AI Summarized Hacker News

Front-page articles summarized hourly.

Xray-core concealed a certificate verification bypass vulnerability

Xray-core masked a certificate verification bypass for about six months. The issue stemmed from the pinnedPeerCertSha256 option, introduced after removing the old pinnedPeerCertificateChainSha256; it could bypass standard verification in favor of custom pinning. A bypass vulnerability was found Feb 6, 2026 and silently fixed the same day without disclosure, with later claims of security improvements. By July 3, 2026 the fix was incomplete, and a GitHub Security Advisory was filed. The episode highlights poor security practices and user exposure to MITM attacks.

HN Comments

A man who listens to whales

David Gruber, marine biologist and founder of Project CETI (the Cetacean Translation Initiative), aims to decode sperm whale communication using artificial intelligence and machine learning. He views this as the natural next step in science, though some see it as audacious or a fool’s errand. Gruber’s life—from a New Jersey kid who felt kinship with tiny creatures to a scientist exploring microbiology, oceanography, and visual communication—shaped his quest to understand whale language.

HN Comments

Incentives in Academic Research

Incentives in Academic Research argues that current incentives push results toward publishing and prestige rather than truth and scientific understanding. The author laments a culture of lax honesty, reluctance to retract known errors, and tolerance for misleading findings. Personal anecdotes illustrate a shift from past rigor and accountability to present indifference among some researchers. He questions how to fix a system that rewards fame over correctness, calling for integrity, transparency about uncertainties, and prompt correction to train the next generation properly.

HN Comments

I asked Claude build a physically accurate O'Neill cylinder you can walk around

Could not summarize article.

HN Comments

Homa: The End of TCP for AI Clusters [video]

Could not summarize article.

HN Comments

Remove and Disable Apple Macos27 AI Models Tool

RemoveMacAI is a macOS 27 utility that turns off Apple Intelligence and removes its on-disk models to free space. Changes are fully reversible with removemacai revert. It applies a configuration profile to disable features and blocks model re-downloads via a local port; no data leaves your device. Install with a one-line curl script or via Homebrew. Disabled features include Siri, Writing Tools, Genmoji, Image Playground, the ChatGPT extension, and several Mail/Notes/Safari/nlp features; removed models include foundation models and related image/Spatial Photos/Xcode completion assets. Apple silicon required.

HN Comments

Improper redaction reveals Google Data Center water and electricity usage

An audit of Nebraska data-center reports reveals improper redaction masking electricity and water use. Google’s Lincoln data center (Agate LLC) shows 52.65 MW peak demand and about 13.3 million gallons of water last year; six centers total about 765 million gallons. Fireball Group LLC (Papillion) reports the most water at 547.88 million gallons for 2025. Public records show Google centers expected tax refunds in the tens of millions (Agate $55.8M; Fireball $39.2M; Westwood Solutions $22.6M). The reports are part of a governor-ordered self-reporting program overseen by the Data Center Task Force.

HN Comments

Bill Draper has died

Could not summarize article.

HN Comments

The dot and the Swarm: Benefitting from the bitter lesson

Mollick revisits the Bitter Lesson: systems that learn from data beat hand-built management tools, and this extends to organizing work with AI agents. Personal agents like Muse and Dots can self-organize tasks and draft plans with minimal human input, and when many such agents act together they can coordinate across thousands of messages with thin supervision—as shown by the Navier-Stokes swarm. Humans still set the goals and steer direction, but organizing work may become easier through agents, though risks remain (Hugging Face incident).

HN Comments

Page Table Memory Consumption

Examines page-table memory consumption and cache/TLB implications of tree vs hashed page tables; argues that a good TLB fill should cache as many entries as fit in one cache line. Surveys memory-efficiency concerns when many processes map the same pages: PTEs scale with address spaces, so 512 processes mapping one 4 KiB page cost 4 KiB in PTEs, potentially dwarfing data pages. Covers 32-bit lowmem/highmem, PATCHes like mshare, and real-world DB cases (Postgres, ClickHouse) where huge pages reduce page-table growth. Discusses NUMA challenges (remote page tables) and approaches (replication vs on-demand copying) like Hydra vs Mitosis.

