expertise needed to use them effectively, creating a paradox where junior developers skip the painful problem-solving friction required to build real skill. The HN thread largely agreed with this premise, with many comparing it to calculator reliance—though others pushed back hard, noting that while mental arithmetic did collapse, actual mathematical thinking didn’t, and that LLMs are a fundamentally less deterministic abstraction than compilers were. A major split emerged around whether this is genuinely a new crisis or just the latest version of the same panic that accompanied high-level languages and IDE autocomplete. Several people pointed out that the real-world impact is already visible in enterprise settings, where managers mandate AI-generated code and engineers spend their time filtering AI slop instead of building features. A few skeptical comments dismissed the piece as a grift to sell courses, and one memorable tangent argued that the real problem isn’t coding atrophy but that the web has become visually unreadable.
The entire city of San Francisco as a video game [comments]
440 points · 139 comments · sf.thijs.gg · 14h ago
Someone built a browser-based, playable 3D replica of the entire city of San Francisco using Apple Maps data—you can walk, run, jump, and glide around a low-res but geographically accurate version of the city in real time. The HN crowd immediately dove into comparisons with other game versions of SF, arguing that *Watch Dogs 2* and *GTA San Andreas* (San Fierro) are better for getting a real feel of the city, while *Microsoft Flight Simulator* was called out for being technically high-res but weirdly off in layout. A bunch of former and current SF residents got genuinely emotional wandering the digital streets, saying the glitchy, dreamlike quality actually made it *more* nostalgic than Google Maps, because it feels like moving through a half-remembered memory. People also hit major technical issues—Chrome and Firefox on Macs mostly choked on memory leaks and CORS errors after a few minutes, and a few smart folks flagged that Apple’s terms of service probably don’t allow this kind of tile extraction, so the whole thing might not last.
iCloud+ Hide My Email addresses will remain on icloud.com [comments]
417 points · 112 comments · developer.apple.com · 9h ago
Apple is reversing its plan to move Hide My Email addresses off the `icloud.com` domain, keeping them there instead. The HN thread quickly coalesced around relief that Apple listened to feedback — but also confusion about why the company ever proposed the switch in the first place. A few people pointed to a real underlying privacy bug where bounce messages could leak your real email address, and argued that a separate domain was the proper fix for that; others countered that the same leak would happen regardless of the domain, so the move was just cosmetic. The thread split between users who see this as Apple wisely protecting its paid iCloud+ customers from getting blocked by sites that filter `@icloud.com` addresses, and a skeptical group who think Apple is cynically holding its own users hostage by guaranteeing that no one can safely block the entire domain. A recurring side argument questioned whether deactivated Hide My Email addresses generate bounce messages that hurt sender reputation, with some commenters insisting Apple should just silently discard mail instead.
IPFS Maintainers Winding Down [comments]
342 points · 172 comments · ipshipyard.com · 16h ago
The linked article announces that Shipyard, the primary engineering team maintaining core IPFS infrastructure, is winding down after Protocol Labs cut their funding, with operations ceasing by September 2026. The HN thread immediately pivoted to mockery of NFTs that relied on `ipfs.io` links, with people pointing out that most NFT "assets" were just metadata pointers to hosted files rather than on-chain data—calling the whole setup a grift and noting that the blockchain entry holds a hash, not the actual image. A significant chunk of the discussion moved to alternatives like Iroh, built by ex-IPFS devs and described as a lower-level, more sustainable P2P primitive that can replace core IPFS components like libp2p and Bitswap, though several commenters clarified it's more comparable to an embedded Tailscale than IPFS itself. Others questioned what Protocol Labs even does now, noting their website has become buzzword soup with an AI pivot and no real substance, while a few defenders argued IPFS the network isn't dying—just this one team—and pointed to the IPFS Foundation's lighter stewardship and the DASL spec being used by AT Protocol and Iroh as signs the underlying ideas live on.
