Sep 7Tuesday, September 8, 2026 · all daysSep 9 · today »
1.I've factored the RSA keys of a Certificate Authority from the 90s(mcpherrin.ca)
487 points by ahlCVA 2 days ago | 123 comments | permalink
tl;dr: The author factored two 512-bit RSA root CA keys from the defunct Canadian CA "E-Certify" that shipped in Netscape 4.51 in 1999, using CADO-NFS on a Ryzen 9 5950X in about 30 hours each. They also cracked a 512-bit VeriSign test code-signing CA from IE 3.02 (done on GPU in ~1 hour). The recovered private keys, tools, and a demo TLS server compatible with Netscape 4.51 are published on GitHub, illustrating how weak early Web PKI standards were even by contemporary cryptographic norms.
HN Discussion:
  • Reinforces how comically weak 512-bit keys were even by 1999 standards
  • Reflects on broader implications like harvest-now-decrypt-later surveillance of past traffic
  • Nostalgic appreciation for reverse-engineering childhood-era tech
  • Criticism of the author's reliance on unverified LLM output in the writeup
  • Curiosity/questions about historical expectations and technical context
2.Mistral raises €3B(mistral.ai)
841 points by kuberwastaken 2 days ago | 593 comments | permalink
tl;dr: Mistral raised €3B in a Series D at a €21B+ post-money valuation, led by Samsung Electronics with EQT's Scaleup Europe Fund and PSG Equity — the largest equity round ever for a European tech company. The funds will expand frontier research, compute capacity, and international growth, positioning Mistral as a full-stack "sovereign AI" provider offering open-weight models, infrastructure, and products to enterprises and governments seeking control over data and deployment.
HN Discussion:
  • Mistral's contrarian sovereign AI strategy is smart and shouldn't be judged on benchmarks alone
  • EU-based location gives Mistral a sovereignty advantage that will attract government and enterprise clients
  • Mistral's LLMs are not competitive with other open-weight models despite decent auxiliary offerings
  • Mistral's revenue and salaries are too low to realistically compete with US labs
  • EU would be better served funding datacenters to run Chinese SOTA models rather than Mistral
3.TALA Is Open-Source(d2lang.com)
304 points by alixanderwang 2 days ago | 23 comments | permalink
tl;dr: Terrastruct has open-sourced TALA, its autolayout algorithm for software architecture diagrams, under MPL-2.0 and bundled it into D2 v0.9.0 (usable via `--layout=tala`). Unlike Dagre and ELK, TALA is an orthogonal layout engine optimized for whiteboard-style diagrams and supports custom or partial node positioning—useful for AI-generated diagrams where models place nodes but struggle with routing. Tradeoffs include nondeterministic-feeling output when inputs change, weaker DAG handling, and nonlinear runtime scaling on larger diagrams.
HN Discussion:
  • TALA produces impressively tidy layouts for most diagrams shown
  • TALA's output can be worse than alternatives for certain diagram types like the Go queue example
  • Enthusiasm for D2 and TALA being open-sourced, filling a gap in layout tools
  • ~Automatic layout algorithms fundamentally don't scale well; interactive editors would be better
  • Curiosity about integration with existing tools like Graphviz or the underlying heuristics
4.We have a year to fix security everywhere(jyn.dev)
297 points by saikatsg 2 days ago | 336 comments | permalink
tl;dr: A speculative near-future scenario (referencing fictional models like GLM 5.3-flash and GPT-6 Astra) argues that cheap, open-weight LLMs with safety guardrails removed will soon enable anyone to run automated cyberattacks against real infrastructure for the cost of a consumer workstation. The author urges urgent action: governments should mandate and fund pentesting and patch deployment, while companies should hire security engineers, use frontier models defensively, invest in supply-chain security and memory-safe languages, and drastically speed up patch triage and rollout before attacker capabilities outpace defenses.
HN Discussion:
  • ~Personal computers and end-user devices are overlooked in the security discussion
  • LLM threat is overblown since dangerous information is already freely available
  • Author overestimates current LLM performance on consumer hardware
  • We have even less than a year; the threat is already here
  • Security has been chronically underinvested for decades; maybe AI panic will finally force change
5.Watch Los Angeles get built, one building at a time (1880–2026)(lax-skyline.parcelscope.net)
335 points by rustywasm 2 days ago | 180 comments | permalink
tl;dr: An interactive visualization plots every building currently standing in LA County as a box, appearing in the year it was constructed, spanning 1880 to 2026. Because demolished structures are excluded, the animation depicts the surviving building stock rather than a true historical record of the county's development.
