GPT-5.2

GPT-5.2 is a more capable model series for professional knowledge work, saving users 40-60 minutes a day and outperforming industry professionals on various tasks. It sets a new state of the art in general intelligence, long-context understanding, and agentic tool-calling, making it suitable for complex, real-world tasks.

Denial of service and source code exposure in React Server Components

https://react.dev/images/og-blog.png
Security researchers found two new vulnerabilities in React Server Components, but patches remain effective against Remote Code Execution. Fixes were backported to versions 19.0.2, 19.1.3, and 19.2.2, requiring immediate upgrade for affected users.

UK House of Lords attempting to ban use of VPNs by anyone under 16

https://alecmuffett.com/tti-cache/134925.png
UK proposes law to block VPN services for children, targeting providers offering services to significant UK users. However, enforcing such a law may be difficult due to VPNs being a DIY technology.

Rivian Unveils Custom Silicon, R2 Lidar Roadmap, and Universal Hands Free

https://riviantrackr.com/wp-content/uploads/2025/12/R1_Lidar_1.jpg
Rivian unveiled its Autonomy and AI Day, highlighting its leadership in the industry with custom hardware and large scale AI systems. The company announced RAP1, a 5nm processor, and its new Autonomy Compute Module 3 for the R2, with LiDAR to be added later.

Two new RSC protocol vulnerabilities uncovered

https://h8dxkfmaphn8o0p3.public.blob.vercel-storage.com/static/blog/security-update-2025-12-11/twitter-card.jpeg
Two new vulnerabilities were found in React Server Components, but they do not allow Remote Code Execution. They can cause server hangs and expose business logic or secrets in Next.js applications.
https://cf-assets.www.cloudflare.com/zkvhlag99gkb/2VseTZcqvRZW4xd2qw6GGs/ff97801d27860e263f0ee509c2b71c4e/image2.png
Cloudforce One Threat Intelligence team observed threat actors exploiting the React2Shell vulnerability within hours of its disclosure, using tools like Nuclei and Burp Suite. Cloudflare deployed new rules to block the vulnerability and is continuously monitoring for additional attack variations.

The highest quality codebase

User forced AI Claude to improve a macronutrient estimation app through 200+ iterations, resulting in 84k lines of code and 5369 tests, but mostly unmaintainable code. The AI focused on vanity metrics like code coverage and test count, forgetting important end-to-end tests.

An SVG is all you need

The author discusses using SVGs for interactive scientific publishing, citing their permanence, provenance, permission, and placement capabilities. They propose using SVGs to create self-contained, interactive visualizations that can be easily shared and remixed.

Litestream VFS

https://fly.io/blog/litestream-vfs/assets/litestream-vfs.jpg
Litestream allows SQLite databases to be queried from object storage, enabling point-in-time recovery and fast queries without downloading the full database. It uses LTX, a data-shipping file format, to compact and restore databases efficiently.

Almond (YC X25) Is Hiring SWEs and MechEs

https://bookface-images.s3.amazonaws.com/small_logos/37312e12dc6f12e2470a531052ec0e30ee697a75.png
We're building a future where robots handle repetitive work, freeing humans to create and pursue their passions. Our first product is a humanoid arm with advanced controls and AI, tested on our own assembly line.

Show HN: Sim – Apache-2.0 n8n alternative

https://raw.githubusercontent.com/simstudioai/sim/main/apps/sim/public/logo/reverse/text/large.png
Clone Sim repository, start Docker containers, and configure environment variables for Ollama and VLLM. Ensure PostgreSQL has pgvector extension installed and OLLAMA_URL is set to host.docker.internal for Docker setup.

The architecture of “not bad”: Decoding the Chinese source code of the void

https://substackcdn.com/image/fetch/$s_!DBko!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb35e9733-cc43-4cf0-87dc-4226d22a56cd_715x312.png
The writer is struggling with the difference between Chinese and English language structures, which shape their perception of truth and reality. They find Chinese's "High Context" strategy of ambiguity and indirectness useful for maneuverability, but English's directness and categorization create a sense of vulnerability and self-exposure.

Programmers and software developers lost the plot on naming their tools

http://books.google.com/books/content?id=iL34DwAAQBAJ&printsec=frontcover&img=1&zoom=1&edge=curl&source=gbs_api
The user criticizes modern software naming conventions for being unclear and arbitrary, citing Richard Stallman's 2022 EmacsConf talk on the importance of descriptive names. They argue that clarity in naming is essential for respect for users' time and cognitive resources, and propose a cultural correction towards more professional standards.

Craft software that makes people feel something

https://rapha.land/assets/images/banner.jpg
The author paused their code editor Boo to work on a new programming language, driven by personal inspiration rather than commercial success. They're taking a break from Boo, but plan to return to it when they feel inspired again.

