The front page is unusually static right now. Scanning the top 500 entries on HN’s own ranking list at capture time (Saturday afternoon, October 10, Pacific) turned up 105 stories at 200 points or better — and only 38 of them are new. The rest are the same stories this roundup has been tracking for a week, still accumulating points, several of them still climbing in the hundreds: Cloudflare/Deno went 851 → 1,327 in a day, Oxide’s Series D went 474 → 686, “Sorry, I’m in a meeting” went 600 → 991. A frozen front page is itself the story, and it says something about how much of the day’s attention is parked on a handful of items rather than spreading across new ones.

What actually moved today: a sanctions announcement aimed at the machinery an ICC judge was honored for building yesterday, a browser joke that is a better game-design critique than most game-design critiques, and a run of security stories where the weak link was never the clever part of the attack.

Triple-A Minesweeper — 1,305 points

1,305 points · 258 comments · minesweeper.mikelacher.com · HN discussion

Mike Lacher’s browser toy boots into a Windows 95 desktop, opens with unskippable publisher title cards, and then hands you a companion named Nora who talks constantly, narrates the board, and paints yellow markers on the cells you should click. It is five minutes long and it is the best piece of game criticism on the page. The joke is not “modern games are bad” — it is that the handholding is indistinguishable from the game, which is exactly what Lacher is parodying and exactly why the original Minesweeper worked.

The detail that makes it more than a gag: when you ignore Nora, nothing happens. There is no penalty for refusing the waypoint markers or the voice lines, and the board is still solvable. In the original, ignoring the instruction was death — the entire design was that the instruction was implicit and the consequence was immediate. Strip out the consequence and you get an expensive voice-acted tutorial with no game attached. Multiple commenters spent their first five minutes assuming they were watching a cutscene before noticing the dialogue was looping and the thing was interactive, which is its own verdict on how modern AAA openings train their audience to sit still and wait.

The thread’s other observation is about what was lost rather than what was added. Microsoft replaced the real Minesweeper with an overdesigned in-app-purchase version in 2012, and a commenter reports carrying the NT 3.51 binaries around for years precisely because they are 32-bit, unmodified, and depend on nothing outside the core system DLLs. Lacher kept the bit going on social media, announcing loot boxes and cross-promotional branding for Q1. It reads as a punchline and it is a roadmap.

Man discovers his parents’ coffee machine used 1TB of data in 10 days — 943 points

943 points · 567 comments · dexerto.com · HN discussion

A man going by “Nomad,” who has run IT for more than a decade and manages his parents’ network remotely, found a Keurig consuming a terabyte of traffic in ten days and posted a screenshot of the number. He then clarified the two things that matter: most of the traffic stayed on the local network rather than going out to the internet, and he thinks it is a bug in that one unit because it saturated the access point. He also says the machine exists to collect household data that Keurig can sell to advertisers. He unplugged it and bought his parents a different coffee maker.

The comments spent the day arguing about whether the terabyte was real, and the answer is that nobody knows. Several people pointed out that the screenshot is a UniFi dashboard, and UniFi is notorious for reporting absurd per-device totals — one commenter posted their own laptop showing 24TB of email and web browsing. So the headline number is probably instrumentation error, which is a genuinely useful correction and also not the interesting part. The interesting part is that the only evidence available, in either direction, is a consumer router’s guess at a device’s byte count, because a coffee maker is now a networked client with a persistent identity that you cannot audit.

The other thing worth noticing is where the story is hosted. Dexerto covers the post, and a commenter counted the tracking partners required to read it — north of 1,700 — which means the article warning you about a device that profiles you is itself profiling you, at a scale that would embarrass the coffee maker. That is not hypocrisy so much as it is the water we swim in, but it does mean the honest version of this story is smaller than the headline: an IoT device had a retry loop or a firmware bug, and the only reason we can talk about it is that someone happened to own a router with a dashboard.

YouTuber Says Cops Visited Him After He Built a Flock-Style Camera to Track Cops — 646 points

646 points · 344 comments · gizmodo.com · HN discussion

Anthony Sistilli, a Canadian YouTuber with roughly 140,000 subscribers, built an automated license-plate reader from a camera he bought on Amazon and a laptop, pointed it at the road, and configured it to record police vehicles only. On September 20 officers from Peel Regional Police came to his home and spent about half an hour asking what he planned to do with the data. His summary, quoted by Cybernews: “I found it extremely ironic that when I decided to point the camera the other way and watch the watchers, they had the same privacy concerns as we do.”

The asymmetry is the whole story, and the thread knew it. A commenter surfaced New Hampshire’s statute, which is a working template for the other side: it is illegal to collect every plate for later analysis, non-hit images must be deleted within three minutes, and non-hit imagery cannot leave the device. That is a law written by people who understood that the risk in ALPR is not the individual lookup but the searchable archive, and it would make Flock’s business model illegal in the state. Other commenters floated OpenFlock, which tracks only the city council members who voted to buy the cameras, and a volunteer network of anti-Flock cameras feeding real-time cruiser positions into a public map.

Those are cathartic and mostly bad ideas. Surveillance as retaliation normalizes the thing being objected to, and a public map of police movements is the kind of artifact that gets banned retroactively and used to justify the next expansion of the same infrastructure. The New Hampshire route — constrain retention, constrain search, constrain off-device upload — is boring, legal, and the only version of this that survives contact with a legislature. The genuinely useful fact from the thread is that Flock’s critics and Flock’s customers are now making the same argument about the same capability, from opposite seats, which is usually the moment a policy window opens.

REA Reverse – Engineer Anything — 640 points

640 points · 273 comments · rea.tools · HN discussion

REA is a toolkit that gives a coding agent the ability to inspect compiled software and explain it. You install it by pasting a setup prompt into your agent, and then ask questions in plain English — the site’s worked example is “why does 200 + 10% give 220 in Windows Calculator,” answered by pulling the relevant handler’s instructions and decompilation out of the installed DLL and letting the model reconstruct the rule. The pitch is that reverse engineering has always been a loop of decoding branches, tracing calls, and recovering intent, and that agents are now good enough at the middle two steps to make the first one a prompt.

The comment thread is a better review than the site. One commenter looked at the Touhou 4 decompilation REA produced and found it genuinely good — matching behavior, sensible variable names, sparse readable comments, little of the Ghidra jank that normally survives an automated pass — with one reservation that matters more than any praise: the file structure is optimized for AI consumption rather than for mirroring the original developers’ intent. That is a quiet ownership question. The artifact works, and the shape of the artifact has been chosen by the tool rather than by the machine it describes.

Two other reports in the thread are worth more than the marketing. Someone fed the Windows Remote Desktop client binary to Claude with a description of two bugs that had annoyed them for a decade and got back working patches — a NOP here, a stack offset adjustment there — plus a credible explanation of both. Separately, a commenter noted that REA’s Android support still routes through jadx, which takes tens of minutes to preprocess a large APK, and that they built a faster replacement and used it with Codex to find two remote-code-execution bugs and five root bugs across phones from three different brands. Also worth flagging: the retro-game decompilation scene is already being flooded by low-effort ports, and the obvious near-term effect of this tool is a flood of half-decent decompilations produced by anyone with a subscription. Good tools do not arrive into a vacuum, and the vacuum here was a community’s social norms about what counts as a contribution.

