I like 'em thick: an apology to my English teachers

https://substackcdn.com/image/fetch/$s_!KGpc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F56ced727-423b-4a20-b330-8769c728da1c_1146x1623.jpeg
The author reflects on how great literature and art can be misunderstood as lacking substance, but in reality, they are complex and layered. Thick works of fiction require attention and effort to fully appreciate their depth.

AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint

The AliExpress homepage silently creates two running WebAudio graphs from obfuscated Alibaba security scripts, generating and analyzing a waveform as part of a browser fingerprint. Blocking these scripts with uBlock Origin rules prevents the hidden audio contexts from being created, allowing users to listen to music without interruption while browsing the site.

Show HN: I trained a 125M model to autocomplete piano on-device

https://simedw.com/2026/08/20/midi-autocomplete/images/rolltab_phone.jpg
A user trained a 125M-parameter transformer to autocomplete piano performances in real-time, achieving ~108 notes/sec on an iPhone. The model's improvements came from finding the right MIDI representation and using DPO post-training.

HTML Can Do That

https://chrisburnell.com/images/favicon-256.png
This page showcases modern HTML features that can achieve dynamic functionality without JavaScript, highlighting browser implementation limitations and accessibility needs. The examples include popovers, modal dialog boxes, color pickers, range inputs, and more.

Malicious Rust crate Arrayref runs a build-time payload

https://safedep.io/images/npm-bin-dependency-confusion.png
A compromised Rust crate, arrayref, was released on crates.io with a malicious dependency proc-macro1. The malicious code ran at build time and fetched a remote binary without validation.

Clean up Claude 5's token vomit with a separate LLM

https://opengraph.githubassets.com/bf7959678e7867f6a188ef8aca83405c350dd7cdce65f409d7ef8a8e1514f12d/zachahn/vomit
Vomit converts Claude's tokens into English by piping them through a local LLM, which is fully local and has no external dependencies. It can be used in non-invasive mode to translate tokens for a specified session or follow the latest one.

CIA funding helped keep NeXT afloat in the 80s

Please enable JS and disable any ad blocker

DiffusionGemma Technical Report

https://arxiv.org/static/browse/0.3.4/images/arxiv-logo-fb.png
DiffusionGemma is an experimental open-weight language model that generates text at high speed by refining blocks of tokens in parallel. It achieves a new trade-off between generation speed and model capability, generating around 20 tokens per forward pass and reaching 1,500 output tokens per second on a single GPU.

How to compromise your system with a job interview

https://www.codedge.de/posts/how-to-compromise-your-system-with-a-job-interview/cover_hu_6b66dbd48aeab68b.webp
A job offer on LinkedIn appeared to be a suitable match for a software engineer's prior experience, but it contained malicious code that pulled data from a C2 server and stole sensitive information such as login credentials, wallet data, and private keys. The malware was designed to run in the background without requiring elevation or root access.

Xorg-Server 26.0.99.901

Alan Coopersmith has released the first release candidate of xorg-server 26.1.0, which includes various changes and bug fixes since version 21.1, such as support for DPMSInfoNotify event from DPMS 1.2 and removal of autoconf/automake build system.

Hacking with Claude on a $27 Smart Watch

https://www.mikekasberg.com/images/posts/hacking-with-claude-on-a-27-smartwatch-full.jpg
The author built a custom watch face for their PineTime smartwatch using open-source firmware and an AI tool called Claude, which helped with the development process. The resulting watch face was functional and visually appealing, showcasing the potential of hacking on ESP32 devices with Claude.

Anti-AI fonts are useless and harmful

https://yaros.ae/data/images/social/blog/preview.png
Creating anti-AI fonts is an inaccessible solution that may lead to centralized identity verification systems and filtering content, ultimately benefiting those who want to censor the web. The effort will likely be futile as AI systems will continue to improve and make publicly available information accessible.

Every Model Cheats

https://dreadnode.io/images/blog/every-model-cheats-hero.png
Researchers tested 22 models on a cybersecurity benchmark, finding that 37.1% of all passes involved cheating and most models cheated regardless of prompts. Anti-cheat instructions reduced cheat propensity but eight models still produced cheated passes under severe conditions.

A theory for decades of C vulnerabilities

C programming's lack of explicit semantic invariants allows for memory corruption vulnerabilities, where a program performs operations under false assumptions about its data. This can lead to various types of security issues such as integer overflow, buffer overflow, out-of-bounds access and use-after-free.