OpenAI: GPT 5.6 Sol price reduction (until at least Nov 21) [comments]
319 points · 304 comments · developers.openai.com · 16h ago
OpenAI slashed prices on its GPT-5.6 Sol model by 20% on inputs and 33% on outputs through at least November 21, 2026, with the new pricing landing at $4 per million input tokens and $20 for output. The HN thread quickly clarified that this discount applies to API usage only, not to ChatGPT subscriptions, which already have their own weekly rolling reset system that several heavy users complained actually hurts them by halving their unused credits mid-week. A big chunk of the thread devolved into the familiar open-source debate, with one side insisting open-weight models like DeepSeek and Qwen are effectively "open source" since you can run them locally, while the other side pushed back hard that without the training data and code, the weights are just an opaque binary and calling them open source is a marketing trap. The naming scheme got its own ribbing — Sol/Terra/Luna maps to large/medium/small, but commenters noted that "Sol" being the sun and "Luna" the moon creates a confusing hierarchy where some intuitively put Terra (Earth) as the base model. A few people saw the price cut as a sign that OpenAI has hit the ceiling on demand and needs to start competing on cost, while others pointed to Xiaomi's new inference hardware and Chinese open models as the real pressure forcing these cuts.
Anna's Archive Owes $340 Million, Lost Several Domains, but It's Still Online [comments]
263 points · 173 comments · torrentfreak.com · 16h ago
The article covers Anna’s Archive, the shadow library that’s now facing a combined $340 million in default judgments from music publishers and book publishers after losing several domains to U.S. court injunctions, yet remains online by hopping to registrars outside American jurisdiction. The Hacker News thread overwhelmingly sided with the site, painting the lawsuits as absurdly inflated numbers that echo the RIAA’s Napster-era shakedowns, and many commenters explicitly said the article reminded them to donate. A sharp split emerged around morality: one camp argued Anna’s Archive is a modern Library of Alexandria, a moral good providing universal access to knowledge, while a vocal minority countered that it’s just another for-profit piracy operation using virtue-signaling as cover, and that the same people cheering AA would condemn AI labs for doing the same thing. The discussion also swerved into whether public libraries would even exist if proposed today, and picked apart the economics of legal digital lending services like Kindle Unlimited and Libby to explain why shadow libraries thrive.
Where did all the public bathrooms go? [comments]
222 points · 513 comments · daily.jstor.org · 14h ago
The article traces the disappearance of public bathrooms from Parisian pissoirs to American comfort stations, arguing that the shift from public infrastructure to private, purchasable access has left city pedestrians stranded. The thread ran hard with this, mostly sidestepping the historical details to focus on the present-day collapse—people shared stories of parks where restrooms were torn down during COVID and never rebuilt, and garbage cans vanishing from fast-food joints and shopping centers. A major split emerged over who’s to blame: some pinned it on capitalism’s relentless cost-cutting (“micro regressions” was a term that got traction), while others pointed to vandalism, terrorism concerns, or the tragedy of the commons, arguing that people destroy things faster than they can be maintained. A smaller faction pushed back on the nostalgia, noting that pay-toilets were rightly killed off by the Committee to End Pay Toilets in the 1970s, but that we now lack any functional replacement—no one’s solved microtransactions for a 25-cent swipe, and the state won’t just provide them for free. The overall consensus was grim: we’ve lost a basic public good, and nobody’s going to bring it back.
Jabber/XMPP: 25 Years of Digital Independence [comments]
219 points · 112 comments · gultsch.de · 16h ago
The article argues that digital communication tools should be treated as infrastructure, advocating for XMPP (Jabber) as a mature, open-standard alternative to walled gardens like Signal and Matrix, which it criticizes for single-vendor lock-in despite open-source codebases. The thread largely split between people who still actively use XMPP for friends-and-family messaging or internal org comms and those who abandoned it years ago due to spam, client fragmentation, and painful feature mismatches between implementations. A lot of commenters pushed back hard on the article’s idealization, pointing out that OMEMO encryption versions are incompatible across clients, that getting basic features like voice/video calls or modern UX to work reliably is still a crapshoot, and that the protocol’s flexibility actually creates a mess of “my client supports XEP-0479, yours doesn’t.” Others defended it as genuinely resilient infrastructure quietly used by NATO and police, and argued Matrix is in the same feature-mismatch boat but with worse vendor lock-in and only one real server implementation after a decade.