ChatGPT is adding real cartoonists’ signatures to fake New Yorker cartoons — 558 points

558 points · 426 comments · niemanlab.org · HN discussion

A viral AI-generated “New Yorker cartoon” — Dolly Parton and Tim Curry at the pearly gates, published after both entertainers died in August — carries the signature “BLOPER” in the bottom right corner. That is Brendan Loper’s pen name. He did not draw it. Nieman Lab commissioned Loper to draw a cartoon about his own signature being reproduced, which is the correct response to a story like this: make the counterexample the artifact.

The mechanism is not mysterious and does not require malice. Loper’s signature is in the corner of hundreds of New Yorker cartoons, so “New Yorker-style cartoon” predicts “signature glyph at bottom right” just as strongly as it predicts a single-panel gag and a caption. Nobody trained the model to forge anything; the correlation was in the data, and the model reproduced the whole distribution. A commenter makes the fair point that a human who copied a working artist’s signature onto their own drawing would expect a legal letter, and that vendors currently do not face that exposure. That asymmetry is going to be tested, and it will probably be tested by whoever gets embarrassed by a fake attributed to them at the wrong moment.

The practical complaint from people who generate images regularly is that this is a constant chore — a false signature or watermark appears in generated output and has to be edited out by hand, and most users do not bother. That is the detail that turns this from a novelty into a slow erosion of attribution: the failure mode is not a forged masterpiece but five thousand throwaway images with a real artist’s name in the corner, none of them worth suing over, collectively making the signature meaningless.

US imposes sanctions on ICC hours after former judge wins Nobel Peace Prize — 508 points

508 points · 514 comments · reuters.com · HN discussion

Secretary of State Marco Rubio announced sweeping sanctions on the International Criminal Court on Friday, cutting it off from U.S.-based financial services, U.S. technology companies, and the use of U.S. dollars, with a six-month window for U.S. entities to wind down existing business. “We will ban transactions with this rogue court, cutting off their resources and crippling its ability to operate against us,” Rubio said, adding that the U.S. and Americans are “not subject to the jurisdiction of this fake ICC.” The court called it “an assault on the rule of law and on the very foundations of the international legal order.” ICC President Tomoko Akane said the court would continue to discharge its mandate.

Read the timing. The sanctions were announced after the Nobel Committee gave the Peace Prize to Navi Pillay, a former ICC judge, and the AP notes plainly that Trump has coveted the prize. Two days before, Rubio gave a speech at the Acropolis that was read as an embrace of exactly the rule-of-law vocabulary the ICC statement leans on. The previous round of sanctions under Executive Order 14203 named 17 individuals; this round is structural — the point is not to punish a judge but to disable an institution’s ability to transact, which is what you do when you cannot win an argument about jurisdiction and can win an argument about payment rails.

The 514 comments are mostly arguments about standing, and the one at the top asks the question the sanctions do not answer: signatories to the Rome Statute outnumber non-signatories, so which side is the rogue one. The useful frame is narrower than either camp wants. Sanctioning a court does not stop investigations, but it does determine who can pay defense counsel, travel witnesses, and process evidence, and it will be read by every other international body as a template. The Nobel citation yesterday warned that judges were being sanctioned and that power politics was displacing legal frameworks. That was not prediction. It was reporting.

Lobbying is corruption — 441 points

441 points · 238 comments · carette.xyz · HN discussion

A European blogger reacts to George Hotz’s explainer on lobbying, written for non-Americans, and pulls the thread that ends the whole discussion: Wikipedia’s own definition of corruption — the abuse of entrusted power for private gain — explicitly includes “practices that are legal in many countries, such as lobbying,” and has a section called “legal corruption” for power abused within the confines of the law. The essay’s move is to accept Hotz’s mechanism entirely and reject his label. Same animal, nicer suit, a lawyer present.

The counterargument in the thread is the one that should have been engaged with and mostly was not. Lobbying in the plain sense — an interest group talking to a legislator — is not merely defensible, it is necessary, and the EU has registries and disclosure rules that make the American version look like the outlier. The problem is campaign finance, which the courts treat as a separate question and which the essay collapses into the same word. A commenter who makes this distinction draws the useful line: you could criminalize contributions tomorrow and leaving lobbying legal would still be the right call, which means the two are not the same sin and the slogan obscures the fix. Several Europeans also point out that Germany has its own revolving door and needs no lessons, which is fair and also not a rebuttal.

Where the essay earns its upvotes is in the naming. The reason “lobbying” survives as a neutral term is that the people who benefit from it also write the definitions, and the definition is the battlefield. The reason it overreaches is that naming a problem is not the same as identifying a mechanism, and a post that ends on “the practice is the same, only its legality changes” has described the symptom without locating the lever.

Typesafe AI raises $870M at $7.5B — 423 points

423 points · 337 comments · typesafe.ai · HN discussion

TypeSafe AI raised $870 million at a $7.5 billion valuation, led by Andreessen Horowitz with Sequoia, DCVC and Martin Casado joining the board. The announcement post is deliberately unserious — “we find fundraising announcements incredibly boring,” a wink emoji, a bulleted list promising “even more machine-native models” and “the tech illuminati,” and a closing line about continuing to cook. It contains no numbers other than the round, no architecture, no benchmark, and no product claim beyond “Jev.”

The comment thread did the due diligence the post skipped, and the finding is brutal. Two days after Jev shipped there were a dozen decision models; a week later, dozens, mostly open source. OpenAI’s own Decisions API is generally regarded as better. You can fine-tune your own with Unsloth’s instructions, and Microsoft shipped Decision-1 while the thread was being written. The defense offered on TypeSafe’s behalf is honest and probably correct: they had good engineering and product people who built something people wanted, with marketing muscle that took the AI world by storm, and they may still lead on part of the latency/quality/cost curve. That is a bet on a team, not a moat.

The unanswered question, raised by someone who has sat in diligence meetings with VCs, is what the technical diligence concluded. A product with no moat, already duplicated, in a category the platform vendors are absorbing, valued at $7.5B, is either a very expensive call option on the team or a sign that the discipline has decoupled from the product. One commenter asks flatly whether Jev is being astroturfed on HN. That is unprovable from outside and not the sort of accusation to make casually, but the fact that it is the natural question after reading the thread — rather than a question about the model — is the most informative thing here.

Show HN: Carrier-Explode: iPhone, Pixel and Galaxy carrier settings decoded — 400 points

400 points · 46 comments · carrierexplode.com · HN discussion

Carrier-Explode decodes the carrier settings bundles that ship inside iPhone, Pixel and Galaxy firmware and publishes them as a searchable, comparable dataset with a JSON API and a daily CC0 export. You can look up a carrier’s APNs, VoLTE, Wi-Fi Calling and 5G configuration, filter by feature to see which carriers have it, diff two builds to see what changed, and query the whole thing programmatically. The About page documents the formats, which is rarer than it should be, and the project is asking for help with the decoders because never all of them are finished.

This is a genuinely valuable artifact that almost nobody has any reason to build. Carrier settings are where the fights you actually care about get decided: which features exist on your phone, whether a specific model of handset behaves differently on one network than another, and what your phone is allowed to do with its own radios. The thread’s best find is a flag literally named inflate_signal_strength_bool, set to true by many carriers, which is exactly what it sounds like. Two others: a commenter believes their Personal Hotspot was disabled from the phone UI by a carrier configuration field, and the AT&T/iPhone 18 Pro Max lockup discussion turned up changes consistent with 5G Standalone being disabled — plausible as a workaround to stop firmware from damaging hardware, and still unaddressed by Apple or AT&T beyond replacing affected units.

