Feed aggregator
Move Over Oppenheimer – climate scientists still minimising how bad things are
Article URL: https://jacksondamian.substack.com/p/move-over-oppenheimer
Comments URL: https://news.ycombinator.com/item?id=48894517
Points: 1
# Comments: 0
I Squeezed 31.9 TFLOPS out of an RTX 4060, Beating cuBLAS by 14%
Article URL: https://github.com/houslast3/How-I-Squeezed-31.9-TFLOPS-out-of-an-RTX-4060-Beating-cuBLAS-by-14-
Comments URL: https://news.ycombinator.com/item?id=48894503
Points: 1
# Comments: 0
20problems.com – Daily Math Quiz
Article URL: https://www.20problems.com/
Comments URL: https://news.ycombinator.com/item?id=48894467
Points: 2
# Comments: 0
Silvia – AI CFO built for serious investors
Article URL: https://www.cfosilvia.com/
Comments URL: https://news.ycombinator.com/item?id=48894466
Points: 2
# Comments: 0
Show HN: GraphCompose 2.0 – Java DSL for business PDFs, now split into modules
Article URL: https://github.com/DemchaAV/GraphCompose
Comments URL: https://news.ycombinator.com/item?id=48894461
Points: 1
# Comments: 0
Detection of a four-carbon sugar in interstellar space
Article URL: https://www.nature.com/articles/s41550-026-02905-7
Comments URL: https://news.ycombinator.com/item?id=48894447
Points: 2
# Comments: 0
A/B Test results: Trying different homepage heroes got us 2.6x sign-ups
Last year, we rebranded forms.app, a form builder app. With the rebranding, we had an experimental hero section that we quite liked. It was an AI generator; people write what type of form they like, and even before they sign in, they get it.
I'd have liked to include all images here, but you can check them out here: https://salimdin.substack.com/p/how-an-ab-test-more-than-doubled-our-signups-on-formsapp
After a few months, we realized something was off. We thought it was about rankings, but after a few discussions, we decided to test our homepage hero section against two alternatives.
- Variant A: The AI generator version
- Variant B: Only sign-up buttons (nothing else)
- Variant C: A single button for the app itself (playground without sign-up)
We ran the experiment for 2 weeks and only for new visitors. The results were interesting, to say the least:
- Variant A came last on every single metric
- B got 2.6x the sign-ups of A
- C got fewer sign-ups than B, but those who did sign up activated more; so it's a more distilled result.
Seeing these results, we decided to move forward with Version B, as it has more promise, and agreed that B and C deserve their own testing.
Recently, we changed our pricing, and with it, Version B got an update. Soon, the C version will be updated too, and we'll pit them against each other. I'll be sharing the results when we run that A/B test.
What do you think? Are the results what you expected, or did they surprise you too?
It's not a promotion, just an article where I show the version and the results, but I couldn't submit with the URL (probably due to the Substack URL). So here it is: https://salimdin.substack.com/p/how-an-ab-test-more-than-doubled-our-signups-on-formsapp
Comments URL: https://news.ycombinator.com/item?id=48894437
Points: 1
# Comments: 0
Show HN: Overplane: Containers and formal verification for AI code
Article URL: https://www.overplane.dev/
Comments URL: https://news.ycombinator.com/item?id=48894426
Points: 2
# Comments: 1
Show HN: S4Ready – Deduplicate and fix SAP data before an S/4HANA migration
Article URL: https://s4ready.fenikstech.ai/
Comments URL: https://news.ycombinator.com/item?id=48894419
Points: 1
# Comments: 0
Engineering High-Performance Parsers with Data-Oriented Design
Article URL: https://www.arshad.fyi/writings/engineering-high-performance-parsers
Comments URL: https://news.ycombinator.com/item?id=48894417
Points: 1
# Comments: 0
Trump invested crypto gains in stocks and bonds, filings show
Article URL: https://www.reuters.com/legal/government/trump-invested-crypto-gains-stocks-bonds-filings-show-2026-07-13/
Comments URL: https://news.ycombinator.com/item?id=48894404
Points: 2
# Comments: 1
Show HN: Display Excel files in your web app
Hello Hacker News!
I have just launched SpreadsheetPreview, an embeddable Javascript/Typescript component that displays an Excel file (.xlsx) in any browser.
Benefits: No upload. No server. No Microsoft Office dependency.
You can see it here: https://spreadsheetpreview.com.
The component is based on DataGrid Toolkit, the toolkit that also powers upcoming DataGridXL v4, which is an editable data grid component with an Excel-like interface.
The component is free to use for non-commercial projects. Commercial use requires a license.
Please try it out and let me know what you think!
