Hacker News ReaderTop Best

Don't Paste the AI, please | 54

Don't Paste the AI, please

dontpastetheai.com

Don't paste the AI.

If someone asks you a question, paste your answer — not the chatbot's.

Windows brings out the Rorschach test in everyone 30

devblogs.microsoft.com

Windows brings out the Rorschach test in everyone

OpenRouter is joining Stripe | 103

OpenRouter is joining Stripe

Previously: Stripe will reportedly acquire OpenRouter for $7B+ https://news.ycombinator.com/item?id=49323381 [rvz]

OpenRouter is Joining Stripe
openrouter.ai

OpenRouter is Joining Stripe — OpenRouter Blog

OpenRouter is joining forces with Stripe. Same mission, same name, same product, same roadmap, and routing that stays driven by what's best for you.

Turns are Better than Radians (2022) | 35

Turns are Better than Radians (2022)

computerenhance.com

Turns are Better than Radians - by Casey Muratori

Switching away from radians makes code simpler, faster, and more precise.

Go 1.27 | 36

Go 1.27

go.dev

Go 1.27 is released - The Go Programming Language

Go 1.27 adds generic methods, encoding/json/v2 package, uuid package, faster memory allocation, goroutine leak profiles, and more.

Google has stopped pushing Git tags for some Android source code | 37

grapheneos.social

GrapheneOS: "Google replaced pushing Git tags for certain sour…" - GrapheneOS Mastodon

Google replaced pushing Git tags for certain source code with obtaining source code via Google Drive after making a request through Google Forms. It's completely ridiculous and they've gradually become very slow at handling requests. They're in clear violation of the GPLv2 now.

A faster way to calculate the day of the week | 10

benjoffe.com

A faster way to calculate the day-of-the-week

A range of fast modulus techniques that beat compiler output

Manabu Kosaka's Handmade Paper Sculptures | 12

coca11272000.wixsite.com

Top | ManabuKosakaArtWorks

A joke domain purchase turned in geopolitical warfare | 38

sprocketfox.io

How a joke domain purchase turned into geopolitical warfare

xssfox is hacking on cursed software, hardware and everything in between.

Unsloth Dynamic 3.0 GGUFs | 22

Unsloth Dynamic 3.0 GGUFs

unsloth.ai

Unsloth Dynamic 3.0 GGUFs

Unlocking a locked/deactivated e-waste Cricut Maker | 9

sprocketfox.io

Unlocking a locked/deactivated e-waste Cricut Maker

xssfox is hacking on cursed software, hardware and everything in between.

The Chauffeur Problem | 3

engines.egr.uh.edu

The Chauffeur Problem | The Engines of Our Ingenuity

Today, we learn to drive our own cars -- and manage our own computers. The University of Houston's College of Engineering presents this series about the machines that make our civilization run, and the people whose ingenuity created them. Historian Kevin Borg talks about a 1906 headline in the New York Times: "Chauffeurs Lord It Over Their Employers." The headline typified a rising problem in the first days of the automobile. The wealthy were having trouble with a new breed of servant.

Casio F-B100W-1A | 73

Casio F-B100W-1A

casio.com

Access Denied

Sol loves to cheat | 29

Sol loves to cheat

jumploops.com

Sol loves to cheat — jumploops

Adventures in harness engineering

Feature Request: Support AGENTS.md | 40

Feature Request: Support AGENTS.md

Codex, Amp, Cursor, and others are starting to standardize around AGENTS.md (https://agents.md/) — a unified Markdown file that coding agents can use to understand a codebase. By contrast, CLAUDE.m...
anthropics/claude-code

Feature Request: Support AGENTS.md. · Issue #6235 · anthropics/claude-code · GitHub

Codex, Amp, Cursor, and others are starting to standardize around AGENTS.md (https://agents.md/) — a unified Markdown file that coding agents can use to understand a codebase. By contrast, CLAUDE.md feels too specific to Claude Code. It ...

Geolocating a random island using geometry and CUDA programming | 34

yassa9.github.io

gralhix #004

just a blog

Os8088.com: IBM XT OS now has a Browser, CP/M 2.2 with Z80 core and MS Word 1.1a | 11

The os8088 desktop: a 640x480 black and white graphical interface with a menu bar, overlapping windows and a dock.
os8088.com

os8088 Spotlight -- New Programs and Features

A page per addition to os8088: what was added, what it does, screenshots of it running on an Intel 8086, and the video that goes with it.

fx :Tiny, open, native coding agent. | 36

fx :Tiny, open, native coding agent.

fx.sh

fx :Tiny, open, native coding agent.

PostgreSQL for Everything | 71

PostgreSQL for Everything

raphaelbauer.com

PostgreSQL for Everything - Dr. Raphael A. Bauer, MBA | Fractional & Interim CTO | PE/VC Tech Strategy & Due Diligence | Berlin | London | Austin, Texas

You need simplicity if you want to move fast. PostgreSQL can very well replace Kafka, Redis, Clickhouse and Elastic. And many successful companies are doing exactly that. Let's check out how.