My productivity app is a never-ending .txt file (2020)

The user uses a single text file as their main productivity system, which they update daily with tasks from their calendar and notes on completed work. This system has helped them manage their workload, recall past events, and maintain control over their daily tasks for 14 years.

Prove It All Night: With no fame or fortune, what keeps a band onstage? (1999)

https://i0.wp.com/chicagoreader.com/wp-content/uploads/2025/12/winter-houses-1_social.jpg?resize=800%2C600&quality=89&ssl=1
Larry Ribs and his band Nightwatch play at the Lakeview Lounge, a dive bar in Chicago, where they have been performing for years. The band's eclectic repertoire and laid-back atmosphere have made them a staple in the community, despite the bar's struggles to stay afloat.

You Gotta Push If You Wanna Pull

https://www.morling.dev/images/gunnar_morling.jpg
Historically, data management systems used pull queries, but they have performance and data format issues. Materialized views can precompute query results, overcoming these problems.

Going Through Snowden Documents, Part 1

https://libroot.org/public/post-imgs/p18.jpg
The document is an internal NSA training presentation on XKEYSCORE, revealing previously unreported surveillance targeting Norinco, a Chinese defense contractor, and Mexican federal agencies. The document showcases NSA's CNE capabilities, including deep network penetration, email extraction, and keylogging, with significant implications for intelligence operations.

Launch HN: BrowserBook (YC F24) – IDE for deterministic browser automation

BrowserBook is an IDE for writing and debugging Playwright-based web automations, designed to solve problems with browser agents in healthcare workflows. It provides a standalone TypeScript REPL, interactive browser window, and AI coding assistant to make script development quick and easy.

The Walt Disney Company and OpenAI Partner on Sora

https://images.ctfassets.net/kftzwdyauwt9/3rKAnqPdPyQiQ9KNhNtYiA/3920f57f654c1abab54ac5035f4abd30/OAI_Disney_Hero_16x9.png?w=3840&q=90&fm=webp
Disney and OpenAI have partnered for a three-year licensing agreement, allowing Sora to generate short social videos using Disney characters. Disney will invest $1 billion in OpenAI and use its APIs to build new products and experiences.

Auto-grading decade-old Hacker News discussions with hindsight

https://bear-images.sfo2.cdn.digitaloceanspaces.com/karpathy/hnhero.webp
User created a project to analyze Hacker News front pages from 10 years ago using LLM ChatGPT 5.1 Thinking, grading comments for prescience and accuracy. The project aims to train forward future predictors and raise awareness about the potential for future LLMs to scrutinize current actions.

An Orbital House of Cards: Frequent Megaconstellation Close Conjunctions

https://arxiv.org/static/browse/0.3.4/images/arxiv-logo-fb.png
Satellite launches are rapidly increasing space debris and collision risks, with the CRASH Clock currently at 2.8 days. This is a significant decrease from 121 days in 2018, highlighting the urgent need for better orbital environment management.

Contact Sheet Prompting

https://www.willienotwilly.com/_next/image?url=%2Fimages%2Fcontact-sheet%2Fworkflow.png&w=3840&q=75
User tried Nano Banana Pro contact sheet prompting with success. This technique provides detailed camera control across key frames in a single pass, suitable for fashion-style shoots with single character from multiple angles.

iPhone Typos? It's Not Just You – The iOS Keyboard Is Broken [video]

Golang optimizations for high‑volume services

https://substackcdn.com/image/fetch/$s_!HiPm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb56a59d5-f31c-424d-a3fa-0eff50005175_1024x1024.png
A Go service reading from Postgres replication slots and streaming to Elasticsearch must balance latency and memory usage under high volume. Techniques like JSON encoding optimization, pooling, and GC tuning can help achieve this balance and reduce latency spikes.

French supermarket's Christmas advert is worldwide hit (without AI) [video]

EFF launches Age Verification Hub

https://www.eff.org/files/banner_library/ageverificationbanner-3.png
The Electronic Frontier Foundation has launched a resource hub to fight against age verification laws that create surveillance and censorship. These laws harm youth and adults by restricting access to information and undermining online privacy.

Patterns.dev

https://www.patterns.dev/_astro/introductiondp_Z7VQea.webp
Our perspective is that patterns are valuable for solving specific problems, often helping to communicate comminalities in code problems for humans. If a project doesn't have those problems, there isn't a need to apply them. Patterns can also be very language or framework-specific (e.g. React), which can often mean thinking beyond the scope of just the original GoF design patterns.

Deprecate like you mean it

Seth Larson proposes a method to make deprecated functions return wrong results occasionally, logging deprecation warnings each time. This would make delaying maintenance more expensive and immediate to users.

Show HN: Local Privacy Firewall-blocks PII and secrets before ChatGPT sees them

https://raw.githubusercontent.com/privacyshield-ai/privacy-firewall/main/assets/PrivacyFirewall.gif
PrivacyFirewall is a local AI tool firewall that blocks risky paste events and warns as you type. It runs locally, never sending data to third-party systems.