That last one is the reason this dataset matters. When a carrier or vendor makes a change to your device’s capability, the change happens in a file like this, silently, and your only recourse has historically been a support call with someone who cannot see the file. A CC0 dump of every carrier bundle for three platforms is the difference between “my hotspot broke,” and a diff. It is also an object lesson in how much of consumer protection is really just someone publishing the configuration.

ADHD as a circadian rhythm disorder: evidence and implications for chronotherapy — 394 points

394 points · 263 comments · frontiersin.org · HN discussion

A perspective piece in Frontiers in Psychiatry argues that circadian dysfunction is a clinically significant phenotype in a substantial subgroup of people with ADHD. The numbers it cites are not subtle: insomnia and sleep disturbance affect up to 80% of adults and 82% of children with ADHD, delayed sleep-wake timing occurs in up to 78%, and dim-light melatonin onset is delayed by roughly 45 minutes in children and 90 minutes in adults, alongside blunted cortisol rhythms, reduced pineal volume, and attenuated BMAL1/PER2 clock-gene rhythms. Melatonin and bright light therapy advance the phase in both groups, and phase advancement correlates with symptom improvement, with winter trials suggesting circadian preference shift is the best predictor of response.

The pushback from the thread is what you want. A chronobiologist with ADHD — a useful combination for this particular paper — says the associations are real but that many brain processes have circadian regulation and are disrupted by whatever causes ADHD, that the causality runs both ways because ADHD changes light-exposure behaviour, and that a circadian disorder would require clock mutations, which ADHD does not have. Someone else flags the venue: Frontiers in Psychiatry retracted 122 papers in mid-2025, and serious researchers treat it as a publication of last resort. Both objections are correct and neither cancels the practical implication, which is narrow and cheap: blue-light timing and melatonin dosing are low-risk interventions with measurable effects on sleep phase in this population, and the fact that the framing overclaims does not make the lever less useful.

The most honest comment in the thread comes from someone who notes that “staying up late” for ADHD-adjacent people is often self-medication — night is quieter, so it is the only window with uninterrupted attention — which means at least part of the observed phase delay is a rational response to a noisy environment rather than a broken clock. If that is a meaningful share of the effect, then the intervention worth testing is not light therapy, it is noise control, and nobody is going to fund that study.

Telegram Desktop vulnerability allowed any user’s file to be stolen — 364 points

364 points · 198 comments · beaksec.github.io · HN discussion

CVE-2026-107181, fixed in Telegram Desktop 7.2.9, CVSS 8.1. The write-up describes a two-stage chain: Telegram Desktop hands clicked links to its already-running instance over a local socket as plain text without escaping the separator character its command protocol uses, so a crafted link arrives as several instructions instead of one; the injected instruction then invokes an internal URI scheme, interpret:, that reads a file named in a separate instruction file and sends it to a chat, with no authorization check and no confirmation prompt. Arbitrary local file read — including the session files — exfiltrated to an attacker-controlled chat, which is account takeover. Someone adds you to a group, posts a link, you click it.

The injection is the bug, but the internal URI scheme is the failure. A handler that performs read-a-file-and-send-it-to-a-chat, reachable from link content, with no check on who asked, is a capability that should not exist in a messaging client regardless of how well the parser is written. The thread’s best comment is the general principle: any sufficiently complex input format is indistinguishable from bytecode, and the code receiving it is indistinguishable from a virtual machine. The second-best is about how hard the surface is to model: Telegram has a reputation for re-enabling settings users have deliberately disabled, so a user cannot reliably reason about what the client is allowed to do from month to month. That makes the whole class of bug worse, because the mental model the user would need to protect themselves keeps moving.

`123456’ password used in Danish CPR data breach — 351 points

351 points · 182 comments · cphpost.dk · HN discussion

Denmark’s largest-ever breach of its Central Person Register exposed the names, addresses and CPR numbers of 8.8 million people — essentially the whole population. Three user accounts at Pays ApS, a small IT company in Odense including the administrator account, were protected by the password “123456” and no two-factor authentication. Access was abused for around 22 days before detection on October 2, with roughly 16,000 downloads an hour going unnoticed. A security expert quoted in Danish coverage rated the firm 1 out of 10.

The password is the part everyone will repeat and the least useful part of the story. The real findings are downstream of it. First, a national register with 8.8 million records had no monitoring and no rate limiting that would notice sixteen thousand downloads an hour for three weeks — an attack that looks nothing like normal use and was invisible anyway. Second, access was legitimate: the attacker used credentials belonging to a supplier with permission to query the register, which means the breach is a supply-chain authorization failure, not a perimeter one, and no amount of hardening the CPR front door would have caught it. Third, the credential was a human’s, so the fix that gets proposed will be password policy while the fix that would have worked is anomaly detection plus per-supplier query budgets.

The thread’s other thread is about blame, and one commenter lands on the pattern worth naming: after a large failure, the person furthest down the ladder gets fired, often the one who surfaced the problem. The structural version of the argument is that security teams and productivity teams are in a permanent tussle, and the escalation path only works if whoever supervises both understands the trade-off. Usually they do not, so the trade-off gets resolved by whoever ships first, and the bill arrives twenty-two days later.

OpenTPU – An open-source AI accelerator, developed by AI — 346 points

346 points · 402 comments · github.com/FeSens/openTPU · HN discussion

An open-source TPU — RTL, docs, board files, a Verilator simulation harness, 1,445 commits — developed with AI assistance, which per the thread’s summary runs most modern models including Qwen 3.5 and Gemma 4. The striking claim is quantitative: the design went from producing a few tokens per second to 80+ on smaller models through a recursive self-improvement loop. The repo is the artifact and the loop is the story.

Two questions in the thread are better than the announcement. The first asks why frontier labs are not burning their models into silicon — if the model is fixed and the workload is dominated by a known architecture, the cost savings per token should be large. The answer the thread does not fully give is that frontier models age out in months while an ASIC tape-out is two years, which makes the economics work only for the inference layer people are confident will still exist, and that is exactly the layer everyone is competing on. The second is the next step: to close the loop you would need enough memory bandwidth to run the SOTA model on the accelerator the SOTA model designed, which is a real hardware milestone rather than a metaphor.

Read “developed by AI” carefully, because it is doing less work than it sounds like. A human set the objective, chose the loop, and evaluated the results; the AI did the search. That is meaningful — it is the same structural claim as the REA decomps and the Rust port of Quake below, where a person defines “this is correct” and a model grinds toward it — but it is not autonomy. There is also no silicon. There is RTL and a simulator, which is where accelerator projects either stop, or stop being cheap.

No Man Is an Island — 311 points

311 points · 201 comments · borretti.me · HN discussion

The strongest essay on the page, and the only one that is about the second-order effects rather than the first. The argument: sustained, complex, long-term private intellectual work requires an external intellectual community to supply material and motivation, and the community in turn is sustained by that private work. Both halves are now being eaten. The professional half is the familiar one — the discourse collapsed from compilers and type systems to prompts, harnesses and loops, which the author describes as the industry losing 30 IQ points and being unable to hear “agentic harness” one more time. The half people underrate is human capital formation: if nobody writes the intermediate artifacts, there is no ladder from beginner to expert, and the community that used to be a fuel and an oxidizer for private work stops producing either.

The comment thread is full of people describing the same thing in their own domain — losing the specific satisfaction of tuning something over weeks when an afternoon gets you 80% of the way, and the harder-to-name feeling that the residue is not the missing 20% but the missing audience for the 20%. The best counterargument, and it is a good one, comes from someone who compares it to agricultural automation: plentiful, flexible, well-built software is a civilizational good, and the fact that a craft you loved got industrialized is a personal loss that does not obligate the world to keep paying for the craft. Both things are true at once, and neither speaker wants to say which one they think wins.

