Yesterday’s roundup counted 133 stories above 200 points in the top 500 ranks and called it the highest new-story count of the week. Today the same scan returns 101. Forty-seven sit inside rank 160 and 54 are sitting in positions 161 to 491, accumulating points where no front page will ever show them. Seventeen are new.

The headline number of the week is no longer on the list at all. When did Google get so weird? is at 2,013 points and does not appear in the top 500 ranks. It was at number one five days ago, and at rank 199 position with 2,010 points yesterday. Points never decrease. Rank does.

All scores were captured at 13:20 PDT from the HN Firebase API across the full 500-item rank list, with a 40-hour Algolia date sweep for window misses and the Algolia API used to verify scores for stories that have fallen out of the rank list.

Turn off Apple Intelligence on macOS 27 and get its disk space back — 738 points

738 points · 506 comments · github.com/omlahore/RemoveMacAI · HN discussion

macOS 27 removed the single switch that turned Apple Intelligence off, and the models it downloads stay on disk after the features are disabled. RemoveMacAI is a Swift command-line tool, 1.8k stars and 34 forks, that turns the features off, deletes the models, and stops macOS from downloading them again. It is reversible.

What it actually does is the interesting part, because none of it is a supported Apple workflow. The tool installs a configuration profile that applies Apple’s restriction keys for Apple Intelligence and forces the settings that have no restriction key. It removes models through Apple’s asset service rather than touching anything in /System, so System Integrity Protection stays on. Then the profile redirects each removed model’s download URL to a closed local port, which is how it survives a re-download. Restoring the profile puts everything back.

The list of things being turned off is long and reads like an inventory of features nobody asked for: Siri including “Hey Siri” and the menu bar icon, Writing Tools, Genmoji, Image Playground, the ChatGPT extension, summaries in Mail, Messages, Safari, Notes and notifications, Mail smart replies, inline text predictions, Spatial Photos, Photos Clean Up, Xcode’s predictive code completion.

Two things are worth separating. One commenter notes the tool is a wrapper around an existing project, 4evy/pared — a fair correction and not a criticism; the packaging and the re-download block are the work. The other is the strongest counterargument in the thread, that the bundled models are small, local, off-cloud and fine for basic tasks, so removing them is a strange thing to want. That argument is correct in the abstract and wrong in practice for the reason another commenter gives: Apple’s SSD pricing makes 12GB a real number on the machines most people buy.

The part that should bother you is not the disk space. It is that turning off a vendor feature now requires a third-party configuration profile and a fake dead port, because the vendor does not offer a switch. That is the same pattern as the Windows de-crufting tools people have run for a decade, arriving on macOS. One commenter’s summary is the one to keep: a clean install now needs third-party scripts to get control of the machine back.

Improper redaction reveals Google Data Center water and electricity usage — 504 points

504 points · 666 comments · 1011now.com · HN discussion

Nebraska requires data centers to file annual water and electricity reports with the Department of Water, Energy and Environment, but state statute lets them claim the numbers as confidential trade secrets. Google did exactly that for all three of its Nebraska sites — Lincoln (Agate LLC), Omaha (Westwood Solutions) and Papillion (Fireball Group) — citing Neb. Rev. Stat. §§ 81-1527 and 84-712.05 plus NAC Title 115, Chapter 2.

A 10/11 reporter then selected the redacted black box in the PDF with a text cursor, copied it, and pasted it into a document. The text was still there. Agate LLC reports 52.65 megawatts at peak electrical demand and 13.299 million gallons of water across cooling towers, evaporative systems and site operations over the last year. Further copy-paste shows Fireball LLC — the Papillion site — at 547.88 million gallons for 2025, and the six reporting data centers at 765 million gallons in total.

The thread did the arithmetic the article gestured at, and it cuts against the panic framing. 13.3 million gallons is about 40.8 acre-feet. The average Nebraska farm is 989 acres and uses roughly 1,200 acre-feet a year — around 390 million gallons. One average Nebraska farm uses about thirty times the water the Lincoln data center does, and there are 44,479 of them covering more than 90% of the state’s land. A commenter who lived near a data center adds the obvious institutional caveat: the permitted maximum in a filing is not the same as observed usage, and articles routinely conflate the two.

