Hacker News

Latest

OpenAI's $852B valuation faces investor scrutiny amid strategy shift, FT reports

2026-04-15 @ 01:36:22Points: 93Comments: 95

The FCC just saved Netgear from its router ban for no obvious reason

2026-04-15 @ 01:07:19Points: 94Comments: 34

Apple App Store threatened to remove Grok over deepfakes: Letter

2026-04-14 @ 23:41:43Points: 68Comments: 32

Fuck the cloud (2009)

2026-04-14 @ 22:00:11Points: 133Comments: 79

Stop Flock

2026-04-14 @ 21:56:05Points: 507Comments: 125

Free, fast diagnostic tools for DNS, email authentication, and network security

2026-04-14 @ 20:42:21Points: 51Comments: 4

Trusted access for the next era of cyber defense

2026-04-14 @ 20:07:20Points: 72Comments: 49

Tell HN: Fiverr left customer files public and searchable

2026-04-14 @ 18:56:40Points: 473Comments: 97

Besides the PDF processing value add, Cloudinary effectively acts like S3 here, serving assets directly to the web client. Like S3, it has support for signed/expiring URLs. However, Fiverr opted to use public URLs, not signed ones, for sensitive client-worker communication.

Moreover, it seems like they may be serving public HTML somewhere that links to these files. As a result, hundreds are in Google search results, many containing PII.

Example query: site:fiverr-res.cloudinary.com form 1040

In fact, Fiverr actively buys Google Ads for keywords like "form 1234 filing" despite knowing that it does not adequately secure the resulting work product, causing the preparer to violate the GLBA/FTC Safeguards Rule.

Responsible Disclosure Note -- 40 days have passed since this was notified to the designated vulnerability email (security@fiverr.com). The security team did not reply. Therefore, this is being made public as it doesn't seem eligible for CVE/CERT processing as it is not really a code vulnerability, and I don't know anyone else who would care about it.

I wrote to Flock's privacy contact to opt out of their domestic spying program

2026-04-14 @ 17:47:00Points: 558Comments: 228

OpenSSL 4.0.0

2026-04-14 @ 17:45:34Points: 232Comments: 75

Show HN: Plain – The full-stack Python framework designed for humans and agents

2026-04-14 @ 17:43:17Points: 77Comments: 28

Turn your best AI prompts into one-click tools in Chrome

2026-04-14 @ 17:09:43Points: 141Comments: 62

Claude Code Routines

2026-04-14 @ 16:54:33Points: 525Comments: 303

5NF and Database Design

2026-04-14 @ 16:22:49Points: 147Comments: 56

Show HN: LangAlpha – what if Claude Code was built for Wall Street?

2026-04-14 @ 14:48:46Points: 123Comments: 39

MCP tools don't really work for financial data at scale. One tool call for five years of daily prices dumps tens of thousands of tokens into the context window. And data vendors pack dozens of tools into a single MCP server, schemas alone can eat 50k+ tokens before the agent does anything useful. So we auto-generate typed Python modules from the MCP schemas at workspace init and upload them into the sandbox. The agent just imports them like a normal library. Only a one-line summary per server stays in the prompt. We have around 80 tools across our servers and the prompt cost is the same whether a server has 3 tools or 30. This part isn't finance-specific, it works with any MCP server.

The other big thing was making research actually persist across sessions. Most agents treat a single deliverable (a PDF, a spreadsheet) as the end goal. In investing that's day one. You update the model when earnings drop, re-run comps when a competitor reports, keep layering new analysis on old. But try doing that across agent sessions, files don't carry over, you re-paste context every time. So we built everything around workspaces. Each one maps to a persistent sandbox, one per research goal. The agent maintains its own memory file with findings and a file index that gets re-read before every LLM call. Come back a week later, start a new thread, it picks up where it left off.

We also wanted the agent to have real domain context the way Claude Code has codebase context. Portfolio, watchlist, risk tolerance, financial data sources, all injected into every call. Existing AI investing platforms have some of that but nothing close to what a proper agent harness can do. We wanted both and couldn't find it, so we built it and open-sourced the whole thing.

Rare concert recordings are landing on the Internet Archive

2026-04-14 @ 13:46:31Points: 584Comments: 170

jj – the CLI for Jujutsu

2026-04-14 @ 10:33:39Points: 512Comments: 446

Backblaze has stopped backing up OneDrive and Dropbox folders and maybe others

2026-04-14 @ 08:30:27Points: 1017Comments: 618

Introspective Diffusion Language Models

2026-04-14 @ 07:57:33Points: 251Comments: 45

A new spam policy for “back button hijacking”

2026-04-14 @ 03:06:27Points: 860Comments: 488

DaVinci Resolve – Photo

2026-04-14 @ 02:25:15Points: 1081Comments: 271

The dangers of California's legislation to censor 3D printing

2026-04-13 @ 23:44:24Points: 318Comments: 327

Let's talk space toilets

2026-04-13 @ 22:41:19Points: 161Comments: 47

Troubleshooting Email Delivery to Microsoft Users

2026-04-12 @ 12:40:34Points: 50Comments: 14

The Orange Pi 6 Plus

2026-04-11 @ 17:48:02Points: 150Comments: 109

Ask HN: Easiest UX for Seniors

2026-04-11 @ 10:31:51Points: 48Comments: 49

In general, what is the best way to simplify the auth UX for this group of users? Is there any UI libraries out there targeting this group more specifically? Any good web examples you know of?

thx

Picasso's Guernica (Gigapixel)

2026-04-11 @ 08:27:06Points: 84Comments: 20

A Communist Apple II and Fourteen Years of Not Knowing What You're Testing

2026-04-10 @ 22:36:24Points: 91Comments: 10

Understanding Clojure's Persistent Vectors, pt. 1 (2013)

2026-04-10 @ 17:14:18Points: 40Comments: 5

guide.world: A compendium of travel guides

2026-04-09 @ 18:17:32Points: 91Comments: 14

Archives

2026

2025

2024

2023

2022