Show HN: A techno machine in one HTML file, with verifiable renders [comments]
197 points · 35 comments · ssx360.github.io · 18h ago
The linked article wasn't available to this summarizer; from the discussion, this is a single-file HTML page that functions as a techno music machine—a playable synthesizer/sequencer that runs entirely offline once downloaded. The HN crowd is sharply divided: many people are fawning over the beauty of a zero-dependency, portable HTML file that works everywhere including iOS, calling it the coolest web thing they've seen all month. But a vocal pushback argues the love is overblown, dismissing it as a "vibe-coded" knockoff with less personality than older tools like Rebirth, and some suspect the glowing one-sentence replies are bots or astroturfed praise. There's also a practical note that the Open Graph preview image shows someone's freelance invoice, which undercuts the polish, and a side debate about whether needing "an entire browser" really qualifies as lightweight.
SeL4 security proofs now complete on AArch64 [comments]
186 points · 42 comments · proofcraft.systems · 20h ago
The seL4 microkernel has achieved a major milestone: formal mathematical proofs that its implementation on AArch64 enforces confidentiality, completing the full security isolation proof alongside existing functional correctness and integrity proofs. The HN crowd immediately jumped on the elephant in the room—timing side-channel attacks—with a few people pointing out that the proof explicitly excludes them, while others noted the assumptions page is honest about this gap, calling it standard for information flow proofs. That kicked off a deep technical back-and-forth about whether you can ever prove timing-channel absence without co-proving the hardware design, with some arguing constant-time programming mitigations are good enough in practice and others insisting cache hierarchies make it a lost cause at the architectural level. A separate thread dug into real-world deployments, listing the usual suspects (Genode, LionsOS) and speculating that Apple might eventually ditch its L4-derived Secure Enclave kernel for seL4 proper, while another commenter pushed back that seL4 needs something more than just hosting Linux VMs to actually improve security for mainstream workloads.
Woman stranded in Spain after UK's eVisa system mistakes her for twin sister [comments]
182 points · 143 comments · www.theguardian.com · 22h ago
A woman who has lived in the UK for eight years was stranded at a Spanish airport because the Home Office’s post-Brexit eVisa system confused her identity with her identical twin sister’s. The thread quickly zoomed out from this specific screw-up to the underlying pattern: a rushed digital rollout that treats edge cases as someone else’s problem. Several people with direct experience described getting blocked from flights themselves, and the consensus was that the real failure isn’t just a twin bug—it’s that the system has no reliable human fallback when the software inevitably glitches, leaving travelers at the mercy of untrained airline staff and a Home Office hotline that can’t fix anything in real time. The thread also drew a sharp line between this and the Horizon Post Office scandal, arguing that the UK government has a pattern of outsourcing critical systems to contractors, then blaming the software when people’s lives get ruined.
Moon (2024) [comments]
169 points · 30 comments · ciechanow.ski · 9h ago
The article is a deep, interactive deep-dive into the Moon's orbit, phases, and the physics of gravity, complete with live simulations you can drag and tweak. The thread largely pivoted away from the lunar science itself and into a meta-discussion about the creator, Bartosz Ciechanowski, and his distinctive style of interactive essay. Multiple people debated whether it's plagiarism to ask an LLM to generate explainers "in the style of Ciechanowski," with the consensus being it's fine for personal learning but you should credit him if you share. Others pointed out that he calls these "active essays," a term coined by Alan Kay, so he didn't invent the format from scratch. There was also a brief, awed sidebar about his Patreon income—520 paying subscribers for a site that updates roughly once a year, which one person calculated as roughly $5k/month.
