Hacker Newsnew | past | comments | ask | show | jobs | submit | pamcake's commentslogin

By "happened to a lawyer" you mean "was done by a lawyer".

If this is your only blocker you could still use passkeys with a different provider, like KeepassXC?

Not while the spec has provisions to allow sites to mandate certain providers.

The pitch is that passwords will supposedly be phased out entirely as an option.

I've been told by multiple people that the recovery method of passkeys is to enter your username/password. If passwords are eliminated, your final recourse is fucked.

Which is a laudible goal, but something that makes "oh just fall back to the standard insecure recovery process" not a very good response to the concerns about users being able to actually hold on to their passkeys easily and reliably.

"What has science done?!"

With that assertion, every running PC has consciousness and a self-bootstrapping compiler or a debugger attached to itself are sentient?

Doesn't seem meaningful.


> debugger attached to itself are sentient?

No standard debugger is capable of being attached to it's own instance.

Nor does a self-bootstrapping compiler point towards it's own instance.

I think from these two examples I should clarify:

A process that processes itself as an input, is definitionally self-aware.


You would find a mention of that in the initial July incident post from HuggingFace. It looks like it was indeed pretty high up the list.

https://huggingface.co/blog/security-incident-july-2026

> We are working with outside cybersecurity forensic specialists to investigate the issue and review our security policies and procedures. Finally, we have also reported this incident to law enforcement agencies.

Do we expect Nvidia acquisition of HF to have changed the vibe? Note that also the OP is from July, before the acquisition.


> Read the full story here: https://www.effort.news/irregular

That is a better link for the story than the current (alt: https://xxcancel.com/brianchau57/status/2099580981271318606).

It was previously submitted but was quickly flagged out. https://news.ycombinator.com/item?id=49704132


> Note that even OS kernels can have this issue - imagine what happens in virtualized environments with overcommitted physical CPU's scheduled by a hypervisor as virtual CPU's? Yeah - exactly. Don't do that. Or at least be aware of it, and have some virtualization-aware paravirtualized spinlock so that you can tell the hypervisor that "hey, don't do that to me right now, I'm in a critical region".

I can't be the only one who learned this the hard way by cramming too many vCPUs onto too few physical cores and initially wondering where the high load and latencies came from.


From a business perspective, Amazon was/is a legit business threat to ~every physical bookstore (and, arguably, many publishers). It doesn't follow that they could take Amazon to court for that.

Of more concern, the Nitter github repository was permanently archived a couple of days ago.

https://github.com/zedeus/nitter


On that same page:

UPDATE: Following legal advice, the Nitter project will continue. More details will be announced soon.


That update was made 9/6: 5 days prior to archival and on the same day xcancel.com previously also "returned". I can find no public updates regarding Nitter project after the 9/11 archival.

The repo being archived happened after that UPDATE post that you mention. So the project has gone from suspended, to un-suspended, and now it's suspended again (and the repo got archived this time).

Edit: I see I'm being downvoted for just providing facts, so here's some evidence: you can see on the main project page that the repo was archived on 11 Sep[0]. Looking in the commits, the "UPDATE" message was commited on 6 Sep[1].

[0] https://github.com/zedeus/nitter

[1] https://github.com/zedeus/nitter/commit/1428b4c2b4246f92a7e5...


> Following legal advice

It's impossible to know what this "legal advice" was, but the software project itself is probably fine. The legal risk is always going to be with the person that hosts it with the intention of facilitating the unauthorized access of Twitter's website. Seems like that could run afoul of the Computer Fraud and Abuse Act.

Those people should seek their own legal advice.


In cases like these, companies often try to go after the upstream project, not just operators. The law gives them lots of tools for this: the CFAA has a conspiracy provision; The DMCA has a provision against making software for circumventing copyright; Trademark law might make the name nitter or xcancel illegal; and finally even if the claims are weak the litigation itself is an enormous burden

I imagine it will be hosted in jurisdictions other than the US.

> Computer Fraud and Abuse Act

Meanwhile it's OK for OpenAI, Anthropic and Meta to hack companies all willy-nilly. Mad world!


It's about risk tolerance. Some people stop when there's a hint of legal trouble. Others keep going when there's nothing more to lose.

> permanently archived

Why do you say it’s permanent? Unarchiving a GitHub repository is reversible, and just as easy as archiving it.


Zedeus said "it's hopefully temporary, but it'll remain that way until further notice." in the matrix room

Development still continues by others: https://codeberg.org/mv12star/shitter

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: