Feed aggregator
Kioxia's nearly faster than Optane SSD
Article URL: https://www.blocksandfiles.com/flash/2026/08/03/kioxias-nearly-faster-than-optane-ssd/5282259
Comments URL: https://news.ycombinator.com/item?id=49181295
Points: 1
# Comments: 0
SQS consumer can hang forever by default
Article URL: https://encore.dev/blog/message-queue-hangs
Comments URL: https://news.ycombinator.com/item?id=49181294
Points: 2
# Comments: 0
Drug Discovery Has No Magic Wands by Daphne Koller
Article URL: https://www.a16z.news/p/drug-discovery-has-no-magic-wands
Comments URL: https://news.ycombinator.com/item?id=49181282
Points: 1
# Comments: 0
Sober: Local-first code reviewer for agentic PR (deterministic and model review)
Article URL: https://sober-dev.app/
Comments URL: https://news.ycombinator.com/item?id=49181275
Points: 1
# Comments: 0
People are ghosting long-term partners. Some don't regret it
Article URL: https://www.wired.com/story/people-are-ghosting-long-term-partners-some-dont-regret-it/
Comments URL: https://news.ycombinator.com/item?id=49181264
Points: 2
# Comments: 0
Show HN: Free EN 16931 e-invoice validator that runs in the browser
Article URL: https://einvoicekit.com/
Comments URL: https://news.ycombinator.com/item?id=49181263
Points: 1
# Comments: 0
Belgie – TypeScript Sandboxes and React MCP Apps for Python
Article URL: https://mplemay.github.io/belgie/
Comments URL: https://news.ycombinator.com/item?id=49181252
Points: 3
# Comments: 0
Jeremy (Snail)
Article URL: https://en.wikipedia.org/wiki/Jeremy_(snail)
Comments URL: https://news.ycombinator.com/item?id=49181250
Points: 1
# Comments: 0
Gentle Response to Dontasktoask
Article URL: https://www.dontbeasillygoose.fyi/
Comments URL: https://news.ycombinator.com/item?id=49181246
Points: 1
# Comments: 0
Why the Best Software Engineers Focus on System Design
Article URL: https://www.youtube.com/watch?v=LeUUxLRdvho
Comments URL: https://news.ycombinator.com/item?id=49181243
Points: 2
# Comments: 0
Show HN: Code Factory – Create a reviewable MVP in minutes, with receipts
Article URL: https://github.com/zrk222/code-factory
Comments URL: https://news.ycombinator.com/item?id=49181232
Points: 1
# Comments: 0
Simulation Apps Pinpoint Cause of Electronics Failures
Article URL: https://spectrum.ieee.org/electronics-corrosion-multiphysics-simulation
Comments URL: https://news.ycombinator.com/item?id=49181227
Points: 1
# Comments: 0
Show HN: Nodes – A native macOS Markdown editor that runs its AI on device
Article URL: https://nodes-web.com/
Comments URL: https://news.ycombinator.com/item?id=49181226
Points: 1
# Comments: 1
Beyond Scarcity: How Abundance Shaped Economic Thought from Smith to Romer [pdf]
Article URL: https://www.paecon.net/PAEReview/issue114/Beaudreau114.pdf
Comments URL: https://news.ycombinator.com/item?id=49181218
Points: 1
# Comments: 0
Google’s synchronized passkeys can be stolen in ‘Pass‑ta‑key’ attacks
Passkeys were supposed to make stolen passwords a thing of the past. No password to phish, no secret to reuse, and no string of characters sitting in a database waiting to be leaked.
Over time, it’s thought that passkeys will replace passwords entirely. But what happens when malware steals the master key?
Researchers have found a way for malware to hijack passkey-protected accounts through Google Password Manager, highlighting an important exception: passkeys can be very secure but the software surrounding them still has weaknesses.