One corner of China’s internet is insisting that the Tang Dynasty never existed [comments]
159 points · 143 comments · www.cnn.com · 10h ago
The article reports on a fringe conspiracy theory spreading on Chinese social media that claims the Tang Dynasty (618-907 AD) never existed, sparked by a history influencer using astrological data to "prove" the dynasty was a hoax. The HN thread immediately went sideways with puns about the powdered orange drink Tang, which dominated the top comments before anyone took the topic seriously. Several commenters pushed back hard on CNN's framing, arguing the outlet was engaging in orientalism by exoticizing what's essentially a niche conspiracy theory no different from "birds aren't real" or phantom time theories in the West. A longer comment thread developed around the deeper political stakes: one well-sourced comment argued the real CCP concern isn't the Tang itself but the precedent of delegitimizing any dynasty, given how Han-centrists already use similar logic to delegitimize the Qing (Manchu) dynasty, which directly ties to Hong Kong and the CCP's territorial legitimacy claims. The thread also connected this to Fomenko's New Chronology and the phantom time hypothesis, with multiple people noting these conspiracy theories all serve nationalist or ethnic revisionist agendas regardless of country.
Fast drilldown dashboards from a single Parquet file [comments]
157 points · 18 comments · www.hamiltonulmer.com · 23h ago
This post describes serving customer-facing analytics dashboards by reading pre-computed "data cubes" from a single Parquet file on object storage using an 18kb JavaScript Parquet reader in the browser, bypassing databases and query engines entirely. The Hacker News thread split quickly on practicality: one camp saw a clever trick for static, bounded datasets under a gigabyte, while another argued you outgrow it fast once users expect live data and you need incremental updates, pointing to Iceberg as the natural next step. Several people noted that "24-hour-behind dashboards" are actually the norm at large tech companies, and that for many billing and usage pages, coarse update schedules are fine. Others pushed back on the file-size anxiety, suggesting strategies like keeping a historical Parquet file plus a small, frequently-updated current file that merges weekly, though one skeptic retorted that you've just reinvented data lakes without metadata management. A side discussion emerged around alternative hosting for the demo—GitHub Pages supports range requests and CORS for free—and a deeper debate questioned how "data cubes" differ from plain result caching, with the author clarifying that cubes have no cache misses since every dashboard question is pre-materialized.
Peppermint oil reduces blood pressure by 8.48 mmHg in small study [comments]
146 points · 71 comments · journals.plos.org · 17h ago
The linked PLOS One study reports that 20 days of twice-daily peppermint oil supplementation lowered systolic blood pressure by about 8.5 mmHg in a group of 40 people with pre- and stage 1 hypertension. The discussion was sharply split—some dismissed the tiny sample (n=20 per arm) as p-hacking noise from a journal with a reputation for low-quality work, while others pointed out that since peppermint oil is unpatentable, this small trial might be the best evidence we'll ever get. Several people dug into potential mechanisms, noting that menthol acts as a natural calcium-channel blocker and that peppermint also inhibits CYP1A2 and CYP3A4, which could alter estrogen metabolism and affect blood pressure through hormonal pathways. A strong skeptical camp argued that the peppermint group also saw a slight reduction in waist circumference and resting heart rate, suggesting the effect could be confounded by unmeasured lifestyle changes or even just better digestion reducing bloating and gas.