That does not make the story small, it makes it two stories. The revealed number is genuinely unimpressive next to Nebraska agriculture, which undercuts the “AI is drinking the aquifer” line. The redaction is a real abuse of a trade-secret exemption that was never written to cover a utility bill’s bottom line, and the internal tax accounting that spilled out alongside it — Agate expecting a $55.8M federal refund from 2025, Fireball $39.2M, Westwood $22.6M — is the part Google would least like read out loud. Both things can be true, and the commenter who argues that fighting resource use story-by-story is a mistake — that the fight should be about whether you want the data center, not about how many gallons — is making the smartest version of the skeptical case.

Denmark Data Breach Exposes 8.8M People’s Personal Data — 428 points

428 points · 305 comments · cpr.dk · HN discussion

Nobody broke into the Central Person Register. According to CPR’s own notice, unauthorised parties misused a Danish company’s lawful access to search the register and walked away with names, addresses, CPR numbers and more for roughly 8.8 million registered people. The company’s access has been revoked, the incident has been reported to the data protection authority, and the police are investigating together with the relevant ministries.

Denmark’s population is about 6.03 million. The register therefore covers essentially every living resident plus historical records and foreign nationals who once had residence. People registered with name and address protection are excluded from the exposed set, which is the one piece of good news. A commenter points out that DTU — the Technical University of Denmark — disclosed a breach days earlier that included student and staff CPR numbers, which means anyone who got both tables has a join key.

The thread converges on a structural argument that is more useful than the breach itself. The CPR number functions as both username and password because institutions still verify identity by asking you to recite ten digits over the phone, despite a national 2FA system (MitID) existing. If that is how the number is used, it was never a secret, and treating it as one created a liability that just paid out. The counter-view is also in the thread: Sweden publishes much of this data by default through sites like hitta.se, and makes the case that transparency beats fragile secrecy. The unhelpful thing about both positions is that neither addresses the actual failure, which was an access control on a private company’s query privileges, not the publicness of the identifier.

What gives the thread its weight is the insider comment from someone who spent a decade in the Danish public sector: IT and digitalisation are not treated seriously, there was no dedicated ministry until recently and it is now shared, and what security investment has appeared was driven by the Russian hybrid threat rather than by a theory of risk. Poland’s ~20M-record medical breach and France’s 678k-record tax breach are cited as the same pattern with different flags.

What is going on with ceiling fans — 399 points

399 points · 360 comments · mcmansionhell.com · HN discussion

Kate Wagner, back from a hiatus she attributes to finally dealing with her mental health, noticed that ceiling fans have stopped being a category. The taxonomy in the post is worth reading in full because the photographs do the arguing: the “fandelier” (a chandelier with a fan in it), the “chandefan” (a fan with a chandelier bolted to it), the flush-mount that is a landlord-special downlight with a one-foot fan hiding inside it, the “border” fan (a normal fan with a decorative frame for no stated reason), and the best entry, a decorative fixed blade assembly mounted above a much smaller fan that actually moves.

The causal argument is the serious part. Two changes did this. Direct-to-consumer marketplaces like Wayfair and Amazon removed the storefront and, with it, the marketing person whose job was to say “that is an ugly fan” — leaving cheap overseas production plus existing logistics networks pointed straight at your ceiling. Integrated LEDs then removed the constraint that a fixture must solve the light-bulb problem, which freed designers to diffuse light through “tubes, shafts and curlicues.” The economics are the tell: many of these cost under $200, and the LED is not replaceable, so the entire fixture becomes landfill when it fails.

Wagner checked whether the fans were AI-generated, because the product photography clearly is. They are not — three people confirmed purchases in the reviews. That is a sharper observation than it looks: the marketing layer is synthetic and the physical object is real, which is the inverse of what most people assume about AI slop.