What are passkeys?Passkeys are a password replacement based on public‑key cryptography. Instead of a secret you remember and type, each account gets a key pair where the private key never leaves your devices, and the website only ever sees the public key and signed challenges. Because there’s nothing reusable to phish or reuse on another site, passkeys are marketed as “phishing‑resistant” and safer than passwords stored in a browser or password manager.
By the end of 2024 Google reportedly said that 800 million Google accounts used passkeys.
Passkeys have a major advantage over passwords: there is nothing useful for a phishing site to steal. A passkey is also tied to the website it was created for, making it much harder to trick into authenticating to the wrong domain.
The other significant difference is that if malware steals a password vault, an attacker still often needs to get past a second factor on another device, such as an authenticator app on your phone, before they fully own the account. With passkeys, many services relying on them simply trust the passkey assertion, and in some cases even trust a single “user verified” flag without confirming whether a real biometric or PIN event occurred.
Malware comes into playThe researchers, however, started with a malware infected Windows computer and came up with three possible attack scenarios to steal Google synchronized passkeys. Google Password Manager can synchronize passkeys between devices, which is convenient since you don’t want to register a new passkey every time you buy a new computer. But it also opens them up to abuse.
From bad to worse the attacks are:
- Pass‑ta‑key: malware on the victim’s computer silently asks Chrome and Google’s cloud to create a valid passkey login, no biometric or PIN prompt needed.
- Silver Pass‑ta‑key: malware abuses device re‑enrollment to register its own user‑verification key, then logs in as the victim from the attacker’s machine without touching the victim’s device.
- Golden Pass‑ta‑key: Malware extracts Google’s security domain secret (the master encryption key), decrypts all synced passkeys, and can reuse them anywhere, even after losing access to the original device.
The researchers urge services to stop blindly trusting the user verification flag and to properly validate that a real User Verified event occurred before granting access. Google, in turn, is encouraged to harden device registration and recovery, and verify that new devices and keys are backed by genuine hardware rather than accepting them at face value.
For end users, passkeys still offer strong protection against classic phishing websites and credential stuffing attacks based on reused passwords. The weak point highlighted here is not so much the concept of passkeys, but the way they’re implemented, synchronized, and trusted without enough verification on the server side.
Until vendors close these gaps, basic anti‑malware hygiene remains critical. The best ways to prevent malware from using your passkeys are:
- Keep on top of updates: make sure your systems and software are patched as soon as you can.
- Use up-to-date real-time anti-malware protection.
- Treat unexpected attachments or links as suspicious until proven innocent.
From reporting threats to removing them.
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data
The guidelines are the work of the recently launched Open Secure AI Alliance, which now includes 120 organizations.
The post Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data appeared first on SecurityWeek.
AI Security Institute Reports Anthropic and OpenAI Models Going Rogue Against Organizations
In one instance, an unsanctioned model attempted to inject malicious code into an open source repository.
The post AI Security Institute Reports Anthropic and OpenAI Models Going Rogue Against Organizations appeared first on SecurityWeek.
Let's call Trump's approach to Iran what it is: kindergarten diplomacy
Article URL: https://www.theguardian.com/commentisfree/2026/aug/05/trump-iran-war-diplomacy
Comments URL: https://news.ycombinator.com/item?id=49180850
Points: 2
# Comments: 0
Most security keys ship without a PIN, and websites rarely ask
Article URL: https://www.notebookcheck.net/Most-security-keys-ship-without-a-PIN-and-websites-rarely-ask.1359677.0.html
Comments URL: https://news.ycombinator.com/item?id=49180845
Points: 1
# Comments: 0
Show HN: A multiplayer play-money terminal casino for downtime
Hi HN!
I created Anteroom, a hobby project allowing you to play casino (and non-casino) games with your friends in your terminal. The project is complete with hooks for Claude & Codex which allow in-app alerts as well as a global leaderboard.
Happy to take the past two weeks to craft this and there is definitely room to add more games in the future.
Cheers!
Comments URL: https://news.ycombinator.com/item?id=49180819
Points: 1
# Comments: 0
