Feed aggregator
How the pro-nicotine 'wellness' movement rebranded an addictive drug
Article URL: https://theconversation.com/how-the-pro-nicotine-wellness-movement-rebranded-an-addictive-drug-290129
Comments URL: https://news.ycombinator.com/item?id=49822024
Points: 1
# Comments: 0
Empire of Grift
Article URL: https://www.theatlantic.com/magazine/2026/10/maga-foreign-policy/688352/
Comments URL: https://news.ycombinator.com/item?id=49822018
Points: 4
# Comments: 0
CP/M-80 2.2 Compilers. (Update from June 19, 2026: Dave Glover – by David Lee
Article URL: https://medium.com/@davidly_33504/cp-m-80-2-2-compilers-91958a8f1d58
Comments URL: https://news.ycombinator.com/item?id=49822011
Points: 1
# Comments: 0
Signature 27 is likely Motorola's first smartphone with GrapheneOS support
Article URL: https://www.heise.de/en/news/Signature-27-is-likely-Motorola-s-first-smartphone-with-GrapheneOS-support-11462875.html
Comments URL: https://news.ycombinator.com/item?id=49822006
Points: 1
# Comments: 0
Ten thousand magnets later – CERN Courier
Article URL: https://cerncourier.com/ten-thousand-magnets-later/
Comments URL: https://news.ycombinator.com/item?id=49822001
Points: 1
# Comments: 0
Developers Song (2011) [video]
Article URL: https://www.youtube.com/watch?v=RwMvW9cAIZg
Comments URL: https://news.ycombinator.com/item?id=49821999
Points: 1
# Comments: 0
IonQ Targets Quantum Error-Correction Bottleneck With Single-CPU DecoderIonQ Says Sin
IonQ’s new single processor quantum error decoder minimizes the classical computing overhead in quantum error correction.
The post IonQ Targets Quantum Error-Correction Bottleneck With Single-CPU DecoderIonQ Says Sin appeared first on SecurityWeek.
How device code phishing gives scammers access to your account
You receive an invitation to a password-protected meeting, a secure chatroom, or a shared document. To get access, it says, you need to enter a short code on a sign-in page for one of your accounts.
The message claims the code will let you open the document or join the meeting. In fact, it approves a sign-in the scammer started.
The page is real and the code works, which is why this type of attack—known as device code phishing—is so dangerous.
Device code phishing abuses a legitimate sign-in feature intended for devices that cannot easily display a normal login screen (such as smart TVs, printers, conference-room equipment, and some command-line tools). Instead of entering a username and password on the device itself, you open a browser on another device, visit a sign-in page, enter a short code, and approve the sign-in. This allows the app or device that displayed the code to access your account.
In this phishing attack, the scammer starts the sign-in and gets you to enter the code and approve the request. That can give the scammer access to your account.
How device code phishing worksDevice code phishing relies on the OAuth 2.0 Device Authorization Grant, a standard sign-in method for devices with no browser or limited input.
An attack generally follows these steps:
- An attacker starts a legitimate device code sign-in request for an app or device they control.
- The sign-in service generates a short, temporary code and a legitimate verification page.
- The attacker uses social engineering, such as a fake Teams invite, a document-sharing request, or an invitation to join a “secure” chat, to pass that code to the victim.
- The victim visits the genuine sign-in page, enters the code, and approves the request.
- The attacker’s waiting device receives authentication tokens.
Those tokens act as digital passes, allowing the attacker to access the victim’s account without knowing their password.
What the attacker can access depends on the app and the permissions granted. It could be limited to one service, or include email, files, contacts, and other services. Multifactor authentication (MFA) doesn’t necessarily stop this attack, because the victim may complete the MFA check themselves while authorizing the attacker’s sign-in.
Checking the address alone will not reveal this as a scam because it’s a legitimate page. For example, in an attack targeting a Microsoft account the victim may be sent to a genuine Microsoft sign-in page, such as microsoft.com/devicelogin. Some approval screens identify the app requesting access, but others may not.
The key question to ask yourself here is: Did this code appear in an app or on a device I was trying to sign in to, or was I given it to open a document, join a meeting, or pass a security check?
How to stay safeDevice code phishing is a feature of phishing kits such as EvilTokens. Be cautious if an unexpected message asks you to:
- Enter a code on an account sign-in page.
- Approve a sign-in for a device or application you did not set up.