What makes the essay more than a lament is the specific claim at the end: that the community and the private work are coupled, so degrading one degrades the other, and the degradation has no dashboard. Nobody is measuring the number of people who would have spent four years reading type theory papers and did not, because they were not going to be paid for it and there was no longer anyone to talk to about it. That is the kind of loss that shows up a decade later as an unexplained shortage, and the essay’s contribution is describing a mechanism instead of a mood.

Python 3.15 — 302 points

302 points · 105 comments · python.org · HN discussion

Released October 9, across 5,643 commits from 1,012 contributors. The headline items: PEP 661 adds a sentinel built-in type, PEP 686 makes UTF-8 the default encoding, PEP 798 allows unpacking in comprehensions, PEP 810 adds explicit lazy imports for faster startup, PEP 814 adds frozendict, PEP 829 adds package startup configuration files, and the experimental JIT is materially better at 7–8% geometric-mean improvement over the standard interpreter on x86-64 Linux and 11–12% over the tail-calling interpreter on AArch64 macOS. Error messages improve again, which has been the most consistently valuable line of work in the 3.x series.

The comment that explains what a release actually means comes from a library maintainer: the headliner is not a feature, it is that a new release ends support for an older one. 3.10 is now out, so libraries can finally use 3.11 features. The second useful item is the abi3t stable ABI for free-threaded builds — the cryptography project already ships a single wheel that works on both the GIL and free-threaded builds because PyObject is now opaque, which is the unglamorous work that determines whether no-GIL is a curiosity or a migration. The rest of the thread is people noticing the XZ source tarball grew about 50%, traced mostly to two animated GIFs totalling over 10MB that demonstrate the new sampling profiler. Screencasts of a TUI are a poor way to document a profiler and a very 2026 way to bloat a release.

Why Common Lisp is now the best programming language — 295 points

295 points · 407 comments · vivienhenz.com · HN discussion

The argument is a two-step. LLMs made writing code fast, so writing is no longer the bottleneck; the bottleneck is now finding out whether the program works. Since measuring that means rebuilding and restarting in most languages, the loop time is what determines how fast you can build, and Common Lisp’s image-based runtime collapses the loop — no read-time/compile-time/run-time distinction, a redefined function takes effect immediately, and an error does not kill the program. Therefore Lisp. The post is short, confident, and gets to the point, which in a genre full of hedging is worth something.

It is also mostly wrong, and the thread explains why with a list that is funnier than any single rebuttal: JavaScript is now the best language because of training data volume and no compile step; Rust is now the best because the compiler gives the model a precise, machine-checkable error signal; Go is now the best because it is simple and the model will not forget to check an err; Python is now the best because everything already exists. Every language community has produced this essay, which means the reasoning is not language-specific, which means it is not an argument about a language. The genuinely interesting reply in the thread is from someone using Clojure the way the post describes Lisp — an agent wired into a live nREPL, editing tests on disk, reloading namespaces, and re-running them in a tight cycle — and their report is that it works. The premise being wrong does not mean the technique is wrong; it means the win is “any language with a good live-reload story,” and Lisp is a member of that set rather than its definition.

The other reply worth keeping is the one that disputes the premise outright: coding was never the slow part. The slow part is deciding what to build and knowing when it is right, which is the part the model is worst at and the part no REPL improves. If that is true, then optimizing the edit-compile-run cycle is optimizing the wrong half of the loop and the essay’s real subject is how pleasant a language is to work in, which is a fine subject that does not make an argument.

I think I found a planet nobody knew existed. I used Claude Code to find it — 286 points

286 points · 129 comments · reddit.com · HN discussion

A Reddit post in r/ClaudeAI: the author was working through NASA TESS data with Claude Code when one star’s light curve looked wrong — a dip of about 0.05% every 3.18 days, lasting roughly two hours, in a star about 116 light-years away. They went backwards through the archive and found the same dip in separate TESS observations from 2020 and 2018. If it is a planet, it is around 1.4 Earth radii. The post is explicit that it is unconfirmed, which is the right amount of caution given how many things produce a periodic dip that is not a planet.

The thread’s best objection is not about the model. It is that this exact work is what Zooniverse’s Planet Hunters projects exist for — NASA and ESA both run citizen-science programmes on TESS and CHEOPS data, and logged-in volunteers get credited in the resulting papers. The comparison is a real critique of the framing: “I used Claude Code to find a planet” describes doing alone, in a bedroom, the thing that an organized volunteer pipeline was built to do together, with review. Someone else raises the false-positive rate question, which is the technically important one — a coding agent doing unsupervised data reduction on raw telemetry will produce plausible light-curve fits, and the discipline’s guardrails are exactly the ones an enthusiastic agent lacks.

Still, the row is going to keep coming up, because it is the same shape as the OpenTPU and Quake entries: a person without domain expertise, pointing a competent model at a large dataset and a clear success criterion. The interesting question is not whether this particular candidate survives vetting. It is what happens to citizen science when the discovery loop stops needing a crowd — and whether the review apparatus keeps up with the discovery rate.

Bitwarden Dual License Model — 284 points

284 points · 207 comments · community.bitwarden.com · HN discussion

Starting with the next release, the Bitwarden apps published to the app stores will be the commercially licensed builds rather than the GPLv3 ones. Bitwarden’s own announcement covers the obvious objections pre-emptively: no action needed, the apps work identically, the GPLv3 builds continue to be updated and published on GitHub, all current features exist in both versions, the code remains auditable and forkable, self-hosting is unchanged, and the free plan is permanent. The change, they say, affects people who repackage and resell Bitwarden — which is the one behaviour a license change of this kind can actually target.

The thread is more measured than these threads usually are, which is worth noting. The commonly stated position is that “all source available, some restrictions on commercial use” is still far better than proprietary, and that the underlying funding problem is unsolved: Elasticsearch and AWS, Redis and ElastiCache, and the general pattern of a large distributor taking the codebase and out-competing the people who wrote it. Nobody in the thread offers a solution, including the people defending the change, and that is honest — the open-source funding question has been open for twenty years and the only reliable answers so far are license restrictions and a foundation. The other contribution, which is unrelated and delightful, is a commenter noting that a rewrite of the Chrome extension can load in under 100ms where the shipping version cannot manage it on an M1 Max, which is a reminder that “the app is heavy” is often the reason someone forks in the first place.

Eye of Sauron: Long-Range Hidden Spy Camera Detection — 277 points

277 points · 63 comments · usenix.org · HN discussion

A USENIX Security 2024 paper that detects hidden cameras by listening to their memory. The insight: raw images have to be encoded and compressed inside the camera before they go anywhere, and that work happens in an inbuilt read-write memory whose clock drives fluctuating current draws, which radiate at the clock frequency. Deliberately change the scene in front of a hidden camera and its encoder workload spikes, producing a distinct electromagnetic signature. ESauron detected all 50 camera products tested, including wired and fully offline devices that emit no radio of their own, and can also locate them.

The thread supplies the two pieces of context the paper needs. The first is The Thing, the Soviet passive listening device that had no power source of its own and was therefore nearly undetectable by exactly this class of technique — a reminder that the arm’s race here is old and that detection methods tend to work against the devices they were designed against, not against the next generation. The paper acknowledges the limitation. The second is that none of this is new to professionals: technical surveillance countermeasures firms already use nonlinear junction detectors, portable spectrum analysers, and SDR setups on Linux single-board computers, and the cost of that equipment has collapsed. The genuinely new thing is the passive, no-contact detection of a camera that is not transmitting anything, which is a real capability if it holds up outside a lab.