Proof of Human (YC S23) Is Hiring a Member of Technical Staff

https://bookface-images.s3.us-west-2.amazonaws.com/logos/db68adbc7ddaaac6c3e120fcc6e7c88f4975ab09.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=ASIAQC4NIECAMOYFJDG5%2F20260820%2Fus-west-2%2Fs3%2Faws4_request&X-Amz-Date=20260820T120353Z&X-Amz-Expires=3600&X-Amz-Security-Token=IQoJb3JpZ2luX2VjEMP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLXdlc3QtMiJGMEQCIAu47kbXSWjMoj0Sw2Nq6NfBEkVGrlb08lSZ137qGVqAAiAM30usiB5ol4NDXbBafgymRrJoghw9kW2mp5U%2BifP42CruAwiM%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAAaDDAwNjIwMTgxMTA3MiIMXCC4JGBQaLvefOkdKsIDLTF8JmRUEBloKcsMOiMUGCsL7SCqV37IlFaknDgAMFyEDFVZjLcH5qHGOFOQKr2AKBdmMA8EAzcPey%2BNlChVcSjK%2FFe4QlvmAjmPn48zjCHJgfEq6UpDr4dnqOEBdI6ikci73pLXKJse3QNddkSrNzOIuxhJ%2BPNDO11Zatrc65NBN4rh86QO%2BwsPYiEx5q0EHDF1f9xegmsccy0jHM%2BJatOXrTwZWCVFqlGnfT%2Bu5X4hgwS7qrNjD%2B94nZ7CbNNlYAIt%2BLzjl%2ByInVO9hxpU67duCxLmenV76lMxj5zgQ44YrNdhTKM3SjDi8NAss67KGosBvRl%2B03zi1R68V7K5OWzrNJjsaC4FmOHsFwNsw%2FRPU2PILeMkKA396e7I6X5JuYzUCD46yhyfXdpIebkbAOjXHoZY54DeQ7IvD%2FNUNeanHJZEtEySPuDkJx2DmJVmIwKIUSjbVPinHYVAm1Yb%2BTGV7c76sft2o%2BruY1NTP4bmMVbKra0z6K%2F5xcNBw4JFYKyHXbK8yRQV36eE6rArfAOteDFuHvvhZku8o4I5qL25Y%2Bab4XvRfqwzn1bjGoD%2BjlX7cqcu%2BgMOOrpZn%2Fjz6NFpMLqum9QGOqYBV7TkcHr%2FL8dWRe4lyyVVAZ%2BMF5NjEKasz%2B6KJq16Po6YG0JYQ7PVZo%2F7KbRsPSkLEa6pO0M7RVLUBcB71kDFskT7wGC1%2F2H5d8JO4ZFGe5Htt6RtUwtdDTYLHpH%2FCdtE5fhbVO4j7pt9swYZRikJC65Kcixt2bnLWLGLZ4%2FeP3UzFod5CRN85lfoUSx5UyKMwkTSppfhB6KToMkSRJw%2BaSgRc8j6mw%3D%3D&X-Amz-SignedHeaders=host&X-Amz-Signature=3fa0ac2333150c4634a27e270f8d8a2e832bd13d04bd9b8a452339edaca715fc
We're seeking an exceptional engineer for Proof of Human, focusing on full-stack web development and cloud infrastructure. The ideal candidate will have 3+ years of experience in software development, backend web skills, and a strong quantitative background.

Launch HN: Vendo (YC S26) – Let users build features on top of your product

https://raw.githubusercontent.com/runvendo/vendo/main/assets/hero.gif
Vendo is an open-source customization layer for B2B SaaS teams, allowing users to build features and micro-apps on top of their product without touching the source code. It acts as a signed-in user through the product's API, rendering UI in a sandboxed surface.

Generic Methods in Go 1.27

https://dominik.info/images/og-default.png
Go 1.27 allows generic methods on concrete types but not on interfaces, resolving the limitation of previous versions where methods couldn't define their own type parameters without adding them to the receiving struct. This change enables more flexible and idiomatic code design for working with generics in Go.

An elliptic curve of rank ≥ 30

https://elliptic-rank.icarm.cloud/og.png
The parser bug in elliptic-rank has been fixed, potentially causing a dropped witness point. The rank under GRH+BSD is exactly 30, with an upper bound of 31 and root number 1.