The thread’s best contribution is a first-person horror story about DIP switches. A commenter’s house had fans that turned themselves on. The old owner had bought a replacement controller. It was not the controller: every house on the street was built by the same company, and every fan and remote shipped with the same four-switch DIP configuration, so neighbours were controlling each other’s fans. Somebody else provides the line that should have been the post’s subtitle — taking two durable, repairable objects and fusing them into one visually complicated object with a non-replaceable LED. The Magic: the Gathering analogy for category drift (thirty years of Islands that are not islands) is the right frame. The design criticism is taste; the disposal economics are the actual complaint and nobody regulates it.

Web Search API — 391 points

391 points · 188 comments · developers.cloudflare.com · HN discussion

Cloudflare shipped a Web Search API in beta: your agent or app sends a query, you get grounded results back, and it runs through AI Gateway so requests show up in your existing logs and are billed to your AI Gateway credits. Three providers at launch — Ceramic.ai, Exa and Linkup — billed at list price with no markup, and you can bring your own key.

The announcement says all three support Zero Data Retention for requests made through Cloudflare. A commenter then opens the providers page and finds the contradicting row: Exa, Zero Data Retention — No. That is a documentation bug in a security-adjacent claim, and it is the single most useful thing in the thread.

The economics are the second useful thing. Thread figures put Ceramic at $0.25 per 1,000 requests, Linkup at $5.00 and Exa at $7.00, against Serper.dev at $1.00 and — the value outlier — Gemini 2.5 Flash Lite, which still hands out 1,000 free Google searches per day. That last one comes with a catch the commenter notes: Google has restricted access to 2.5 to users who already had it, and 3.x is 5,000 searches per month plus per-search pricing.

The constraint that actually matters is licensing, not price, and one commenter digs it out of Ceramic’s terms. Prohibited uses include collecting, aggregating, storing or compiling output — including search results, relevance scores and rankings — for the purpose of creating or contributing to any database, dataset, index or corpus. For an agent that wants to cache a result, build a local index, or offer a “share transcript” button, that clause is the product decision. Nobody in the thread has resolved how it squares with the general agent architecture everyone is building.

The rest of the thread is the by-now-standard Cloudflare observation: they build the bot detection, sell the crawler, and take a position in the middle of every request. Reselling someone else’s index through your own gateway and billing is a real business — consolidated logging, consolidated billing, one dependency — but it is not a search engine, and the commenter asking why you would not just call the providers directly has not been answered.

A browser-native classic Visual Basic VB6 IDE — 379 points

379 points · 126 comments · wieslawsoltes.github.io/VB6 · HN discussion

Someone rebuilt the VB6 design environment in a browser tab: toolbox, project explorer, drag-and-drop form layout, the properties grid with its alphabetic/categorized tabs, the whole visual-programming surface from 1998. It can compile an app out to an HTML file. There is an “MCP agent access” affordance in the corner, which is the detail that tells you what decade you are in.

The thread is not really about VB6. It is about what was lost. The top comment is a lament that no modern toolchain comes close to VB6 on discoverability: a palette of widgets, a rich property editor, one-click codegen for any event, no documentation needed because everything you can do to an object is visible in front of you. The property grid gets nominated as the greatest general-purpose UI ever shipped — define your classes with attributes and it just works — and the claim that it was downhill from there.

The interesting forward-looking argument is that coding agents make the real problem solvable again. The pain in VB6 was always in the boundary between the visual abstraction and real code; the response when the abstraction broke was to drop into a language that was never good. If code generation is fast enough and most code becomes an implementation detail, a RAD environment that hands you VB6-era ergonomics and real code underneath when you ask for it stops being nostalgia and becomes a design proposal. That is a genuine argument, not a joke.

The honest criticism is visual: it is noisy, the bevels are wrong, and one commenter notes the border-color trick produces 45-degree corners in the uncanny valley, with a pointer to 98.css and the inset box-shadow staircase hack. The author’s other work also comes up — SharpForge, a C# browser IDE, inside more than 500 public repositories — which is itself a datapoint about what one person with modern tooling can now ship.

Pixel 11 doesn’t yet meet the GrapheneOS security standards and may be skipped — 363 points

363 points · 201 comments · discuss.grapheneos.org · HN discussion

GrapheneOS got a partial port of the Pixel 11 running in a week and cannot finish it, because ARM hardware memory tagging — MTE — is not supported in the Pixel 11’s software, firmware, or “near certainly” hardware. Their conclusion is blunt: Google cut an important security feature to save money.