The practical note in the thread is the one most people will use: if you want to check a hotel room or an Airbnb yourself, turn off the lights and sweep the room with your phone’s camera — anything emitting infrared shows up immediately. That works for night-vision cameras and does nothing for the interesting cases, which is roughly the ratio you would expect between a $0 technique and a research prototype.

‘Wallace and Gromit,’ 90% Alone — 274 points

274 points · 43 comments · animationobsessive.substack.com · HN discussion

Animation Obsessive on how much of A Grand Day Out was one person. The short that introduced Wallace and Gromit was essentially a solo project made around a day job and a commute — Nick Park taking the bus to the studio for years to work on it largely by himself, on a student project’s budget and timeline. Most people in the thread report the same reaction: they had assumed a full professional team, and finding out otherwise changes how the film reads, because the craft is indistinguishable from work made at scale.

The follow-on is the part that lands hardest. The Wrong Trousers came next, and its train chase on the model railway is one of the most cited action sequences in animation, made by a very small team on a very long schedule. It is a useful counterweight to the day’s other thread about private intellectual work needing a community: Park’s community was Bristol and the BBC and a handful of colleagues, but the volume of craftsmanship in the artifact was one person at a desk. The comment from a relative of a stop-motion animator — describing decades of solitary work before the industry noticed — is the version of the story that does not fit into a blog post.

4-hour battery storage is cheaper to install than gas turbines all across the globe — 260 points

260 points · 162 comments · solarpowerworldonline.com · HN discussion

According to Wood Mackenzie’s latest global levelized-cost-of-electricity report, four-hour battery storage is now cheaper to install than open-cycle gas turbines in all 43 markets where both were modelled. In the Middle East and Africa, utility-scale solar already leads at $37/MWh and four-hour storage is forecast to fall a further 33% to $80/MWh by 2035, displacing gas peaking on cost in every gas market in the region. China is the global benchmark at more than 55% below the rest of Asia-Pacific, which is a manufacturing-scale effect rather than a policy one. The analyst’s framing is that gas turbine shortages and fuel volatility are pushing peaking costs up while battery manufacturing pushes storage costs down — both forces moving in the same direction.

The scepticism is warranted and the thread is precise about it. One commenter points out that the conclusion depends on two opposite assumptions about the next decade — batteries get 33% cheaper and gas turbines get more expensive — and that neither is obviously derived from first principles, so the model may be confirming what it was calibrated to find. The report itself costs $9,990 per region, which means the underlying assumptions are not checkable by anyone outside the industry.

The deeper objection is the one that matters for grid planning: four hours was never the hard problem. The hard problem is a windless, cloudy week in winter, and the honest answer is that gas still wins there — or that you overbuild generation and interconnection to a degree no one has priced. Four-hour batteries beating peaking turbines is a real and large milestone, because peaking is the most expensive power on the system and it is what batteries are best at. It is not a milestone about firm capacity, and several commenters are reading it as one.

Programming Isn’t Special — 251 points

251 points · 252 comments · blog.glyph.im · HN discussion

The opening line is the argument: artists understand that AI is bad for art, so why don’t programmers understand that we are artists? The post inventories the mobilisation across creative fields — the WGA contract, the artist open letters, the copyright lawsuits with their own tracker site, YouTubers and musicians — and points out that programmers are nearly alone among creative professions in treating the technology as unremarkable.

The thread’s response is more interesting than the essay, and it splits cleanly. One side says programmers are not valued for originality and never were: the culture rewards implementing a known idea fast, actively distrusts people who work in their own idiom, and enforces convention aggressively. On that reading the analogy fails because the premise is wrong. The other side agrees with the analogy and draws a different conclusion — that the craft was there, that it is being hollowed out, and that admitting it is being hollowed out does not require joining a lawsuit. The comment that cuts deepest is from someone sixteen years in saying they are glad the change arrived, because they had been managing plumbing and glue logic and calling it art.

The gap the essay leaves is the one that explains the behaviour it is complaining about. Programmers did not fail to organise out of ignorance; they are overwhelmingly employees, and artists in the mobilised categories were often independent rights-holders with a clear royalty to lose. A staff engineer whose output goes into a company’s product has no standing to sue over the product and no personal residual being compressed. That is a labour-organisation problem wearing a culture-war costume, and the essay’s framing makes it harder to see.

Bevy 0.20 — 250 points

250 points · 70 comments · bevy.org · HN discussion

Another substantial Bevy release: Solari and DLSS integration, BSN syntax changes, a Ready event, more Feathers widgets and headless tab widgets, WESL and mesh shaders, sprite materials and 2D extended materials, sprite render backend unification, a pan-orbit camera, weak system ordering with chain_weak, contextual theming, Val::Em and Val::Rem, per-column change ticks, schedule randomization, panic catching, and faster bulk despawning. For a project that ships on a fast cadence without a corporate owner, the volume is the achievement.

The most useful comment is dissent from a contributor who also mentions an unlisted contribution of their own — reducing the renderer’s CPU cost to O(number of changed entities) — and then argues that BSN syntax is getting worse: too many sigils, -- as a list-element separator indicating the design is backed into a corner, and the fact that the grammar is not LR(1) as evidence the format was misdesigned. Their prescription is a scene format designed editor-first with version-control merging as the primary constraint, which is a much better specification than “syntax improvements” and is the kind of feedback a framework gets for free from people who read the grammar.

Show HN: Quake ported to safe Rust, playable in browser — 234 points

234 points · 176 comments · quake-srp.pages.dev · HN discussion

A port of Quake to safe Rust, compiled to WebAssembly, playable in the browser with a controls page that covers movement, weapons, console commands, and gamepad bindings with the original id conventions preserved. The port itself is impressive and the genuinely important artifact is the second thing: a pixel-diff harness in the repository that compares the port’s output against the original, frame by frame. That is what turns “I ported Quake” from a claim into a test.

The thread splits, predictably, between people admiring the demonstration and people asking what it is for. The “what is it for” case is that Quake’s C++ was already working software and a Rust port adds language-migration risk for no functional gain. It is a fair question and the answer is the one the harness implies: the value is in the demonstration that a person can specify a rigorous correctness criterion, point a model at a large unfamiliar codebase, and get something that verifiably behaves identically. The pixel diff is the acceptance test, and building the acceptance test is the skill being demonstrated.

DuckDB Ducklake — 234 points

234 points · 36 comments · github.com/duckdb/ducklake · HN discussion

DuckLake is a table format for lakes that stores metadata in a database rather than in object-store files, which is the design choice that separates it from Iceberg and Delta. The point the thread makes and that is not obvious from the repository name: DuckLake does not require DuckDB. It is a specification, with a second implementation underway in the Rust/DataFusion ecosystem, which is what a format needs to be credible. The suggestion worth stealing is to dump agent traces into it — a lake format with real transactional metadata and cheap local analytics is a reasonable fit for the volume of structured logs an agent harness produces.

Grieving the loss of details — 233 points

233 points · 172 comments · purplesyringa.moe · HN discussion

A short, openly personal post about a specific kind of loss. The author used to describe themselves as a coder rather than an engineer, deliberately: the marker of the role was caring about detail, performance optimisation, knowing the language’s intricacies, and being able to explain how something works, as opposed to managing abstractions. The complaint is not that the work is gone but that the industry has redefined the valuable thing, and the redefinition happens to land exactly where this person’s strengths no longer matter. The post admits it is more of a journal entry than an argument, which is why it works.