- Use a sign-in code to join a meeting, access a document, or enter a chatroom.
- Act urgently because an invitation, document, password, or account supposedly expires soon.
- Move a conversation to another messaging app and complete a “security check.”
If you entered the code and approved the sign-in, check the account’s recent activity, connected apps, and devices for anything you don’t recognize. Sign out everywhere and change your password.
Pro tip: Use the free Malwarebytes Scam Guard to help you assess a suspicious message and decide what to do next.
Something feel off? Check it before you click.Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.
Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.
Small Modular Reactors: a short history of a nuclear pipe dream
Article URL: https://engelsbergideas.com/essays/smrs-a-short-history-of-a-nuclear-pipe-dream/
Comments URL: https://news.ycombinator.com/item?id=49820512
Points: 1
# Comments: 0
LensVLM: Compressing long context as images, expanding only relevant pages
Article URL: https://huggingface.co/apple/LensVLM-9B
Comments URL: https://news.ycombinator.com/item?id=49820496
Points: 1
# Comments: 0
Ask HN: Do you offload your coding to AI, or keep your skills sharp?
I used to be a software engineer, but these days I find myself being more of an agents manager: constantly switching between 3-4 tasks that my agents are working on, and making sure that the features get shipped, the bugs fixed, with correct and clean code. There's no doubt that I'm producing more value for the company, but I wonder if that's the best I can do for myself if the goal is staying relevant in the coming years.
I wonder: if the AI is writing all the code, what value am I bringing?
In an attempt to keep my critical thinking and coding skills sharp, I sometimes foolishly try to debug errors or implement a feature myself. But it feels like wasting time when an agent can do it in a fraction of time.
What is gonna be sought after in the coming years: someone that persevered with manual coding and debugging but is slow and uncomfortable around agents, or someone that has little coding and debugging skills left but knows how to orchestrate dozens of agents effectively?
I'm curious to hear what other software engineers on HN's approach is.
Comments URL: https://news.ycombinator.com/item?id=49820486
Points: 1
# Comments: 0
Can internal model transparency tame the AI race?
Article URL: https://blog.karthiktadepalli.com/p/internal-model-transparency
Comments URL: https://news.ycombinator.com/item?id=49820480
Points: 1
# Comments: 0
The meta-harness for coding agents
Article URL: https://soloterm.com/
Comments URL: https://news.ycombinator.com/item?id=49820466
Points: 1
# Comments: 0
Show HN: Jev-mice – mouse colony simulation using Jev and deterministic engine
I built this as a "hello world" for exploring TypeSafe Jev as an alternative to local classifiers. There's a link to the detailed design write-up on the demo page, and that write-up in turn has a link to the repo. I formed some opinions on Jev from this exercise, and am interested in others' perspectives. And am sharing this in the hope it might be useful to someone else.
Comments URL: https://news.ycombinator.com/item?id=49820452
Points: 1
# Comments: 0
Discover Solo: The Ultimate AI-Integrated Control Panel
Article URL: https://blog.master.dev/introducing-solo/
Comments URL: https://news.ycombinator.com/item?id=49820421
Points: 1
# Comments: 0
Steam Frame Teardown
Article URL: https://www.ifixit.com/News/119488/steam-frame-teardown-were-fans-except-of-the-fan
Comments URL: https://news.ycombinator.com/item?id=49820411
Points: 1
# Comments: 0
SpaceX Starshield
Article URL: https://en.wikipedia.org/wiki/SpaceX_Starshield
Comments URL: https://news.ycombinator.com/item?id=49820401
Points: 1
# Comments: 0
Mexican Navy's tall ship Cuauhtémoc will be at the Embarcadero all week
Article URL: https://www.kqed.org/news/12101113/tall-ship-san-francisco-mexican-navy-cuauhtemoc-free-public-tours
Comments URL: https://news.ycombinator.com/item?id=49820396
Points: 1
# Comments: 0
A Worthwhile Trade
Article URL: https://voices.nejm.org/doi/full/10.1056/VOICESpost2600056?referrer=https://t.co/
Comments URL: https://news.ycombinator.com/item?id=49820377
Points: 2
# Comments: 0
Loopjacking in A2A Implementations: Hijacking Human-in-the-Loop Approvals
Article URL: https://adithyanak.com/loopjacking-in-a2a-implementations/
Comments URL: https://news.ycombinator.com/item?id=49820349
Points: 1
# Comments: 0