HN Discussion:
  • LA's inefficient land use and sprawl reflects car-centric planning and restrictive zoning
  • Explicitly reinforces the article's caveat that this shows surviving buildings, not true historical development
  • LA's lost public transit network and historical context adds background to the visualization
  • Shares related visualization or data projects inspired by similar techniques
  • Personal appreciation for LA's scale and character based on lived experience
6.Leaving VMware just got harder after Broadcom pulled VDDK downloads(virtualizationhowto.com)
263 points by josephcsible 2 days ago | 149 comments | permalink
tl;dr: Broadcom has quietly removed public downloads for VMware's Virtual Disk Development Kit (VDDK), a library that underpins migration tools from Microsoft Azure Migrate, Red Hat MTV, Nutanix Move, Platform9's vJailbreak, and virt-v2v. Support has reportedly confirmed the removal is intentional, with access now restricted to Broadcom Technology Alliance Partners, forcing customers into agent-based migrations or storage-assisted workarounds. Proxmox migrations are unaffected since its built-in import tool doesn't rely on VDDK, but the timing—coinciding with the return of vSphere Standard—looks to many like a lock-in tactic against customers leaving the platform.
HN Discussion:
  • Nostalgic lament for VMware's decline under Broadcom's value-extraction strategy
  • Customers deserve blame for building critical infrastructure on proprietary lock-in
  • ~Migration off VMware is technically feasible using alternative tools like qemu-img or Proxmox's built-in import
  • Big enterprises with existing investments are fine staying on VMware/vSphere
  • VMware's ecosystem and tech should be preserved before Broadcom destroys it
7.Jellyfin 12.0(jellyfin.org)
588 points by 0xC0ncord 2 days ago | 331 comments | permalink
tl;dr: Jellyfin 12.0 drops the leading "10." from version numbers and builds on the 10.11 database rewrite with major performance gains, particularly for playlists and collections (now stored per-row rather than as monolithic blobs). Notable additions include proper native support for books/comics (absorbing much of the Bookshelf plugin), alternate versions for TV episodes, per-library recommendation sources, and the Modern layout as default. Upgrading requires being on 10.10.7 or 10.11.x first, a full backup, a mandatory library rescan, and removal of third-party plugins; legacy `/emby/` and `/mediabrowser/` endpoints are also gone.
HN Discussion:
  • Successful smooth upgrades to 12.0 with noticeable performance improvements
  • ~Jellyfin apps and client experience (subtitles, TV interfaces) remain problematic
  • Jellyfin serves as valuable insurance/alternative against Plex's user-hostile direction
  • Delight that native book support absorbs the abandoned Bookshelf plugin
  • Wishes for simpler alternatives or better logging/observability in Jellyfin
8.216M Spy TVs – The LG Smart TV Problem [video](youtube.com)
882 points by treve 3 days ago | 989 comments | permalink
tl;dr: Summary not available
HN Discussion:
  • Users who preemptively disabled network access on their LG TVs feel vindicated by the report
  • The contractual terms and consent requirements imposed by LG are outrageous and possibly illegal under wiretap laws
  • Simple network disconnection is insufficient; drastic hardware measures are needed to truly stop the spying
  • ~Ironic that a story criticizing data collection appears on ad-laden sites with their own tracking partners
  • The industry trend of smart devices spying on users is escalating and manufacturers should face consequences
9.WeatherNext 3(deepmind.google)
402 points by matthieu_bl 7 days ago | 106 comments | permalink
tl;dr: Google's WeatherNext 3 is a global AI weather model that generates hourly forecasts directly from raw satellite imagery, predicting surface variables like temperature and humidity at 5km resolution and wind at 10km. It targets both consumer products (Search, Maps, Gemini) and industry applications such as renewable energy operators needing radiation and cloud cover data. Google claims it helped the National Hurricane Center improve predictions for Hurricane Melissa's landfall in Jamaica.
HN Discussion:
  • Google's current weather forecasts are unreliable, undermining claims of AI improvements
  • ~Reduced input data availability may limit real-world forecast quality
  • The interactive exploration tool and demo are impressive and usable
  • Nostalgia for Dark Sky suggests current offerings still fall short
  • Questions about accessibility, availability, and explanatory value of the model
10.Scientists observe Einstein's gravity in the quantum world(ox.ac.uk)
259 points by mudil 5 days ago | 94 comments | permalink
tl;dr: Summary not available
HN Discussion:
  • Trusts the result while noting difficulty of measurement and finding it a cool advance
  • Curious follow-up questions about physics implications of the finding
  • Skepticism about the authors' track record of making big claims
  • Shares supplementary educational resources to help understand the experiment
  • ~Questions whether the effect is truly quantum or explainable by Newtonian gravity
11.Trusting-Trust Attack against an Entire Linux Distribution(arxiv.org)
238 points by signa11 5 days ago | 58 comments | permalink
tl;dr: Researchers demonstrate that Thompson's trusting-trust attack isn't limited to compilers by implementing it via GNU strip, a build utility that neither reads nor emits source code. Using a single tampered strip binary in the NixOS bootstrap seed, they propagate a backdoor across strip generations that persists after the seed exits the dependency closure, ultimately backdooring nearly every binary in a full graphical installer built from a real nixpkgs revision.