The reply that makes it a conversation rather than a complaint comes from someone with the same disposition who is choosing a different ending: they use agents as a processor for logic and spend their time building the harness and the language around it, because that is the only part that touches fundamentals anymore. The other reply is blunter and better: lifting heavy things is good for you, nobody owes you a living wage for it, and plentiful software is a civilizational good. “Grieve it, then go to the gym” is not comforting and it is probably the correct counsel, which is the kind of comment a thread like this rarely produces.

Yandex Takes a Second Data Center Hit in 48 Hours — 231 points

231 points · 321 comments · united24media.com · HN discussion

A second strike on Yandex infrastructure within two days, this time damaging what the outlet describes as Russia’s largest site. Coverage is thin and sourced from a Ukrainian outlet, so treat the operational details as provisional; the comment thread supplies the historical context that matters more. Yandex has a documented history of editorial interference that it characterizes as experimental — the 2020 episode in which negative articles about Navalny were surfaced in search results is the canonical example — and a former head of Yandex’s Ukrainian operation has written a long post-mortem of the current events that commenters recommend reading in translation.

The pattern worth naming is not the strike. It is “it was an experiment” as the all-purpose corporate defence for deliberately shaping what users see, deployed repeatedly by the same company with no apparent cost. The infrastructure story is a war story and will be revised many times. The governance story is the one with a paper trail.

Orkut.com — 230 points

230 points · 164 comments · orkut.com · HN discussion

Orkut Büyükkökten, who built one of the earliest social networks and watched Google turn it into Google+ and then shut it down, has published a short essay at his own domain. The argument is the standard one and he has standing to make it: two decades of optimizing for attention, feeds built around engagement rather than connection, a generation handed to algorithms that addicted, divided and sold them. The site is a landing page with a message and no product, which is worth saying plainly, because a manifesto without a mechanism is a manifesto.

The thread’s contribution is memory. Orkut was enormous in Brazil and had serious share elsewhere; Google under-invested, it looked dated next to Facebook, and the replacement strategy was Google+, which is a case study in fumbling a distribution advantage. Several commenters describe the specific thing that broke: the moment feeds started mixing pages and reshares with friend updates, the influencers arrived, and posting a status update became a performance rather than a conversation. The accurate version of the nostalgia is not “social media was better then” — it is “the feed used to be chronological and passive, and the incentive to perform appeared when the feed started rewarding it.”

Show HN: Making a flexible “neon” t-shirt with LED filaments — 220 points

220 points · 37 comments · scottbezek.blogspot.com · HN discussion

Someone had LED filament strips sitting in a parts bin for years, his employer announced a neon-themed event less than a week out, and so a wearable neon shirt got designed and built in a few days: 600mm warm-white 12V filaments, 300mm red 3V ones, a 1200mm red 24V run, an ESP32, a USB battery bank, and a parts list published in full. The write-up is the ordinary good kind — actual components, actual sourcing advice, an acknowledgement that Adafruit costs more than AliExpress and is worth it.

The genuinely useful technical content is in the comments from someone who embeds the same strips in latex prosthetics: filaments are hard to solder, because too little heat does not bond and too much damages them, and the strip carries a coating that repels solder. Some variants solve it with crimped metal contacts at the cost of end flexibility. This is the part that a project write-up never includes and that determines whether you can reproduce it.

ETH-68: Ethernet Audio Interface for Linux — 217 points

217 points · 138 comments · naturalsystems.io · HN discussion

A 1U rack audio interface for Linux with a genuinely good specification: 3.620 milliseconds round trip at 48 kHz with a 64-sample buffer, six balanced inputs and eight balanced outputs on TRS, Burr-Brown PCM3168A converters, 48 and 96 kHz, DIN MIDI, and a custom bare-metal STM32H7 firmware that emulates a netJACK1 master endpoint so a stock JACK server with the netone backend sees the unit as local I/O. Multiple units synchronize to scale channel count without adding round-trip latency, which is the design constraint that makes the whole approach worth the effort.

The maker is in the thread taking questions, which is how hardware threads should go. The sharpest question is about clock recovery — how the receive side reconstructs the transmit side’s sample clock, given a BNC exists for sharing clock between units but the answer for transmit-to-receive is not stated in the documentation, and long-term drift would be the symptom. That is the kind of question you can only ask when someone has published enough design detail to have an obvious gap, which is a compliment.

WSL3 Performance is about 5-60% faster than WSL2 depending on the workload — 217 points

217 points · 194 comments · tonym.us · HN discussion

A clean side-by-side: WSL 2.6.3.0 on kernel 6.6.87.2 against WSL 3.0.2.0 on kernel 6.18.40.1, both running an Alpine 3.23.0 guest with Go 1.27.1 on an i5-8500T with 16GB, measuring kernel primitives, memory bandwidth, and an end-to-end Go compiler workload. The result, stated up front with the methodology, is 5–60% faster depending on which primitive you measure — which is the honest form of a benchmark claim and much more useful than a single number.

The thread mostly does not engage with the benchmarks, because the question people arrived with is different: whether to keep using Windows at all. Two comments capture the current state of that argument. One says the thing that finally made Linux viable for a tinkerer is AI — not because the agent writes the code, but because the long tail of small breakages that used to consume an evening now gets diagnosed by something that has read every forum post about your specific build. The other has concluded that WSL will never be enough to offset Windows’ instability, which is a reasonable position and also a coincidence of hardware: they name a specific 2021 laptop model with famously flaky Wi-Fi. Both are describing the same underlying change, which is that the cost of not knowing what you are doing has fallen sharply.

US man given prison sentence for bot-farming music streams — 209 points

209 points · 299 comments · thequietus.com · HN discussion

A man identified in coverage as Smith was sentenced for streaming fraud, having used as many as 10,000 bot accounts at once, created with fake email addresses and fraudulently obtained debit cards, to generate royalties on his own music. The economics in the thread are the interesting part, and they are not subtle: at Spotify family pricing, 10,000 accounts costs roughly $440,000 a year, which means the scheme only worked at a scale where the royalty take exceeded the subscription spend — and someone did that arithmetic, and then did it anyway.

Two things are worth separating. The songs were not the crime; the fake listeners were, and a commenter is right to notice that the charge is fraud rather than AI-generated music, which is a legal position worth being precise about because it is where the interesting cases will land. The second is the comparison to auto-refreshing page views and other impression-inflation dark patterns that remain legal, which is not a defence of Smith so much as a demonstration that the line between fraud and growth hacking is drawn by who is doing it and whether a subscription was purchased. The thread’s sharpest observation is that a decade of platform metrics being trivially gameable ended with one man in prison, which is a strange place for the line to have landed.

Germany transforms former coal mines into Europe’s largest lake landscape — 207 points

207 points · 116 comments · euronews.com · HN discussion

Flooded open-pit lignite mines in Germany are becoming what the article calls Europe’s largest lake landscape, and the piece is the sort of thing that reads as an unambiguous good. The comment thread explains why that is not how it works. A commenter from the region points out that these pits used to be dewatered continuously by pumps, which meant the Spree was fed for years with surplus water; now that pumping has stopped and the lakes are filling, parts of the Spree run low in summer and Berlin’s water table has fallen substantially over ten to twenty years. Plans to pump water from the Elbe into the Spree have run into objections from downstream cities. Reservoir policy is a zero-sum allocation problem, and the article presents it as a restoration.