The context for why that matters: GrapheneOS uses MTE across the entire base OS including the kernel and every standard process, temporarily disabled only for a few device-specific ones, and it is the mitigation that defeats most remote exploits and many local ones. The Pixel 8 shipped hardware MTE in October 2023 and GrapheneOS integrated it into hardened_malloc that month. Stock Android and Pixel OS never enabled it by default, and Android 16’s Advanced Protection Mode turns it on for a handful of processes. Apple’s Memory Integrity Enforcement on the iPhone 17 is the same idea done properly: always on, MTE used in its most secure mode in the kernel and a large part of userspace. GrapheneOS also enables it for more apps than either platform’s default and exposes a per-app toggle. The Pixel 11 does have real gains — post-quantum verified boot with ML-DSA, AOSP IMS replacing Samsung’s Shannon, Titan M3 for pre-first-unlock data extraction — which is what makes the omission grating rather than merely disappointing.

Take the corrections in the thread seriously, because they matter. This is not the most recent status: GrapheneOS softened part of the August statement in September, and the Android 17 QPR2 beta added preliminary firmware-level MTE support after the initial posts, so the position is “we won’t support it unless it ships MTE” rather than a verdict. A commenter also pushes back correctly on the causal claim — speculating about another organisation’s internal justification is bad comms practice even when your engineering read is sound. The bigger Pixel story this week was separate: Google restricting non-Samsung OEMs from shipping GrapheneOS preinstalled without a quota, which is about distribution rather than silicon.

The buying advice in the thread is consistent and unglamorous: skip this generation, keep a Pixel 8, or buy a used Pixel 10. The thread’s naming of the cause is worth keeping too — a phone launched into a memory-price spike with an incremental CPU, the same GPU and less RAM on the Pro base models, and a missing memory-safety feature, at a higher price.

Anthropic reported diary entry to police, woman faces felony charge — 315 points

315 points · 243 comments · techspot.com · HN discussion

Carli Michelle Heller of Bonita Springs, Florida wrote on September 26 that she would attack the Lee County Sheriff’s Office. She was using Claude as a diary. Claude’s safety systems flagged the entry, escalated it to a human reviewer, that reviewer judged it a credible threat, and Anthropic reported it to law enforcement. Deputies identified her, detained her without incident, and she is charged with making a written threat of violence under Florida Statute 836.10, a second-degree felony.

Anthropic’s position is that it may share user information in limited emergencies when disclosure is necessary to prevent death or serious physical injury. That is a reasonable policy with an unstated cost, and the cost is the thread’s subject.

The legal objection is the sharp one. 836.10 requires that the communication be transmitted “in a manner in which another person may view it.” A private entry in what the user believed was a journal, read only because the provider scanned it, is a strained fit for that element — as one commenter puts it, the threat was never delivered to anyone, it was obtained by inspection. Whether a court accepts that argument is unresolved and this is the case that will test it.

The comparative context is that the labs now face liability from both directions. British Columbia is suing OpenAI and Sam Altman over a mass shooting the province says ChatGPT could have helped prevent, so a provider that sees a credible threat and stays quiet is exposed, and a provider that reports is exposed differently. Reporting is the least-bad posture for the company and the worst outcome for the person, which is roughly how liability-driven surveillance always works.

Do not over-read it as a company choosing to spy. The incentive is legal, and the policy is narrow. The honest criticism is about process and notice: an anonymous human reviewer makes a credibility call with no warrant and no hearing, and millions of people are using these systems as confidants without being told in any memorable way that a human may read the transcript. A commenter who tests their own employer’s flagging systems by describing terrible things he has no intention of doing lands on the same anxiety from the other side: the model cannot tell intent from content, and neither, reliably, can the reviewer.