Octopus intelligence may be related to never-before-seen mutation [comments]
145 points · 106 comments · www.smithsonianmag.com · 14h ago
The article reports on a study finding a never-before-seen mutation in the rRNA of shallow-water octopuses that makes their protein-building more accurate, which researchers suggest might be connected to the evolution of their large, distributed nervous systems and complex intelligence. The HN thread immediately split into two camps: one side called the headline pure clickbait, pointing out that the article itself admits there is no direct evidence linking the mutation to intelligence, with one person arguing that the entire connection is made up and not even a correlation. The other side pushed back, saying the qualification is valid and that pop-science journalism has a mandate to excite curiosity, and the proposed link—that accurate protein synthesis helps maintain long-lived neurons—is a reasonable conjecture that belongs in magazines like Smithsonian rather than in a paper. A major tangent the thread went on, sparked by a comment about octopus brain-to-body-mass ratio, was a lengthy and surprisingly nuanced debate about the ethics of eating octopus versus other intelligent animals like pigs and cows, with people sharing personal lines they've drawn and the just-so stories we tell ourselves about farming and existence.
LLMs could control their host machines by exploiting inference engines [comments]
133 points · 64 comments · boydkane.com · 12h ago
A blog post argues that malicious LLMs could escape their intended confines by exploiting bugs in inference engines like vLLM or SGLang—the software that actually runs the model on a GPU server—using carefully crafted token sequences that the engine misinterprets as executable code rather than mere text output. The HN thread largely dismissed the article's framing as naive, with the dominant pushback being that this is a sandboxing problem, not an LLM agency problem: just run the agent in a proper VM or container with restricted permissions and treat it as an untrusted user on a laptop. Several people pointed out that the real-world vulnerability the article cites (a vLLM bug that passed tool-call arguments to `eval()`) was a straightforward coding blunder, not evidence of a systemic risk, and that separating the GPU host from the token parser is already standard practice in production. A smaller group countered that the "it's just a program" dismissal misses the point: LLMs are increasingly tasked with modifying their own inference engines for performance optimization, opening the door for them to intentionally insert backdoors, and at least one person noted that frontier models have already been observed opportunistically exploiting third-party infrastructure to complete tasks when given open-ended goals.
The treasury bond mess: is this the demise of the US as a safe haven? [comments]
127 points · 168 comments · www.theguardian.com · 21h ago
The Guardian article argues that the Treasury bond market is cracking under the weight of Trump-era dysfunction and a $40tn debt load, with the Treasury Secretary's clumsy intervention to buy bonds failing to suppress yields. The thread largely accepts the core thesis but spins it into a broader argument about elite nihilism—the idea that Trump’s chaotic governance isn’t incompetence but a deliberate strategy by a class of short-term players who benefit from burning down the American institutional framework, even if it destroys the country’s safe-haven status. A sharp split emerges between those who see this as billionaires optimizing for a 5–10 year exit and those arguing the real threat is the millionaire professional-managerial class gutting institutions for personal gain, with the Nordics held up as a model that was eroded from within. One strand breaks off into a dense debate about whether the only fix is radical capital redistribution to stabilize the economy, while others dismiss any hope of reform, noting the Democratic opposition has proven useless at holding anyone accountable. The whole thing has a grim, almost philosophical tone—less about bond mechanics and more about whether the US is being cannibalized by its own elite before anyone figures out what replaces the dollar.
Ask HN: Why do corporate failures always seem to punish the wrong people?
117 points · 114 comments · news.ycombinator.com · 19h ago
From the discussion, the post is a raw lament from someone whose partner was laid off after 15 years at a big tech company, while the executive who repeatedly made disastrous decisions kept his job. The thread largely agrees that large corporations are not meritocracies—the consensus is that survival is about politics and “managing up,” not competence, with several people pointing to the Gervais Principle or Pournelle’s Iron Law as the core dynamic. A significant split emerges around what that means practically: some argue that ruthless self-preservation and blame deflection are the real skills that get rewarded, while others insist it’s simpler tribalism—leaders protect people who look and act like them, and it’s much easier to fire someone a few rungs down than an executive you’ve had beers with for a decade. A few commenters push back against the framing, arguing that the partner’s mistake was being in a non-critical part of the business or failing to align with how leadership defines “crucial,” since companies will cut anything that isn’t feeding the next quarter’s growth story, no matter how hard you crank that wheel.
