Feed aggregator
Apple should be ashamed of its hostile App Store rating system
Article URL: https://lapcatsoftware.com/articles/2026/7/14.html
Comments URL: https://news.ycombinator.com/item?id=49098803
Points: 2
# Comments: 0
DoorDash Takes to the Sky with Its Own Drones
Article URL: https://www.wsj.com/logistics-report/doordash-takes-to-the-sky-with-its-own-drones-0cc8658d
Comments URL: https://news.ycombinator.com/item?id=49098801
Points: 1
# Comments: 0
Everywhere Foist Upon Us
Article URL: https://darthmall.net/2026/everywhere-foist-upon-us/
Comments URL: https://news.ycombinator.com/item?id=49098797
Points: 2
# Comments: 0
Show HN: AI that opens PRs on your repo to fix your SEO
Hey HN,
I'm Oli, Software engineer building Zaatar to to automate the organic growth on my different side projects.
The AI orchestrator I've built feels kind of magic tbh,
I hope some of you guys will find it useful!
Cheers
Comments URL: https://news.ycombinator.com/item?id=49098777
Points: 2
# Comments: 0
Four Competing AIs Answer 1 Classic Question
I sought advice from four mainstream A.Is for a basic consumer use case question and to me, the differing style of the answers are quite revealing.
Premise: A poorly hung clothes dryer spectacularly ripped from the wall whilst on and tumbling, smashing into the washing machine beneath and trying to exit out the laundry door in a manner reminiscent of Stephen King's haunted laundromat story The Mangler.
After all the shards of glass, wall plaster etc were cleared up, the six month old washing machine wasn't working - yes, unsurprisingly but the problem was electronic, not mechanical. The display defaulted to blanks flashing - no error code etc. Having tried all the obvious fixes, I put the dilemma to four A.I.s: Chat GPT, Perplexity, Claude (Pro) and Google Search with A.I. Mode.
All suggested more or less the same checkpoints and then a technician but diverged into unique personae + ideas.
Chat GPT: Empathetic, sycophanticaly validating "you've taken a laundry mishap and turned it into a quantum learning exercise...Here is a well-worded, no nonsense description of the problem to show to your technican or Westinghouse...You should be proud though..."
Perplexity: Scolding like the worst school teacher - essentially, "the machine is damaged because of a situation of your making. Even if it is within warranty blah blah" Have you consulted the washing machine manual? I can help you find it. (Yes I'd consulted the manual and no I had not asked Perplexity about trying to get it repaired within warranty)
Google A.I. Mode: Moved briskly onto 'new washing machine' turf. eg "What did you like most about your Westinghouse? Would you like another front loader or given your traumatic experience with the clothes dryer, would you prefer an all in one washing machine and dryer? Affiliate links galore.
Claude: It is definitely a problem with the electronics - eg: a connector ribbon failure, cracked solder joint etc etc - if you're comfortable and have the serial number, I can provide teardown instructions etc etc
I was actually into this idea and liked that Claude would have gone with me on it but as I was also on deadline, with piles of stinky laundry lurking, I ended up using H.I. - Human Intution.
Intuitively - and wasn't in the washing machine manual - I pressed the on/off button for a long hold and the machine revived - No teardown, no new machine, no eloquently composed briefs for Westinghouse nor shady attempt to get help from them either.