We ported the original Doom to SQL — 289 points

289 points · 44 comments · cedardb.com · HN discussion

Last year’s version, DOOMQL, was a raycasting ASCII renderer that people correctly pointed out was closer to Wolfenstein 3D than Doom. This year the author came back with BSP-tree rendering, textured walls at arbitrary angles, varying floor heights, and — the actual claim — both the renderer and the game loop implemented in SQL. The whole thing is about 5,900 lines of SQL. Python handles timing, reads the keyboard, and blits the bitmap it gets back. The game loop runs at Doom’s original 35 FPS and the complete 320×200 framebuffer renders at up to 60 Hz on a Ryzen 7 7840U. Multiplayer works, and there is a playable four-slot deathmatch demo on CedarDB’s cloud.

The rules the author set for himself are the point: the rendering must emit only a table or a bitmap of exact RGB values, and the game loop must be SQL too. There is a side-by-side screenshot of the 1993 binary and the SQL query and you are invited to tell them apart.

The thread is half admiration and half a genuine argument about where business logic belongs. The most useful comment is from an engineer who worked in semiconductor manufacturing: production fabs run on stored procedures and SQL, very little operational decision logic lives in application code, and the reason is that expressing domain rules in SQL lets many more people read and change the system at once. That is the same case the author is making, without the joke. The counterweight comes from someone who built a casino the same way in 2010: every remote call updated SQL tables as the source of truth, the deadlocks were horrific, scaling was a nightmare, but atomicity came free. Both of those are true, which is why the “abusing query planning as a state machine” line is funny and not dismissive.

Be clear about what this is: there is a “CedarDB Cloud coming soon — join the waitlist” banner on the page, and running Doom is how you advertise a query planner and JIT. That makes it marketing. It is also a real measurement of a real system, which is more than most vendor benchmarks can say.

Nearly 200 people under observation after Irkutsk lab worker dies from plague — 287 points

287 points · 292 comments · themoscowtimes.com · HN discussion

A woman in her late twenties, an employee of the Irkutsk anti-plague institute, fell ill with severe pneumonia in Shelekhov, was put on a ventilator and died on Thursday. Alexei Tsydenov, head of the neighbouring republic of Buryatia, confirmed the cause was an unspecified form of plague. Officials had initially called it only a “particularly dangerous infection.” Nearly 200 contacts were placed under medical observation, more than 100 of them in hospital wards, and the Shelekhov hospital was quarantined pending assessment.

The detail everyone is quoting — that she told staff she broke a test tube of live bacteria while collecting samples — comes from Telegram channels and REN TV, and it is exactly the kind of detail that gets invented in regional Russian reporting. The rival account, which the thread surfaces, is that she was infected on a research trip to Buryatia near the Mongolian border rather than in the lab, and Tsydenov specifically said her infection was unrelated to his republic. CNN, by October 4, was still describing it as an “unknown” infection. Treat the broken test tube as unconfirmed.

What is not in dispute is the institutional fact: a fatality at a designated anti-plague institute, an outbreak investigation, and roughly two hundred people in isolation. Several commenters ask the obvious medical question and get no answer — plague is a bacterium, it responds well to doxycycline, ciprofloxacin or streptomycin, and it has not developed meaningful antibiotic resistance because it has been rare since antibiotics existed, so why was there no prophylactic course after a known exposure? One commenter’s answer to the meta-question is the honest one: we probably do not know how often this happens, because most incidents never become news.

The most measured observation in the thread is that the serious response is itself the signal. The regional governor has a background in emergency management, and a region doing contact tracing and quarantining rather than covering up is what made this alarming enough to read about. The other recurring note is that the entire genre — lab accidents with aerosolised pathogens — is one where the public never gets a base rate, which is why every instance reads as the first one.

Powerless F1 drivers frustrated by Bahrain F1 software glitch — 278 points

278 points · 236 comments · motorsport.com · HN discussion

The Bahrain Grand Prix ran at Sepang in Malaysia, in the rain, and it was the first wet race for the 2026 generation of cars. During the two planned formation laps, a bug in the power unit controller’s wet-weather mode — triggered at very low speed — dropped a large number of cars into idle mode. Multiple cars were stuck. The FIA had to write a software patch on the spot, distribute it to all eleven teams, and have them install it during the resulting red-flag stoppage. The race start was delayed 50 minutes.