HN Comments

Declaring a bird extinct: The median wait is 36 years after the last sighting

Access to the page is forbidden (HTTP 403).

HN Comments

Second Chances

Jonathan Lethem surveys Wilfrid Sheed’s 1966 novel Office Politics, republished by McNally Editions, to examine the current boom in rediscoveries and reissues. He traces how publishers like Virago, Vintage, NYRB Classics, and others cultivate uniform editions, forewords, and notes to fuel renewed interest in forgotten authors (Berlin, Powell, Adler, Oreo, etc.) amid a broader “analog” revival. Lethem uses Sheed’s satire of The Outsider’s staff and editor Gilbert Twining to explore how revival culture foregrounds wit, power dynamics, and ambivalent belief. While Sheed’s prose delights, Lethem argues the project should not exceed its usefulness; sometimes we don’t need more Sheed.

HN Comments

Fog-Bank: Archiving the oldest webcam feed

FogCam publishes frames that Fog-Bank preserves, logging every fault. Four fetchers on separate networks pull frames at regular intervals, archiving each one, with frequent sweeps and nightly retries. Each request retrieves the live file to avoid caching. Frames are named by upload time, hashed, stamped without recompression, stored losslessly as JPEG XL, and copied to Cloudflare R2 instantly. A status board monitors the path from camera to YouTube and notifies via Telegram on outages. The page lists outages, attributed to FogCam or the operator, with examples and links to the live archive, backups, and forensic record.

HN Comments

Show HN: Build with Python – a beginner course where your code draws

Draw with Python is a 45-minute SciMigo Build with Python lesson teaching beginners to draw on a canvas. Students build a robot, repeat patterns, and respond to clicks, learning function calls, variables, loops, and click events to create a click-to-draw painting (including a row of circles).

HN Comments

How to scale intent, quality, and artistry with AI [video]

Could not summarize article.

HN Comments

How effective altruism conquered the world (and might yet end it)

Could not summarize article.

HN Comments

Results from the Jane Street hardware puzzle

Jane Street's “Results from the ASIC puzzle” describes a reverse‑engineering challenge: a final GDS layout of a chip that implements an 11×11 Star Battle puzzle (Two Not Touch). About 400 submissions from 30+ countries used tools like KLayout, Yosys, and Z3, with code in Python, Rust, C++, OCaml, Haskell, and more. The chip validates two stars per row, column, and region, plus an adjacency check and a 121‑bit ROM mapping squares to regions; an LFSR scrambles the solution in ROM. The post covers netlist extraction, simulation, backward analysis, SAT solving, and various visualizations. Takeaway: AI aids tooling, but understanding remains key; invites entries to their protocol‑emulator ASIC competition.

HN Comments

'Neanderthals Among Us' review

Could not summarize article.

HN Comments

The CISA Alert: Security Beyond Solitary Confinement

CISA warns OT devices exposed to the Internet and urges immediate actions: remove public Internet connections, change default passwords, restrict remote access, and strengthen authentication and network protections. However, eliminating all connectivity isn't always feasible. The article advocates defense-by-design that reduces attacker opportunities with minimal resource use. JANOS on JNIOR introduces SYN greylisting, ignoring initial SYNs and requiring a retry, shrinking the attack surface across ports before authentication. Tests show disabling it allows SSH attacks to surge resources and threaten determinism. The piece calls for broader adoption of low-overhead, invisibility-like defenses in embedded TCP/IP stacks.

HN Comments

Building a RAG Pipeline for Semantic Code Search

JetBrains describes a RAG pipeline for semantic code search (Air Context). Part 1 covers pre-processing: parsing and structure-aware chunking for nine languages (Kotlin, Java, Python, JavaScript/TypeScript, C#, PHP, Go, Rust) with line-based fallback; smart chunk sizing and metadata; and vectorization to embeddings. To scale, they use 1-bit quantization for storage, trading some recall for massive compression, and keep path-based metadata to improve search. They ensure privacy: no code is stored, no data used for training, using open-weight embedders. Future parts will tackle storage, latency, and evaluation.

HN Comments

Made by Johno Whitaker using FastHTML