Comments URL: https://news.ycombinator.com/item?id=49098762
Points: 2
# Comments: 0
Show HN: OnlyVibes – No Fuss Realtime Interviews
Article URL: https://onlyvibes.cc
Comments URL: https://news.ycombinator.com/item?id=49098758
Points: 2
# Comments: 0
What screen time does to children's brains is more complicated than it seems
Article URL: https://www.bbc.com/news/articles/c9d0l40v551o
Comments URL: https://news.ycombinator.com/item?id=49098751
Points: 2
# Comments: 0
Gemini for macOS adds new natural language capabilities
Article URL: https://blog.google/innovation-and-ai/products/gemini-app/speak-naturally-gemini-app-mac-os/
Comments URL: https://news.ycombinator.com/item?id=49098747
Points: 2
# Comments: 0
Secure Your APIs: OAuth2 and JWT for Beginners
Article URL: https://blog.jetbrains.com/kotlin/2026/07/secure-your-apis-oauth2-and-jwt-for-beginners/
Comments URL: https://news.ycombinator.com/item?id=49098735
Points: 2
# Comments: 0
Lucia, Arctic and Oslo have been deprecated
Article URL: https://pilcrowonpaper.com/blog/18
Comments URL: https://news.ycombinator.com/item?id=49098734
Points: 2
# Comments: 0
The Scientific Literature Is Poisonous to LLMs
Article URL: https://www.reinvent.science/p/the-scientific-literature-is-poisonous
Comments URL: https://news.ycombinator.com/item?id=49098728
Points: 5
# Comments: 0
Possible arbitrary file read and remote code execution in Active Storage
Article URL: https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm
Comments URL: https://news.ycombinator.com/item?id=49098724
Points: 2
# Comments: 0
Steve Jobs Demoing Core Animation at WWDC 2007
Article URL: https://twitter.com/lucaslovexoxo/status/2082098579632783441
Comments URL: https://news.ycombinator.com/item?id=49098717
Points: 2
# Comments: 0
AI Doomsday Bullshit Is Getting Tired
Article URL: https://karlbode.com/ai-doomsday-bullshit-is-getting-tired/
Comments URL: https://news.ycombinator.com/item?id=49098716
Points: 3
# Comments: 0
I FELL 15,000 FEET AND Lived (2009)
Article URL: https://uss-la-ca135.org/60/1960Judkins-Knott.html
Comments URL: https://news.ycombinator.com/item?id=49098705
Points: 2
# Comments: 0
Americans say large tech companies have too much power
Article URL: https://www.axios.com/2026/07/29/little-tech-big-tech-americans-power
Comments URL: https://news.ycombinator.com/item?id=49098704
Points: 2
# Comments: 0
Show HN: Parse a PDF from your terminal with PaddleOCR-VL-1.6
I built OpenParser because I wanted PaddleOCR-VL-1.6 behind an endpoint I could actually use. Now there are open-sourced CLI and TypeScript/Python SDKs:
``` npm install -g @openparser/cli openparser auth login openparser parse sync document.pdf ```
That is basically it. It doesnt get easier and cheaper that this. Give it a PDF and get back the text and document structure.
Repo: https://github.com/eigenpal/openparser
I would love feedback from anyone willing to try the CLI and tell me what is still annoying.
Comments URL: https://news.ycombinator.com/item?id=49098696
Points: 5
# Comments: 0
AI robocalls: Why caller ID is still lying to you
If you feel like your phone has turned into a scam megaphone, you’re not alone. Robocalls have been a problem for years. Artificial intelligence (AI) is making them slicker, faster, and harder to spot.
A new investigation by Transaction Network Services (TNS) shows that while the big telecom players have stepped up caller ID authentication, many smaller providers are still lagging behind. That leaves plenty of room for criminals to keep making spoofed, AI‑voiced robocalls that seem legitimate right up until they empty your bank account.
Turning back the clock to 2019, lawmakers in the US passed the TRACED Act with a simple goal: make it harder for scammers to lie about who’s calling. The technical was solution STIR/SHAKEN, a pair of catchily-named standards that let phone networks cryptographically sign calls so downstream providers can check whether the caller ID is trustworthy.
On paper, it’s working fairly well for the major carriers. TNS reports that about 85% of voice traffic between Tier 1 networks in 2025 was signed using STIR/SHAKEN, and 93% of those calls received the highest “A” attestation. If the entire ecosystem looked like that, spoofing would become much harder.