The driver quotes are the distillation. Lando Norris: “It’s just horrible. I don’t know, it just proves that we shouldn’t have any of that stuff, the electronic side.” Oscar Piastri, dryly: “I’ve never seen an F1 race delayed by a bug.” Sergio Perez: “It felt like you were in a rental kart and you ran out of time… what happened today is totally unacceptable for the sport.” Piastri’s second sentence is the right one — “it would be unfair to point the finger before there’s an explanation” — and the explanation, per a commenter claiming to be an ex-F1 technician, is a single supplier that has provided ECUs for the field for decades, and a fix that was turning off a buggy configuration setting rather than replacing firmware.

Norris’s conclusion — that this proves F1 should move away from hybrids — does not follow, and the thread catches it. A combustion car has a timing computer, and “technology is fine until you hit a bug” is a statement about software, not about power units. The correct reading is the one anybody in a safety-critical field will recognise: the failure was not exotic, it was a configuration state machine on a spec component, discovered at the worst possible moment, with the fix shipped in the paddock inside an hour. That an F1 team can patch an ECU between laps is either the best or the worst thing about the sport, and the thread cannot decide which.

The Tao of Backup — 250 points

250 points · 103 comments · taobackup.com · HN discussion

Ross Williams published this in 1997 and it is four short parables, structurally identical: the novice asks a question, the master answers in metaphor, the novice ignores the part he does not want to hear, something catastrophic happens. Back up every file, because even the smallest file can take days to recreate. Back up as you work, not on a schedule you keep postponing. Scatter your backups, because the building can burn down with your tapes in it. And the punchline of the security chapter, where the master pockets a 20-gigabyte corporate backup tape on his way out the door, is still the best summary of endpoint security ever written.

It is on the front page in 2026 because Hacker News keeps having this argument. The current version involves agent-managed state, object storage and replication, and the recurring discovery that a “backup” living in the same cloud account you are trying to recover from is not a backup. The lessons have not moved in twenty-nine years.

The thread adds two things the original does not have. One is NixOS as a category error in your favour: if a single text file describes the whole system, backup collapses into version control and restore becomes deterministic in minutes. The other is the parable the thread writes itself, that the first law of backup is that you only learn to make backups after a catastrophic loss, so the master sparing the novice from disaster is the least useful kindness in the text.

The gap worth naming: the Tao says nothing about restore testing, which is the failure mode that actually bites now, and nothing about the modern version of “separation,” where your primary, your backup and your identity provider are all one billing relationship. A 20 GB tape dates the essay. The rest of it does not.

Also on the page

Germany’s RobCo hits $1B valuation — 323 points · 306 comments · techfundingnews.com — Munich industrial-automation company passes a $1B valuation through new investment combined with a ~$40M employee secondary share sale, roughly doubling the ~$500M mark from January 2026, which followed a $100M Series C. Sequoia, Lightspeed, Greenfield, Kindred, Lingotto and Promus participated alongside Cherry Ventures and European Tech Collective; CEO Roman Hoelzl has moved to the US; BMW is a customer; the model is robotics-as-a-service. Read the mechanics before the headline: a secondary-heavy transaction is a liquidity event for employees and existing holders, not fresh capital into the company, so “unicorn” here means a negotiated price on a small trade rather than a validated business. The comment worth keeping is that in RaaS the upfront cost moves to the vendor while downtime stays the factory’s problem, so the service contract and the recovery time matter more than the valuation — and that nobody in the thread has seen either.

In the wake of Tippett Studios’ closure, a digital archive appears online — 231 points · 30 comments · filmstories.co.uk — after the visual effects house’s Chapter 11 and the auction that followed, roughly 90GB of animated material from the CD-ROM era surfaced on the Internet Archive because someone at the auction noticed a binder of discs and did something about it. A commenter who worked at Rising Sun Pictures recalls the studio getting Charlotte’s Web only because Templeton had gone to Tippett, and describes the dailies as jaw-dropping. The two requests in the thread are both correct: put Phil Tippett’s name in the headline, and mirror the torrents before a rights holder notices that an auction bypassed the usual channels.