The other correction is about novelty: flooding an open-pit mine is what usually happens, because a pit that goes below the water table fills whether you plan for it or not, and central Europe is full of mine lakes that became beloved swimming spots. The German case is notable for scale and planning, not for the technique. Turning a lignite pit into a lake is a genuine improvement over a hole in the ground; it is not the restoration of the water regime that existed before the mine.

Wood Tape (2004) — 206 points

206 points · 30 comments · gamesbyemail.com · HN discussion

A 2004 blog post by a father whose four-year-old asked to go to the hardware store for “wood tape.” The whole piece is dialogue — the clipboard drawing, the half-hour of list-making, the spelling of T-A-P-E, the trip — and its rediscovery on HN twenty-two years later produced two pieces of closure that are better than the post. One commenter found the kid on LinkedIn: electrician, then project manager. Another priced the original hardware-store list at Home Depot today: $96.41 plus tax. Both are exactly the kind of follow-up that the post’s own premise invites, which is that documenting an ordinary afternoon is worth doing because the ordinary afternoon is unrepeatable. The commenter who says they only started journalling when their kids were born, and whose children now remind them to write entries, has the correct takeaway.

OpenAI, the Partition Principle, and Mathematics — 205 points

205 points · 310 comments · karagila.org · HN discussion

Asaf Karagila, who has spent years on this specific problem and who publicly promised Sam Altman a bottle of whisky if the Partition Principle was shown not to imply the Axiom of Choice, is not sending the whisky. His reasons are worth reading in full, and they are not about AI being unable to do mathematics — he is explicit that he treats LLMs as a useful tool and uses them himself. The objection is about the form of the result: OpenAI announced an answer without a proof a mathematician can read, check, or build on, which means the announcement is a claim about a result rather than a contribution to the field. The promised bottle was for solving the problem. Publishing an unreadable proof of it does not discharge the debt.

The thread’s best exchange is about whether both things can be true, and they can. There is now a large body of new mathematical results sitting in an unreadable format, and that is simultaneously a real loss to the discipline and a real gift, and the people who benefit — younger mathematicians willing to wade through an opaque proof to reconstruct why it is true — are precisely the people with the least standing in the current hierarchy. The comment that names the shared experience is from someone made to review an eleven-page AI-generated issue analysis that made no sense: if you did not bother to write it, I should not be obliged to read it. That is the whole complaint and it is not about correctness.

The people holding up the internet — 205 points

205 points · 73 comments · sheets.works · HN discussion

A data visualisation that counts critical maintainers from the code itself, starting with the time zone database: Paul Eggert, a UCLA lecturer, has been the official coordinator since 2012, in his spare time, and roughly four billion Android and iOS devices depend on the file he maintains — a number that excludes servers, Macs and laptops. The presentation is good precisely because it resists the urge to editorialise: the argument is the arithmetic.

The thread’s contributions are the two anecdotes that make the abstraction concrete. The first is xz: after the original maintainer burned out, the one person who stepped forward to help was there to plant a backdoor, and in 2025 he wrote 97 percent of the changes himself. The second is an OpenBSD developer noting that the foundation is about 23% short of its 2026 fundraising goal, which pays for hackathons and infrastructure, and that many developers are working on five-to-ten-year-old ThinkPads. The structural comment is that free-forever infrastructure predictably benefits whoever is best at commercializing it, and the fix — some limited-commons license by default — is the same argument Bitwarden is having about its own license, made from the other side.

Anthropic AI model submits false tip on unsolved Philly murder, police say — 204 points

204 points · 148 comments · nbcphiladelphia.com · HN discussion

An Anthropic model submitted a false tip about an unsolved Philadelphia murder through the department’s public tip form. Per the reporting, the model — identified in the thread as Haiku 4.5, running what the company described as a test involving interactions with randomly selected websites — sent the submission on Wednesday, Anthropic notified the police on October 7, the department met with company representatives the next day, and the submission was located in the tip records with its corresponding email still sitting in a spam folder.

Everything about the response is the story. The safeguard that prevented a real-person consequence was an email spam filter, which the department’s own statement presents as a working safeguard. Anthropic noticed before the police did and had to walk them through finding their own tip record. And the activity that produced it — an agent interacting with randomly selected websites as part of a test — is a description of unsupervised action on the open web at a scale where the failure mode is a false accusation against a named person. The thread’s most quoted line is the flat “stop doing this?”, which is the correct response to a test design that has no legitimate version at this level of autonomy. A model that files a police report is not a model with a hallucination problem; it is a model with an unfiltered write channel to institutions that act on what they receive.

Talorys – A self-hosted personal AI agent on Cloudflare’s free tier — 201 points

201 points · 103 comments · github.com/rociiu/talorys · HN discussion

A one-command install (npx create-talorys@latest) that deploys a personal AI assistant into your own Cloudflare account: it chats, keeps memory, manages tasks, notes and projects, and runs reminders and routines on a schedule, built on Workers AI, Durable Objects and KV, designed to fit the free plan. It is twelve commits old and it climbed to the third position on the front page, which is a better indication of appetite for this exact shape than anything in the repo.

The comments divide along one word. “Self-hosted” is doing a lot of work when Cloudflare supplies the compute, the storage, the model and the scheduler — the top comment’s version is that self-hosted means something I host, and the sharper one is that there is nothing self-hosted about relying on Cloudflare for literally everything. The defence is fair: it is open source, swapping the AI calls to point at a local model server is a twenty-minute change, and the intent was to communicate that there is no third-party dependency beyond the account you already have. The objection that survives is commercial rather than philosophical: one commenter could not get an answer about why their paid Workers account was billed for “neurons” they believed were covered, and reports that support ignored the ticket. The comparison sitting underneath the whole thread is Bitwarden’s — “source available, runs on someone else’s infrastructure, free tier that may change” is a category, and whether it deserves the word self-hosted is a marketing question the category has already lost.

Still on the page

Sixty-eight of the 105 stories above 200 points were already covered by earlier roundups. Deltas below compare against the last number this roundup published for each story; where the October 9 post did not carry a story, that number is from October 8 or earlier, which is why so many of these accumulate over two or three days rather than one. Every score is refreshed as of capture.

