How Mark Klein told the EFF about Room 641A [book excerpt]

You don't have permission to access "http://thereader.mitpress.mit.edu/the-whistleblower-who-uncovered-the-nsas-big-brother-machine/" on this server.

Opus 4.7 knows the real Kelsey

https://substackcdn.com/image/fetch/$s_!q0IX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F830c09c6-06a9-47e6-8552-6ba2cbfd3da5_2121x1414.jpeg
The author is concerned that AI models like Claude Opus 4.7 can identify individuals from their writing style, even if they write anonymously. This could lead to a loss of anonymity for writers and potentially harm those who rely on it for protection.

For Linux kernel vulnerabilities, there is no heads-up to distributions

CVE-2026-31431 is a Linux kernel vulnerability introduced in 2017, affecting multiple kernel versions. A workaround patch has been attached to disable the affected module.

Shai-Hulud Themed Malware Found in the PyTorch Lightning AI Training Library

https://semgrep.dev/assets/people/isaac-evans.jpeg
A supply chain attack compromised the PyPI package 'lightning' versions 2.6.2 and 2.6.3, stealing credentials and attempting to poison GitHub repositories. The attack is linked to the 'mini Shai-Hulud' campaign and affects teams using lightning in their dependency tree.

I Got Sick of Remembering Port Numbers

https://raw.githubusercontent.com/graiz/local.vibe/main/docs/dashboard-grid.jpg
The user created local.vibe, a tool to simplify local development by auto-assigning ports and proxying hostnames. It's a single Go binary with a setup process and a Unix socket reverse proxy, open-sourced under MIT license.

Maladaptive Frugality

The writer realized they had maladaptive frugality, prioritizing saving over spending on essential expenses and experiences. They learned to reframe frugality as a tool, not a virtue, and focus on mindful spending to achieve a higher quality of life.

Can I disable all data collection from my vehicle?

https://media.rivian.com/image/upload/f_auto,q_auto/v1695930282/rivian-com/default-riv-com-sharing-image_gjg8mw.jpg
Rivian vehicles have a core feature of vehicle connectivity that can be disabled to limit functionality. Disabling connectivity will not affect subscriptions like Connect+, but will require separate cancellation.

CPanel and WHM Authentication Bypass – CVE-2026-41940

https://storage.ghost.io/c/a0/dc/a0dcbbe4-0ae7-4d7e-90f7-ebbc3a0f5a84/content/images/size/w1200/2026/04/Group-8730--2-.png
A vulnerability in cPanel & WHM allows authentication bypass due to unstripped CRLF in session loading and saving. Exploiting this vulnerability can lead to unauthorized access to management planes of significant parts of the internet.

I built a Game Boy emulator in F#

https://nickkossolapov.github.io/fame-boy/building-a-game-boy-emulator-in-fsharp/images/pokemon.gif
A software engineer built a working Game Boy emulator, Fame Boy, in F# after learning about computer hardware by emulating a Game Boy and using AI to write unit tests. The emulator's development involved optimizing performance, fixing issues with the PPU and APU, and learning about functional programming and domain-driven development.

Claude Code refuses requests or charges extra if your commits mention "OpenClaw"

Something went wrong, but don’t fret — let’s give it another shot. Some privacy related extensions may cause issues on x.com. Please disable them and try again.

Vercel’s pricing page

https://theupsellgame.com/og.png
Vercel's pricing page hides per-seat tax, bandwidth overages, and DDoS costs. The Hobby plan has a hard cap that takes sites offline without warning after 30 days.

How an oil refinery works

https://substackcdn.com/image/fetch/$s_!AIFC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff98b1375-89f9-4b10-a92a-25faf8a82069_800x600.png
Oil refineries process crude oil into various products like gasoline, diesel, and jet fuel using distillation, cracking, and other processes. The refining process is complex and requires large industrial facilities to handle the massive volume of crude oil consumed worldwide.

Show HN: Winpodx – run Windows apps on Linux as native windows

https://raw.githubusercontent.com/kernalix7/winpodx/main/CI.svg
winpodx is a Linux tool that runs Windows apps natively, with real icons and WM_CLASS, using FreeRDP RemoteApp and dockur/windows. It's in active development with a redesigned host-guest pipeline and auto-discovery of installed apps.

Reverse Engineering SimTower

https://phulin.me/_astro/original.C9m_DFGt_Z1MbqzI.webp
The user attempted to reverse engineer a childhood video game, SimTower, using a large language model (LLM) to create a clean-room spec. However, the LLM struggled with complexity and verbosity of the binary, requiring a different approach.

OpenWarp

OpenWarp 是基于 Warp 开源代码的社区分支,支持自定义 OpenAI 接口和多语言。它保留 Warp 体验,允许用户控制 AI 层和凭证。
The SIMD Quad algorithm is a new search algorithm that combines quaternary interpolation search with SIMD instructions to efficiently locate a target value in a sorted array of 16-bit unsigned integers. It outperforms binary search on both Intel and Apple platforms, with significant speedup on large arrays in cold cache scenarios.

New mechanical panoramic film camera from Jeff Bridges

https://wideluxx.com/wp-content/uploads/2026/04/a-different-way-to-see.jpg
The WideluxX is a modern swing-lens camera that captures panoramic images on 35mm film through a single continuous exposure. It preserves the character of the original system while offering a unique way to create images that reflect duration rather than a single instant.