Best,
Robbert
Comments URL: https://news.ycombinator.com/item?id=48894390
Points: 1
# Comments: 1
GPT 5.6 sets new record on proofreading benchmark
Article URL: https://twitter.com/tmuxvim/status/2076692926059499646
Comments URL: https://news.ycombinator.com/item?id=48894384
Points: 1
# Comments: 0
Elon Musk and Sam Altman spar on X after Apple files OpenAI lawsuit
Article URL: https://www.cnbc.com/2026/07/12/elon-musk-and-sam-altman-spar-.html
Comments URL: https://news.ycombinator.com/item?id=48894359
Points: 1
# Comments: 0
BTS and McDonald's Collaborate for a Third Time With New Collectible Toys
Lessons Learned from CISA’s Recent GitHub Leak
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a recent data leak in which a contractor published dozens of internal CISA credentials — including AWS Govcloud keys — in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps identified in the agency’s initial response provide important lessons that all security teams should absorb.
On May 15, 2026, the security firm GitGuardian asked for help in notifying CISA about the existence of a public GitHub repository called “Private CISA” that included 844 MB of sensitive CISA-related data. One of the exposed files, titled “importantAWStokens,” included the administrative credentials to three Amazon AWS GovCloud servers. Another file — “AWS-Workspace-Firefox-Passwords.csv” — listed plaintext usernames and passwords for dozens of internal CISA systems.
CISA quickly acknowledged our initial alert, but took more than 48 hours to invalidate the AWS keys and many other important secrets leaked in the GitHub repo. In its report on the data leak, CISA said the complexities of the agency’s systems and interconnections with federal and industry partners caused its key rotation to take longer than anticipated.
“Drawing on this experience, CISA encourages others to maintain mature and well-tested key management capabilities,” the report notes.
CISA also admitted it can do better when it comes to responding to security incident notifications from external parties. The postmortem stresses that clear and distinct reporting channels are essential to ensure that incidents affecting the organization itself are handled differently from those involving its products or customers.
“In CISA’s case, these channels were not well defined, leading the security researcher to try multiple avenues – including emailing the contractor, submitting through CISA’s vulnerability disclosure platform (which is intended for vulnerabilities impacting the broader cybersecurity community), and ultimately involving a reporter,” reads the analysis written by Preston Werntz and Brad Libbey, the acting chief information officer and acting chief information security officer at CISA, respectively.
CISA said it is refining its reporting channels to make them easier and faster for researchers. “Additionally, while many researchers rely on the security.txt file, organizations can ensure clarity by publishing reporting instructions in multiple prominent locations,” the CISA authors wrote.
Guillaume Valadon, the GitGuardian researcher who first contacted KrebsOnSecurity about the exposed CISA credentials, said CISA ignored nine automated alerts about the exposed credentials prior to our notification on May 15. Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures.
“Letting nine notification emails go unanswered is how a one-day incident becomes a six-month exposure,” Valadon wrote in an analysis of CISA’s report. “Make it trivial to report a leak about you, not just about your products. The person reporting a leak to you is not the threat. Publish a security.txt, but do not stop there. Put reporting instructions in several prominent places, and make sure a report about your own infrastructure does not land in a product-bug queue.”
The report’s authors also emphasized the importance of continuously scanning public code repositories like GitHub for exposed secrets, and said CISA has since rotated all secrets and created an action plan to improve management of developer secrets and to better monitor for them going forward.
The report notes that while CISA had developed a playbook for responding to cybersecurity incidents, that playbook somehow didn’t include what to do in situations involving GitHub or other cloud services. Valadon said the report validates the need to scan continuously — not just quarterly — for exposed secrets.
“The Private-CISA repository sat public for six months,” Valadon wrote. “Continuous monitoring of public GitHub surfaced it. Comprehensive internal scanning could have caught the plaintext passwords and committed backups long before they left the building.”
CISA gave itself passing grades on several areas of security preparedness that it said helped the agency gauge the scope and impact of the exposed secrets, including enhanced logging capabilities, and the adoption of zero-trust principles in both its production and development systems. CISA said those detailed logs allowed it to show that no customer or mission data was exposed, and that the leaked credentials were not used outside of CISA’s environments. The agency said the contractor who exposed the secrets had their system access revoked.
Valadon reckons the biggest takeaway is the CISA postmortem itself, and praised the agency for being transparent about what worked and what didn’t.
“To my knowledge, it is also the first time a national cybersecurity agency has publicly advocated for secrets scanning and for simplifying relations with security researchers,” Valadon wrote. “That is exactly the incident communication we should expect from every organization.”
Best Laptop for College Students: Top Laptops for School in 2026
These 5 Photoshop AI Tools Are Great for Beginner-Level Photo Editing
Auth and Curl
Article URL: https://taonaw.com/2026/07/10/auth-and-curl.html
Comments URL: https://news.ycombinator.com/item?id=48893620
Points: 1
# Comments: 0
Joys of cancelling a TBB task group
Article URL: https://aras-p.info/blog/2026/06/28/Joys-of-cancelling-a-TBB-task-group/
Comments URL: https://news.ycombinator.com/item?id=48893613
Points: 1
# Comments: 0