HN Discussion:
  • Wheeler's diverse double-compiling counter-attack still applies and the paper dismisses it unconvincingly
  • Provides supplementary context on bootstrap seeds and encourages extending the work to other platforms
  • The attack is not novel — Thompson himself noted it applied beyond compilers, and it's essentially a known virus concept
  • Points to existing solutions like Guix full-source bootstrap or Orange Book traceability as mitigations
  • The finding is trivial — compromised build tools obviously compromise artifacts
12.Navier-Stokes – Tristan Buckmaster [pdf](cims.nyu.edu)
1996 points by procedurecall 2 days ago | 811 comments | permalink
tl;dr: Summary not available
HN Discussion:
  • Outrage at OpenAI for allegedly stealing research and threatening academics
  • Skepticism that AI companies honor their no-training-on-data promises
  • This will cause institutions to distrust and restrict AI tool usage
  • Defense of OpenAI or noting the accused has denied allegations
  • ~Questioning credit attribution since original ideas came from other mathematicians
13.This Month in Ladybird – August 2026(ladybird.org)
279 points by exploraz 5 days ago | 79 comments | permalink
tl;dr: Ladybird's August update brings video playback on Twitch, JavaScript debugging in DevTools, CSS scroll snap, resumable downloads, and full session restore. Major performance work landed via a new incremental style engine, layout result caching, and off-main-thread CSS animations, roughly doubling StyleBench scores and lifting Speedometer numbers significantly. CSS parsing and the painting pipeline were rewritten in Rust, JavaScript value caging was added for security, and site compatibility fixes improved ChatGPT, VS Code, iCloud, Strava, and Outlook. First alpha is still on track for 2026.
HN Discussion:
  • Enthusiasm about Ladybird's progress and eagerness to use it as a daily driver or replace Firefox
  • Skepticism that Ladybird can truly compete with established browsers due to web standards complexity
  • Curiosity and questions about how browser engines are built and the process involved
  • Appreciation for the technical rigor, like parallel engine testing in debug builds
  • ~Concern about specific technical choices like parallel download connections fragmenting files
14.Keep Our Servers Running(blog.archive.org)
1032 points by sonicrocketman 3 days ago | 272 comments | permalink
tl;dr: The Internet Archive is running a September fundraising campaign, offering a 2:1 match on new recurring donations of $25 or more. The organization, which maintains 210 petabytes of data across self-managed infrastructure without ads or paywalls, says donations averaging ~$25 fund the servers, storage, and staff behind the Wayback Machine and its digital library.
HN Discussion:
  • Enthusiastic supporter encouraging donations and volunteering for the Internet Archive
  • ~Supporter frustrated by donation UX issues like hard-to-cancel recurring charges
  • Skepticism about the 2:1 matching scheme's transparency and legitimacy
  • Explanation that matching donations serve legitimate 501c3 public support requirements
  • Questions about donation logistics like EU receipts or higher-tier data access
15.Simple Is Not Small(jyn.dev)
257 points by zdw 6 days ago | 88 comments | permalink
tl;dr: The author argues that "simple" (decoupled) is often conflated with "small," using Unix pipelines as an example: they're small but tightly couple concerns like aggregation and ordering, making modifications painful. In contrast, large programs like Google Drive or Clojure's map-based structs can be decoupled and thus simpler to use and extend. Writing truly simple software is hard and sometimes requires massive engineering investment (see SQLite, Blink), but coupling should always be minimized regardless of program size.
HN Discussion:
  • Connects article's thesis to Rich Hickey's 'Simple Made Easy' talk and reinforces its value
  • Unix pipelines are extensible, so the criticism of them is unfair
  • Clojure's approach couples runtime type info to data; Rust's tradeoff isn't strictly worse
  • ~The term 'simple' is ill-defined or used confusingly in the article
  • ~Agrees decoupling is hard but frames complexity through domain modeling or proof length instead
16.bzip3(github.com)
423 points by tosh 3 days ago | 122 comments | permalink
tl;dr: Bzip3 is a modern successor to Bzip2 that combines a Burrows-Wheeler transform (via suffix arrays), LZP preprocessing, and an order-0 context mixing entropy coder to achieve significantly better compression ratios and speed. In benchmarks compressing a tar of all Perl5 releases, bzip3 outperformed xz, bzip2, and zstd on ratio (546MB vs. 2GB for xz), with decompression time competitive with zstd. It's LGPLv3-licensed and works well for text and code, though the author warns of the usual risks of relying on a newer compressor for irreplaceable data.