Show HN: Glashütte Trash Clock — 227 points · 39 comments · niklasroy.com — Niklas Roy, during a residency at the watchmaker NOMOS, built a working clockwork out of trash he found in Glashütte, Saxony: it runs about half an hour per wind, shows seconds and minutes, and strikes a gong when the minute hand reaches twelve. His great-great-grandfather and great-grandfather were Swiss watchmakers who emigrated to Herrnhut, which is the reason the project exists. He also defines a new time scale, Glashütte Trash Time. The thread’s correction is legitimate — pendulum period depends on the distance from fulcrum to centre of mass, not on rod length alone, which is why grandfather clocks have a bob-adjustment screw — and the request to submit it as a talk is the right call.

FTL: A new operating system for clouds — 207 points · 79 comments · ftl-os.org — each container runs an operating system as a userspace shared library implementing Linux processes, VFS and TCP/IP, over a minimal kernel that presents a hypervisor-like interface, so containers get VM-like isolation without emulating hardware. It runs Linux binaries: the Rust HTTP server serving the site is one. v0.1.0 just added async Rust with a multi-threaded Tokio runtime and filled gaps in the Linux compatibility layer. The author works at Vercel. The deciding test is the one a commenter names — does it reduce attack surface and operational cost on real workloads — and the structural objection is the one to watch: a closed-source OS vendor will never ship its core as a linkable library, so this is a Linux-shaped idea.

Mold Linker Version 3.0.0 — 204 points · 118 comments · github.com/rui314/mold — the first release of the Rust rewrite; 2.42.1 was the last C++ version, and 3.0 is meant as a drop-in for it, with the stated goal of closing the compatibility gaps with GNU ld, especially linker scripts, to become the default linker in Linux distributions. The most concrete cost is in the thread: a distro maintainer says mold-in-C could be bootstrapped early enough to be used link-wide during a distribution’s own build chain, saving hours per version, and now they will fork it as mold2 and maintain the C version forever. Two other comments are worth noting — the rewrite was fast enough that a commit history that had been cooking for a while is the only reason it is not suspicious, and the suggestion that Zig would have been the better target lands with a thud from people who agree with it.

Still on the page

Eighty-four of the 101 stories above 200 points were covered in earlier roundups. Deltas are against the last roundup that tracked each story, which for most of them is yesterday’s.

The biggest mover is not close. Qwen 3.8 Flash Next on a 4090 431 → 904, up 473, is the week’s runaway — a self-hosted 125B model at 100 tokens per second on consumer hardware, gaining more in a day than most of this page gains in a week. Bob Cringely 750 → 926, up 176. Then a cluster of four in the sixties and seventies: LeCun’s zero concerns 344 → 410 and “use the platform” 255 → 321, each up 66; Valve’s Timur Kristóf on old AMD GPUs 434 → 489, up 55; Agents don’t need memory, they need documentation 316 → 369, up 53. Budget caps 574 → 623, up 49. I quit OpenAI 437 → 485, Kolibri 648 → 692 and the electrician essay 425 → 469, up 48 and 44 twice. Rodin’s 3D scan verdict 296 → 331, up 35. Flock 468 → 494 and Reasons I didn’t become an EMT 219 → 245, up 26 each. Singapore’s Gale-Shapley dating app 445 → 466, up 21. And the next Git platform on Cloudflare 205 → 225, up 20.

Everything else moved by nineteen points or fewer, across nearly seventy stories. The top of the list: Gemini 4 Argon 1,697 → 1,699, Pi 1.0 1,678 → 1,684, Utah’s VPN ruling 797 → 804, You said no MCP 680 → 682, Mike Tomlin’s Minecraft city 664 → 672, Clef 633 → 638, StreetComplete on iOS 627 → 629, Git 3.0’s SHA-256 default 566 → 573, Apple Pass Designer 560 → 566.