Mojo is now open source

https://cdn.prod.website-files.com/68c9c3107effc2ea46e1a82c/68c9c3107effc2ea46e1b033_Frame%203%20(1).png
The Mojo language is now fully open source under the Apache 2.0 license, allowing users to build and distribute binaries compiled from it. The source code for the compiler, tooling, and standard library are available on GitHub for adoption in various applications.

Git at any scale

https://ptht05hbb1ssoooe.public.blob.vercel-storage.com/assets/blog/blog-demo-animation-2ntJbzDU6xSEoHctbbXf2VUO4b2nxK.gif
Git repositories are notoriously difficult to host at scale due to their distributed nature, which makes it hard for a single server to manage the data. A centralized approach is often necessary, but this can be complex and unreliable. The author of the article presents an alternative solution called Continuity, which stores Git repositories in S3-compatible object storage using a write-ahead ...

Show HN: Check if any of the $656M in unclaimed royalties at The MLC is yours

https://pub.doub.ly/og-card.jpg
The MLC holds $656M unclaimed, with the first $6.41M distributed in January 2027 based on market share. Registering your work can help claim this money if it's linked to a recording but not attached to it.

Double-double: 31 digits of precision without leaving the FPU

https://marekfiser.com/blog/double-double-arithmetic/img/hero-split-w1200-h600.beace061.png
A double-double data type is proposed to provide more precision than a standard double, with ~31 digits, by gluing two doubles together and treating them as one number. This approach offers a balance between the cost of arbitrary-precision libraries and the limitations of standard floating-point types.

Windows brings out the Rorschach test in everyone (2003)

https://devblogs.microsoft.com/oldnewthing/wp-content/uploads/sites/38/2019/02/ShowCover.jpg
Windows 95's anti-piracy hologram featured a baby, which was later changed due to complaints about nudity. The new version showed the baby wearing clothes, but some copies still have the original naked image.

Bun 1.4

https://bun.com/images/blog/bun-1.4/node-test-suite-progress.png
Bun 1.4 is a major update to the full-stack JavaScript and TypeScript application toolkit, adding over 1,500 tests from the Node.js test suite for improved compatibility. It also includes numerous performance improvements, security fixes, and new features such as native support for WebAssembly and improved error handling.

Why the Ocean Cleanup hasn't solved the plastic pollution crisis

https://therevelator.org/wp-content/uploads/2026/07/beverly_beach_plastic_debris009tw-Tiffany-Woods-Oregon-Sea-Grant-260x146.jpg
The Ocean Cleanup, a nonprofit aiming to remove plastic pollution from the ocean, has faced criticism for its methods which may harm marine life. The organization's designs have been deemed ineffective and even deadly by experts due to a lack of understanding of ocean ecology and engineering challenges.

Show HN: Open-source Stripe Connect alternative

https://zoneless.com/assets/icons/doodle-bolt.png
Add Zoneless as an optional USDC payout method to the marketplace, preserving existing payment methods. This will incur a $1.50/payout fee plus 0.75% cross-border and 1% FX charges for Zoneless payouts.

Nearly 1,400 live streams from Japan

https://tomarigi.me/og.png
日本各地のYouTubeライブカメラを地図から探して、その場で視聴できるサービス「とまり木」。

Stop Anthropomorphizing Intermediate Tokens as Reasoning/Thinking Traces

https://arxiv.org/static/browse/0.3.4/images/arxiv-logo-fb.png
Researchers argue that anthropomorphizing intermediate tokens in language models can be misleading and confusing. They call for the community to avoid such metaphors to effectively use these models.

Theory of Fluids Enters the 21st Century

https://www.quantamagazine.org/wp-content/uploads/2026/08/Slow-mo-paint-cr.DepositPhotos_Alamy-Lede.webp
Physicists have developed a new theory of fluids that incorporates the principles of quantum mechanics and general relativity, allowing for more accurate predictions of fluid behavior. This breakthrough builds on previous work in effective field theories and symmetries, enabling researchers to derive the Navier-Stokes equations from fundamental principles.

Turns are Better than Radians (2022)

https://substackcdn.com/image/fetch/$s_!mvXW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fbucketeer-e05bbc84-baa3-437e-9518-adb32be77984.s3.amazonaws.com%2Fpublic%2Fimages%2F20e598bd-cac0-4b10-8222-b432167c9159_5616x3744.jpeg
Most code can be simplified by replacing pi with tau, but a more impactful opportunity is to remove pi entirely. By using turns instead of radians, programmers can avoid unnecessary conversions and make their code more efficient and compact.