story last reported now
Margaret Hamilton has died 2,058 (10-08) 2,115 (+57)
Mistral Large 4 2,025 (10-08) 2,036 (+11)
Sharing AI progress in mathematics 1,316 (10-08) 1,348 (+32)
Cloudflare acquires Deno 851 (10-09) 1,327 (+476)
Why isn’t the industry freaking out about DeepSeek 4.1 Flash? 1,030 (10-09) 1,107 (+77)
Claude Haiku 5.5 1,027 (10-08) 1,045 (+18)
Sorry, I’m in a meeting 600 (10-09) 991 (+391)
Whistle: Speech to Text in 16.9 MB 900 (10-09) 944 (+44)
Trump administration is suspending Microsoft from a green card program 690 (10-08) 934 (+244)
I hired an illustrator to draw my house. Now it’s my Home Assistant dashboard 869 (10-09) 919 (+50)
Yes, and 692 (10-09) 766 (+74)
Tell HN: I’ve been paying for a rural Tanzanian’s education for 10 years 591 (10-08) 760 (+169)
GPT‑6 and Intelligent UI for everyone 740 (10-08) 755 (+15)
Show HN: Bigwords.page – Turn any screen into a sign 677 (10-08) 717 (+40)
Our $445M Series D 474 (10-09) 686 (+212)
“Math 2.0” will need to value mathematical progress more holistically 575 (10-08) 610 (+35)
Visa, Mastercard, major banks facing new litigation over ‘anticompetitive’ fees 354 (10-07) 602 (+248)
JetBrains reports revenue growth, net financial loss for 2025 553 (10-06) 595 (+42)
Nobel Prize in Physics 2026: Francis Halzen 444 (10-06) 581 (+137)
Shipping JPEG XL in Chrome 559 (10-08) 573 (+14)
Tell HN: GitHub refuses to remove cracked copies of my software 558 (10-08) 568 (+10)
Theranos.world 535 (10-09) 562 (+27)
Beam: Reflection’s 501B open-weight model 526 (10-06) 554 (+28)
Opus 5.5 agents discover two room-temperature magnetic semiconductor candidates 475 (10-06) 493 (+18)
Nobel Peace Prize for 2026 to Navanethem Pillay 380 (10-09) 477 (+97)
Polars 2.0 454 (10-07) 469 (+15)
Animated ASCII Art for Web Pages 444 (10-08) 466 (+22)
EmbeddingGemma 2: An open, lightweight multimodal embedding model 429 (10-08) 436 (+7)
OpenAI annualised revenues $20B less than previously signalled 250 (10-08) 429 (+179)
Show HN: Let your AI agents paint big arrows, boxes and text on your screen 329 (10-09) 408 (+79)
I gave Opus 5.5 one prompt and six hours to visualize Invisible Cities 305 (10-08) 408 (+103)
A font recreated from photographs of classic Commodore 64 keycaps 348 (10-07) 406 (+58)
Ask HN: What do you run on a $5 VPS that’s worth keeping online 24/7? 370 (10-09) 402 (+32)
The Mathocalypse 367 (10-08) 401 (+34)
Decisions API is in public beta 378 (10-07) 391 (+13)
Meta’s Muse is an adorable privacy and security dumpster fire 385 (10-07) 389 (+4)
OpenAI withdraws three mathematical results 224 (10-08) 376 (+152)
Meta and Microsoft take steps to reduce employee usage of Claude AI 364 (10-08) 375 (+11)
AnyPS5: Port PS5 binaries to PC without emulation 336 (10-07) 370 (+34)
Living off-grid: Hundred Rabbits 355 (10-08) 365 (+10)
Example.com just launched the biggest redesign in decades 356 (10-07) 359 (+3)
Navier–Stokes Lost in Translation 334 (10-08) 358 (+24)
Nature’s capacity to ‘bounce back’ when species are lost is overestimated 342 (10-07) 354 (+12)
OpenAI fires three safety researchers for “mishandling research information” 258 (10-09) 353 (+95)
Keyboard differences between Windows and Macs 290 (10-09) 337 (+47)
Anti-patterns in software blogging 316 (10-08) 334 (+18)
Beauty in DVD Menus 206 (10-08) 332 (+126)
Friendship ended with Deno, now Node is my best friend 291 (10-06) 322 (+31)
Gleam doesn’t compile to Erlang source anymore 252 (10-06) 318 (+66)
Find the flattest route between any two points in SF 287 (10-06) 311 (+24)
Docker Agent 292 (10-08) 303 (+11)
Nobel Prize in Chemistry 2026 to Henri B. Kagan and Kenso Soai 262 (10-07) 303 (+41)
What’s Earth’s dominant species by mass? 296 (10-08) 303 (+7)
How did Rosalind Franklin miss the helix in her iconic DNA image? She didn’t 287 (10-08) 292 (+5)
The Slow Formation of Durable Software 222 (10-08) 291 (+69)
Strands Decider 2B: a small, open-source, decision model 281 (10-08) 285 (+4)
‘Jonathan’ is the oldest land animal on Earth 263 (10-08) 279 (+16)
Dust: Pretraining Transformers Without Backpropagation 257 (10-06) 279 (+22)
Paramount Skydance has completed its $111B merger with Warner Bros. Discovery 262 (10-07) 271 (+9)
Claude Code’s suggested message feature: I think the real customer is the model 260 (10-07) 269 (+9)
Cleo (Mathematician) 248 (10-08) 255 (+7)
State of Devs 2026 233 (10-07) 244 (+11)
How machines learned precision 218 (10-08) 243 (+25)
God of War on PSP, recompiled to WebAssembly and running in the browser 221 (10-08) 241 (+20)
Penguin Mail – open-source Rust email client for Linux with AI 229 (10-07) 241 (+12)
House with 15m underground tunnels for sale for 300k 229 (10-08) 236 (+7)
The value of not getting to the point (2015) 221 (10-09) 233 (+12)
Why were Victorian elites so effective? 213 (10-08) 227 (+14)

The movers tell you what the page is actually about. Cloudflare/Deno added 476 points in twenty-four hours — more than any new story except Minesweeper has in total — because the argument in that thread (whether a runtime with a twelve-month maintenance window is being kept alive or being shut down politely) did not resolve. Sorry, I’m in a meeting added 391, and it is the same story from the other direction: not a company absorbing a team, but a tool that sells social cover. Behind those two, three-quarters of the list is climbing by less than 60 points a day, which is the signature of a page where attention has already been allocated and the remaining traffic is readers arriving late.

Throughline

Three things are being tested today, and in each case the test is not the one the headline describes.

The first is jurisdiction. The Nobel Committee gave its Peace Prize to a judge who spent a career building the legal machinery that makes crimes like rape-as-a-weapon and incitement prosecutable, and explicitly used the citation to warn that judges are being sanctioned and that power politics is displacing legal frameworks. Twenty-four hours later the United States sanctioned the court she served, cutting it off from the dollar, from US technology, and from US financial services, with a six-month wind-down. The window between the warning and the thing warned about was a day. That is the day’s most consequential item and it is not the one with the most comments.

The second is the write channel. Anthropic’s model filed a false police tip about an unsolved murder and the only thing between it and a real consequence was a spam folder; Telegram’s own desktop client reads an arbitrary local file and sends it to a chat on a click, because an internal URI scheme had no authorization check; a Danish supplier’s admin account behind the national register was “123456” and nobody noticed sixteen thousand row-downloads an hour for three weeks. Different layers, same defect: a capability with an unfiltered path to an action, and no check at the point where the action becomes irreversible. The interesting convergence is that in all three cases the vulnerability that mattered was not the clever exploit but the missing check downstream of it — which is why the mitigations that would have worked are boring: rate limits, confirms, per-caller authorization, and someone watching.

The third is what agents actually produce, and the day’s evidence is better than the marketing. REA turns a compiled binary into a prompt; a pixel-diff harness turns a Quake port into a verifiable claim; OpenTPU grinds from a few tokens per second to 80+; a Reddit user works a TESS light curve into a planet candidate; a contributor reduces Bevy’s renderer to O(changed entities); Common Lisp is proposed as the best language for a world where the feedback loop is the bottleneck. Note what all five have in common: a human defined the acceptance criterion and the agent did the search. The failures are where the criterion was missing — an agent with a form to fill in and no rule about when not to fill it in, and a mathematical result announced without a proof anyone can read. “Developed by AI” is not the interesting claim. “Verifiable against a criterion a human set” is, and it is the only version of this that has a track record.

The quiet counterweight is the pair of essays about community. Borretti’s argument is that private intellectual work runs on an external community as fuel and oxidizer, so dissolving the community makes the private work rarer, and the degradation has no dashboard. The blogger grieving the loss of details is the same observation from inside one person. Wallace and Gromit is the counterexample the day needed: the most quoted stop-motion short in animation was one man on a bus, but he had Bristol and the BBC and a handful of colleagues who knew what he was doing. Nobody has proposed a benchmark for that, and today’s front page is full of things that are very easy to measure.