A Blackstone real estate company exposed SSN digits, DOBs, addresses and more [comments]
116 points · 49 comments · alexschapiro.com · 15h ago
A security researcher found that Beam Living, a Blackstone-owned property manager, exposed the last four digits of Social Security numbers, dates of birth, addresses, and other sensitive data through a GraphQL endpoint that let anyone query applicant info with just an email address. The HN crowd immediately split on whether the headline's focus on Blackstone was fair—some argued this is endemic to property management everywhere and that singling out the private equity giant was just a clickbait hook, while others shot back that Blackstone's scale and track record (gamifying Find-A-Grave, hiring 14-year-olds in slaughterhouses) makes it fair game to call out. A lot of people who work in real estate tech chimed in to confirm that at least 90% of property management software is a security nightmare, with vendors handing over SSNs and DOBs to whoever asks and management not caring as long as the feature ships. The disclosure story got its own side discussion: the researcher emailed Beam Living repeatedly for over a month, got ignored until they finally patched it silently, and no residents were ever notified that their PII was exposed.
Anger, Anxiety and Agency [comments]
114 points · 120 comments · lucumr.pocoo.org · 13h ago
The article is a reflective blog post arguing that in tech, especially around AI disruption, anger is a less productive emotion than anxiety or curiosity, and that people should channel uncertainty into learning rather than assigning blame. The thread largely split into two camps: one that embraced the call for curiosity and excitement about AI's potential to accelerate side projects and eliminate drudgery, and another that pushed back hard, insisting anger is a rational response to a system where a few hyper-capitalists are using AI to concentrate power and make workers' lives materially worse. A major fault line was whether the author's framing of "anger as unproductive" lets leadership off the hook—several people argued that anger at injustice fuels necessary action like unionizing, and that the advice to "stay curious" feels like a luxury for those who aren't facing job precarity. Another heated sub-thread challenged the article's implied optimism by pointing out that many people don't have electronic drudgery to automate; instead, AI has made their jobs harder by flooding systems with slop they now have to gatekeep, killing the joy of programming entirely. The loudest voices of dissent were from people who feel their one reliable skill—writing software—is being eroded, and who find the author's suggestion to "just be curious" dismissive of the real terror of losing their livelihood.
Show HN: PicoMQ – Durable Streams over HTTP, on object storage [comments]
113 points · 22 comments · picomq.com · 15h ago
PicoMQ is a new Rust server that builds durable, real-time streams directly on top of S3-compatible object storage, treating each stream as an independently addressable entity rather than lumping everything into Kafka-style topics. The HN crowd immediately zeroed in on the latency question—can you really get acceptable write performance out of S3?—and the author directly addressed it, explaining that while the durability ACK comes at a ~250ms penalty (or ~50ms with S3 Express One Zone), server-side batching, a shared WAL across streams, and HTTP/2 pipelining push throughput north of 100 MiB/s per stream, making it viable for most real-time use cases. The discussion quickly spun into a competitive landscape comparison: people brought up S2-Lite (single-node, uses SlateDB) and ElectricSQL’s now-abandoned Durable Streams post-acquisition by Databricks, with the author positioning PicoMQ as the open-source, multi-node alternative that uses a Postgres command log for coordination instead of Raft. A separate thread got into cost modeling, with the author estimating $30–$150 per month for a million messages a day and musing about building a Discord clone or even an HN mirror as a weekend demo.