Belgium stops decommissioning nuclear power plants

Belgium will nationalize its nuclear power plants, reversing a 2003 decision to phase out nuclear energy by 2025. The government aims to build new nuclear plants and reduce dependence on fossil imports.

Honker – Durable queues, streams, pub/sub, and cron scheduler in a SQLite file

https://honker.dev/_astro/honker.DaDfuCrv_Z2dOHq9.webp
honker adds durable pub/sub and task queue to SQLite without client polling or daemon. It uses SQLite's PRAGMA data_version for wake signals, with ~0.7 ms latency and ~3 µs read time.

Roboticist-Turned-Teacher Built a Life-Size Replica of Eniac

https://spectrum.ieee.org/media-library/man-crouches-behind-three-robots.png?id=65575461&width=1200&height=937
Tom Burick has always considered himself a builder. Over the years he’s designed robots, constructed a vintage teardrop trailer, and most recently, led a group of students in building a full-scale replica of a pivotal 1940s computer. Burick is a technology instructor at PS Academy in Gilbert, Ariz., a middle and high school for students with autism and other specialized learning needs. At the ...

Snowball Earth may hide a far stranger climate cycle than anyone expected

https://scx0.b-cdn.net/pic/Gaby.jpg
A new study suggests that Earth's Sturtian glacial period was not a single long period of glaciation, but rather cycles of glaciation and warm periods. The cycles were triggered by the weathering of the Franklin Large Igneous Province, which drew down CO2 and caused repeated glaciations.

Full-Text Search with DuckDB

The user explores DuckDB's full-text search (FTS) capabilities, comparing them to other FTS solutions like Elasticsearch and Postgres, and finds them powerful but limited. They provide a tutorial on using DuckDB's FTS extension with Python, including pre-processing email data and querying with Okapi BM25 algorithm.
https://bidprowl.com/_next/image?url=%2Fhero-bg.jpg&w=3840&q=75&dpl=dpl_F47zHcWqRVxrLvoiyWwPCEkVkuh2
We monitor 27 government auction sources with 75,070 listings, scoring auctions for price, bid velocity, and time left. Daily emails highlight top-scored auctions with direct links to original listings.

Does Postgres Scale?

https://cdn.prod.website-files.com/672411cbf038560468c9e68f/69ea2dc7999383569d2a806e_5415db4d.png
A Postgres server can handle up to 144K writes per second or process 43K workflows per second, making it suitable for most use cases. The bottleneck in performance is often the write-ahead log (WAL) and can be mitigated by sharding across multiple Postgres servers or using multiple queues.

10Gb/s Ethernet: what I did to get it working in my home

https://www.gilesthomas.com/images/x-icon.png
The user upgraded their home network to 10Gb/s Ethernet, starting with their study and then expanding to the rest of the house, using a combination of 10Gb/s switches, SFP+ modules, and DAC cables. They encountered some thermal issues with the switches and SFP+ modules, but were able to mitigate them and achieve speeds of up to 9Gb/s, with plans to potentially upgrade to 40Gb/s or higher in ...

Show HN: What happens when you load a webpage (Interactive)

A web page load involves seven distinct phases, each with its own physics and bottleneck. Optimizing the render phase, which accounts for most wall-clock time, yields the greatest performance gains.

The Church Rock Uranium Mill Spill

https://upload.wikimedia.org/wikipedia/commons/thumb/d/d5/United_Nuclear_Corporation_Church_Rock_Uranium_Mill.jpeg/250px-United_Nuclear_Corporation_Church_Rock_Uranium_Mill.jpeg
The Church Rock uranium mill spill occurred on July 16, 1979, in New Mexico, releasing 1,100 tons of radioactive waste into the Puerco River. The spill contaminated groundwater and affected local residents, mostly Navajo people, who were not warned of the dangers for days.

A Milestone in Formalization: The Sphere Packing Problem in Dimension 8

https://www.alphaxiv.org/api/paper-twitter-image?title=A+Milestone+in+Formalization%3A+The+Sphere+Packing+Problem+in+Dimension+8&authors=Sidharth+Hariharan%2C+Christopher+Birkbeck%2C+Seewoo+Lee%2C+Ho+Kiu+Gareth+Ma%2C+Bhavik+Mehta%2C+Auguste+Poiroux%2C+Maryna+Viazovska
Viazovska solved the sphere packing problem in dimension 8 using modular forms in 2016. The result was formally verified in February 2026 using Lean Theorem Prover and autoformalization model 'Gauss'.

Follow-up to Carrot disclosure: Forgejo

User faced backlash for vulnerability disclosure on Mastodon and Forgejo, receiving unwanted attention and vile names. User apologized and sent constructive email to Forgejo security team with recommendations and proof-of-concepts.

The Hearts of the Super Nintendo

https://fabiensanglard.net/snes_hearts/resonator.webp
The Super Nintendo's components work together at the hardware level with a CLK output pin connected to a copper line spreading to most components. The console has two master clocks, one at 21.47727MHz and another at 24.576MHz, which are used to generate various clocks for the CPU, PPU, and other components.