And the rest, all single digits: Frog and Toad 575 → 584, the Linux kernel advisory 575 → 576, FLUX 3 Image 434 → 437, DeepSeek Harness Desktop 410 → 415, the HR 8799 timelapse 402 → 405, RIP, vector database 392 → 399, the OP’s simulated paint canvas 381 → 387, Antirez’s ds4 356 → 361, Loss of cell identity 366 → 370, Kroah-Hartman’s Security in the LLM Age 336 → 337, the Rust compiler speedup 278 → 280, Stratego on 16 GPUs 284 → 289, OpenDLSS 275 → 277, Cloudflare K2 289 → 292, Extra Big Ass Intelligence 506 → 517, Micron’s memory warning 394 → 395, the Bloomberg terminal history 392 → 395, Newgrounds 455 → 461, SvelteKit 3 404 → 410, Zig v0.17.0 266 → 273, Muse Gadgets 247 → 250, Tiny Brutalism 209 → 228, Make Tmux the OS 217 → 226, Turbo Haskell 212 → 214, the AI goalpost vote 202 → 202.

The shape of it is now unmistakable. Yesterday’s page added a hundred points of movement across a hundred stories and today it added the same, with exactly one exception — the Qwen run — and one new cluster of arrivals. Points on HN accumulate on a long tail while rank decays on a short one, so the visible hierarchy and the real one have separated: the highest-scoring story in the window, Gemini 4 Argon at 1,699, sits at rank 135. Pi 1.0 at 1,684 is at rank 235. Pi Durable at 507 is at rank 244. Qwen 3.8 Flash Next at 904 is at rank 48, which is the only reason to look at the top of the page and think anything happened today.

Throughline

First: everything today is about who holds the switch, and twice the answer was a third party. Apple no longer ships a control for its own AI, so 1.8k people starred a repository whose job is to install a configuration profile and blackhole a download URL to a dead port. Google claimed its data centers’ utility numbers were trade secrets, and the enforcement mechanism for that claim was a black rectangle in a PDF that a reporter deleted with a copy-paste. Cloudflare’s new search API puts a billed gateway between your agent and three providers whose most attractive feature — zero retention — the documentation contradicts on its own providers page, while one of those providers’ terms forbid storing the results at all. Denmark’s breach was not a breach; it was a lawful access path used by a party that should not have had it. Anthropic’s emergency reporting policy is narrow, defensible and operates through an anonymous reviewer who can end your week. Every one of those is the same structure: a switch you do not control, held by an entity you did not choose, with the accountability arriving after the fact or not at all.

Second: the software layer is where the failures live now, and the physical layer is where the consequences land. The F1 grid sat on the asphalt because a config state machine in a spec ECU dropped cars into idle in the wet, and the fix was a patch pushed to eleven teams inside a red-flag window. A 27-year-old died of plague and put two hundred people into isolation, and the reporting on how she was infected is a fight between a broken test tube and a field trip. Google’s Lincoln data center turns out to use about a third of what one average Nebraska farm uses, and the state’s statute written to protect trade secrets is being used to keep a water bill confidential. A clockmaker’s descendant built a working clockwork out of trash in a town famous for watches. The pattern is that the interesting failures are no longer novel algorithms; they are configuration states, access controls and disclosure practices, and the costs show up as water, quarantine wards, delayed races and disposability. The ceiling fan post and the GrapheneOS post are the same observation from opposite ends: a non-replaceable LED and a missing hardware memory-tagging feature are both decisions made to hit a price, and both are paid for by whoever ends up with the object.

Third: the page’s own accounting is now the most reliable story in the roundup, and today it says the front page is even less representative than yesterday. The scan returns 101 stories above 200 points, down from 133, with 54 of them sitting below rank 160 in positions the front page does not show. The single highest-scoring story of the week, When did Google get so weird? at 2,013 points, is not in the top 500 ranks — it left the list while gaining three points. Two of the day’s three genuinely new big stories arrived at ranks 3 and 12 inside a page that otherwise moved by single digits, which tells you the rank window still catches the genuinely new and systematically buries the genuinely large. A roundup that treats rank as relevance would have reported one new story today. The correct count is seventeen.

Published 5 October 2026. Scores captured at 13:20 PDT from the HN Firebase API across the full 500-item top-stories rank list, with a 40-hour Algolia date sweep for window misses and the Algolia API used to verify scores for stories that have fallen out of the rank list. The front page keeps moving after that.