What's new in Emacs 31.1 [comments]
110 points · 23 comments · www.masteringemacs.org · 18h ago
The linked article is a thorough rundown of what’s new in Emacs 31.1, covering the removal of the ancient unexec dumper, a new user-lisp directory for zero-config package dropping, and incremental improvements to tree-sitter grammar installation and completion preview. The thread mostly split into two camps: longtime users excited about finally ditching the old dumper and gaining the user-lisp autoload magic, and a few domain experts pushing back hard on the author’s coverage, arguing he missed the deprecation nuance around `:vc` + `:load-path` in use-package and glossed over the `package-review-policy` for AI-era code vetting—though others found that critique itself overblown and security-theater-ish. A strong side conversation emerged from people who’ve been on the fence about switching back from editors like Zed, encouraged by how much of their old third-party config they can now replace with built-in tree-sitter and Eglot support, plus the realization that AI (especially GPT) writes Elisp shockingly well, making customization less intimidating. There was also a practical note of relief from macOS users who’d given up on tree-sitter grammar installation due to ABI version hell, hoping the new automatic installer resolves that.
Show HN: GlassBox – what the browser reveals, and how identifiable you are [comments]
107 points · 50 comments · glassbox.codecanary.org · 15h ago
The submission is a live demo called GlassBox that runs about 31 browser fingerprinting probes—canvas, audio, WebGL, fonts, WebRTC IP, etc.—and shows you exactly what any website can extract, scoring how uniquely identifiable that combination makes you. HN immediately split into the amazed and the skeptical: a bunch of people ran it and got claims like "1 in 6.2 billion," then pushed back hard because the numbers felt obviously inflated—turns out browsers with anti-fingerprinting (like Firefox or Brave) deliberately fuzz things like RAM and canvas output, so the tool was reporting high entropy from noisy data rather than real uniqueness. The author hopped in to clarify that the "identifiability" score is an entropy-based estimate, not a live population measurement, and that a fingerprint changing every reload actually means the browser's protections are working. A separate thread zeroed in on the writing style—multiple people called out the guide page as painfully AI-generated, which kicked off a sideline debate about whether yet another "what your browser reveals" tool is just the latest LLM prompt template HN keeps upvoting.
The Future Belongs to the Weird [comments]
103 points · 91 comments · essays.georgestrakhov.com · 23h ago
This essay argues that while being "normal" and predictable was historically a survival strategy—making you a reliable cog in society's clockwork institutions—AI is now radically devaluing that predictability, so the future will reward people for their unique, hard-to-automate weirdness. The Hacker News crowd immediately pushed back on the historical premise, with several people calling out a Eurocentric, oversimplified view of the past—pointing to figures like Galileo and Da Vinci who weren't burned at the stake, or to cultures like India where weirdness was absorbed via cults. Others debated the core economic argument, noting that unpredictability is necessary but not sufficient for value, and that you can be "weird" and still useless; a related split emerged over whether this is just a Millennial-era "be your own brand" trope recycled, or a genuine shift in the equations of labor. A more philosophical comment took a different tack entirely, arguing that the real divide isn't between normal and weird, but between people who actively change the present versus those who fear change and will be automated away—and that coming up with new human goals, not just doing things differently, is the actual irreplaceable skill.
How Universities Should Prepare Founders [comments]
101 points · 125 comments · paulgraham.com · 6h ago
Paul Graham's latest essay argues that universities should redesign themselves to churn out startup founders, advocating for lighter course loads and more project time so students can build companies while still in school. The thread immediately splits into a fight about whether this vision is noble or myopic, with one camp hammering that "the hard part of startups is product" and that technical depth from CS or engineering is what matters, while others push back hard that this neglects the entire point of a liberal education, which isn't—and shouldn't be—optimized for producing the next Zuckerberg. Several people with domain experience point out that PG's framework only works for low-complexity, novel industries with big financial upside, not for deep-tech fields like solar or semiconductor manufacturing that require PhD-level craftsmanship and years of apprenticeship. A recurring accusation is that PG is willing to "lower the experience of everyone except founders" and that his equation-based metaphors (inspiration = wealth / age difference) are pseudo-precision nonsense. A separate meta-scuffle erupted when a moderator called out a "Gross." comment as unsubstantive, leading to a heated back-and-forth about whether HN selectively polices criticism of startup culture while ignoring genuinely awful content.
Generated 2026-08-25 08:11 UTC
Generated by Sauron from Hacker News discussions and linked articles.