HN Discussion:
  • Benchmarks are cherry-picked; zstd's window size was unfairly small compared to bzip3's block size
  • ~Real-world adoption is limited by lack of software/tooling support for newer compressors
  • The naming convention piggybacks on the bzip brand inappropriately
  • Bzip3 isn't actually impressive when compared on standard benchmarks like enwik
  • Provides useful context/history via previous discussions and benchmark references
17.Caltech Mathathon – first hackathon ever devoted to research level mathematics(mathathonchallenge.com)
266 points by astroanax 3 days ago | 95 comments | permalink
tl;dr: Caltech is hosting the first research-level math hackathon Oct 30–Nov 1, giving 100 teams 40 hours and $2M+ in AI credits to attack open conjectures using frontier models, then defend results before leading mathematicians. Prizes will be awarded on-site and again after community verification. The event is framed around recent AI-driven breakthroughs (e.g., claimed disproofs/constructions on Erdős's unit-distance conjecture, non-sofic groups, and complex structures on the six-sphere) and asks how AI reshapes mathematicians' roles.
HN Discussion:
  • Organizer clarifies event details and emphasizes responsible AI use commitment
  • Sharing useful resources like open problem lists for potential participants
  • Hackathon format is poorly suited to LLM-based math research workflows
  • Event fills a gap left by Caltech's weak CS/AI department offerings
  • Skepticism that big AI labs are exploiting mathematicians as cheap validation labor
18.Smartphone makers don't bother to comply with EU repairability requirements(theregister.com)
304 points by mdp2021 3 days ago | 200 comments | permalink
tl;dr: One year into the EU's smartphone repairability rules, over 80% of devices fail to provide required repair information, with roughly half of registry entries containing blank URL fields and some pointing users to Temu or AliExpress for parts. Manufacturers self-assign repairability scores with no verification, and many non-compliant vendors still give themselves top "class A" ratings. Right to Repair Europe is calling for stricter enforcement and mandatory documentation ahead of February's incoming rules requiring user-replaceable batteries.
HN Discussion:
  • ~EU enforcement is typically slow and gradual; low compliance early on is expected and improvement will come
  • Regulation is good but must be backed by robust and even-handed enforcement to be effective
  • Confirms and amplifies the article's findings about manufacturers deceptively linking to AliExpress
  • Focus should be on user-replaceable batteries as the key repairability issue
  • Early-stage non-compliance doesn't matter much; consumer choice and gradual change is what counts
19.Bill Gates tries to install MovieMaker (2003)(techemails.com)
420 points by highfrequency 3 days ago | 285 comments | permalink
tl;dr: In a 2003 internal email, Bill Gates details his hour-long ordeal trying to download Windows Movie Maker from Microsoft.com, encountering broken search, slow pages, confusing Windows Update flows, forced reboots, cryptic hotfix names cluttering Add/Remove Programs, and a broken registration form — ultimately failing to install either Movie Maker or the Digital Plus pack. The follow-up thread shows Microsoft managers scrambling to assign ownership, with debate over whether the mess belonged to marketing, Windows Update, or the product teams, and complaints that no single group owned the end-to-end download experience.
HN Discussion:
  • Executives dodging ownership and forming committees illustrates dysfunctional corporate culture
  • ~Gates himself is to blame for not grasping the deeper systemic design failures
  • Microsoft's poor UX problems persist to this day, confirming the article's diagnosis
  • Monopoly status allowed Microsoft to tolerate broken products without consequences
  • Firing someone might have forced accountability, though executives are structured only to report
20.De-Brainrot Vacations(devz.cl)
506 points by DanielVZ 3 days ago | 207 comments | permalink
tl;dr: A software engineer noticed his thinking had grown lazier after 8 years on the job, compounded by AI tools and phone-based dopamine hits. During a slow countryside vacation, he read four books and rediscovered learning for its own sake by working through calculus, trigonometry, and physics textbooks (Stewart's Calculus, Paul's Notes, University Physics). He reports feeling less intellectually lazy, though he's unsure if the effect will last.
HN Discussion:
  • The cognitive decline from constant dopamine and AI reliance is a universal, troubling phenomenon
  • Older engineers confirm the effect exists even for those who remember life before constant dopamine hits
  • Physical disconnection via walks, pilgrimages, or remote travel is an effective de-brainrot method
  • ~Rest and simplicity, rather than intellectual self-improvement, is the better vacation approach
  • ~Exercise, side projects with real doing, and sustained habits matter more than one-off vacations