Why spoofing still worksThe same report found that most lower‑tier communications service providers—typically smaller or specialist carriers—aren’t even close to that level of protection. On average, they only use the required cryptographic signatures about 20% of the time. That means four out of five calls effectively go through the network “unsigned.”
There are reasons for this. The Federal Communications Commission (FCC) has granted some providers extensions, particularly very small and satellite providers, as long as they implement other robocall mitigation measures. Even so, the result is uneven implementation.
From a scammer’s point of view, this is great. Cybercriminals are already using AI to run increasingly sophisticated and scalable robocall attacks and know that even calls with strong authentication can be spoofed or abused when other parts of the chain are weak.
AI voice cloning can be done with just a few seconds of original audio. Combine that with call spoofing and personal information gathered from data breaches, and scammers can make a call appear to come from your bank while using a calm, familiar voice that knows your name or other personal details.
Robocalls cost almost nothing to send. Internet calling allows scammers to dial thousands of numbers for a few cents, which is why the volume is so high. Industry estimates suggest US consumers received around 55 billion robocalls in 2025, with projections creeping toward 60 billion in 2026. That’s roughly 160 million spam calls every single day in one country. Globally, that’s about 385 billion spam/robocall calls each year.
How to stay safeWhat can you realistically do as a consumer, given that the network itself is still in transition and attackers are upgrading faster than some carriers?
A few habits still go a long way:
- Be skeptical of urgency. Real organizations rarely need you to make immediate decisions over the phone about payments, credentials, or remote access. Hang up and call back via a number you find on their official website.
- Treat caller ID as a clue, not proof. Even if the number looks familiar or matches what you see on a card or website, it can be spoofed.
- Don’t press buttons or follow instructions in automated menus you didn’t expect. Many robocalls use “press 1 to speak to an agent” as the gateway into a full social‑engineering script.
- Use call‑blocking and screening tools. Your phone, carrier, or security app may already offer options to block known spam numbers, send unknown callers to voicemail, or label suspicious calls.
And finally—and this is where we can help—check suspicious numbers with our Scam Number Check before you answer or call back.
Scammers know more about you than you think.
Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in.
OpenAI explains how its AI agent breached Hugging Face
On July 28, OpenAI published an update on the agent that escaped its sandbox and hacked into Hugging Face during an internal cybersecurity evaluation.
In the update, OpenAI reiterates that the “rogue” system was a more capable, pre‑release research model, not something intended for public deployment, and that it has now been deactivated and locked down for restricted research access only. The company also says it has found no evidence of similar behavior by other models or agents. Taken together, OpenAI presents the Hugging Face incident as an isolated event rather than the start of a broader pattern.
From a security standpoint, four things in the update stand out:
- OpenAI clarifies that the evaluation environment did not have direct internet access. To reach the internet, the model identified and exploited a previously unknown zero-day vulnerability in Artifactory, the package registry cache proxy used in the test environment. OpenAI says it has disclosed that vulnerability to the vendor and is continuing to work with Hugging Face on the investigation.
- The system’s goal was simply to “win the test” (cheat on ExploitGym), not to cause damage, yet it still produced a multi‑day, cross‑company security incident. Benign intent did not limit the impact.
- “Internal only” models can still affect external victims if infrastructure controls fail. A lab environment does not magically contain cyber‑capable systems.
- The review also found a small number of cases where the models identified and used publicly exposed account-level credentials on publicly available services. This included four accounts across four services as part of the Hugging Face incident, as well as a handful of accounts accessed during other evaluations.
The attacker in this case happened to be an OpenAI research agent, but the tools, techniques, and impact will look awfully familiar to anyone who has spent time in incident response. Now we’ve learned that even the harmless intent in this case did not limit the impact.
The uncomfortable truth is that once we provide an AI agent with the tools, access paths, and a strong incentive to succeed, it may exploit whatever weaknesses it can find, regardless of whether the model is ever intended for public release.
It’s also a reminder that credentials, API keys, and other secrets should never be left in publicly accessible resources.
From reporting threats to removing them.
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