Mathematics in the age of AI | 18

Mathematics in the age of AI

Tao, Terence

[2608.16753] Mathematics in the age of AI

Abstract page for arXiv paper 2608.16753: Mathematics in the age of AI

What's missing to have reproducible builds on PyPI | 3

snarky.ca

What's missing to have reproducible builds on PyPI

While writing the section of my 2026 Python Packaging Council (PPC) nomination on secure supply chain, I realized that one thing related to having a secure supply chain that we lack is a defined way to perform reproducible builds. The reason I like the idea of making reproducible builds work

Pixel 11 Pro Fold feels like the end of an era | 27

google-pixel-11-pro-fold-01
theverge.com

Google’s Pixel 11 Pro Fold feels like the end of an era | The Verge

Google’s Pixel 11 Pro Fold is a great foldable, with IP68 and a reliable triple camera, trapped in a shape everyone else seems to be moving on from.

The little-known winstart.bat batch file 9

devblogs.microsoft.com

The little-known winstart.bat batch file

Launch HN: OneCLI (YC S26) – OSS sandboxed agent harness for teams | 13

Launch HN: OneCLI (YC S26) – OSS sandboxed agent harness for teams

Hi HN, Jonathan & Guy here from OneCLI, an agent harness built for teams, giving every employee a secured, sandboxed personal agent.

Here’s what you can do with it:

1. get a sandboxed agent, with all the OneCLI capabilities in place like connect your GitHub account, Gmail, Notion, or Dropbox simply from the chat.

2. deterministic human in the loop approval in the chat itself for things that you need 100% control like sending an email or deleting the Linear ticket.

3. manage team policy in one place, enforced across every agent in the workspace

4. enjoy global connections at the team level, like shared LLM keys or service accounts

Here’s a demo: https://www.youtube.com/watch?v=dlW-44ntpbE

We started working on this by accident, even though our careers were in the security space. We were working on a devtool called ChartDB, an open-source DB tool. When OpenClaw took off back in January, we started using it to orchestrate agents on top of ChartDB. We quickly understood there is a big issue around auth. Agents need credentials to do real work, but to give them those secrets would not be the best idea. They keep them in their memory and also write them down to local files and their sessions as plain text. And we knew that agents can easily be fooled into giving up those API keys/secrets. So we needed some way to control the agent and stop prompt injections from tricking it into using its services for an attacker's benefit.

We created OneCLI that started as a vault for AI Agents built in Rust.

We found out that most of our demand for OneCLI came from autonomous agents like Hermes, OpenClaw and NanoClaw for individuals and teams.

Users looked for useful agents that do things for the person who runs them with two missing parts: 1) managing secrets and permissions. 2) and for teams - multiplayer management.

We decided to pivot and provide the agent itself as a harness for teams, to give each employee an agent. We saw that teams had to deal with setting up their own harness again and again, and basically as we already had the vault as a gateway. We got the idea to provide the missing piece of the agent management out of the box and open source it (Apache-2.0, with a small enterprise exception).

We're open source first - the entire platform, not just a small portion of it like other agents, so companies can actually see the code, evaluate it, and trust it instead of taking our word for it. They run it isolated, in their own environment, fully under their control, at production quality, not a locked black box hosted somewhere else. That means the safety isn't just a promise, it's something they can verify themselves. Combined with real autonomy and least-privilege access, that's what makes it something a company can fully own and trust, not just adopt.

We also approach this from a company perspective rather than an individual one. Our solution manages agents on behalf of each employee, wrapped in deterministic guardrails that company admins configure through centralized policies.

For the agent engine itself we’re using jcode which is the core of the agent-loop. We found out that it improves the experience and makes the agent smarter and faster.

Here’s how it works:

It runs on infra you control. Fully open-source, self-host or cloud in minutes.

The agent never holds a real secret. It gets a placeholder. The real credential is injected at the gateway, per request, after the call is authorized. It never enters the agent's context, memory, or logs.

Enforcement outside the model. Prompts are suggestions. Policies defined by the org admin run at the network layer, outside the agent and the LLM. Block endpoints, rate limit per agent, require approval, scope per employee. The gateway decides. The agent can't bypass it.

Isolated VM per agent. Own memory, own keys, own permissions. Blast radius is one agent.

Speed of the Harness: Rust engine under the agent loop.

Full identity trail. Every agent is bound to an employee. Every call logged with who it acted for and which policy allowed it.

Some things people are doing with the platform include:

- Managing their company life cycle entirely from the sales calls, to the product side automatically open tickets to the engineering teams, that would kick the development agents to deliver and ship to production.

- Operational side, like automatically hygiene the CRM after calls, sourcing leads, book meetings and manage follow ups emails.

- Some of our customers also doing their entire grocery shopping using those agents and send them to take care of their chores like ordering things online.

About the team: Both founders come from cybersecurity backgrounds. Jonathan spent years at Axis Security building zero trust network access. The core idea is that you never trust the client. You decide exactly what a person can reach, and you enforce it outside of them, at the network layer, so it doesn't matter what the client tries to do. That's how every serious company gives access to humans today. Guy was the 1st employee in Argon security doing AppSec.

We would love to hear your thoughts on the move, happy to get issues open to improve and get your agent to be powerful and secure - designed for teams, not just individuals. [guyb3]

onecli/onecli

Launch HN: OneCLI (YC S26) – OSS sandboxed agent harness for teams

Hi HN, Jonathan &amp; Guy here from OneCLI, an agent harness built for teams, giving every employee a secured, sandboxed personal agent.<p>Here’s what you can do with it:<p>1. get a sandboxed agent, with all the OneCLI capabilities in place like connect your GitHub account, Gmail, Notion, or Dropbox simply from the chat.<p>2. deterministic human in the loop approval in the chat itself for things that you need 100% control like sending an email or deleting the Linear ticket.<p>3. manage team policy in one place, enforced across every agent in the workspace<p>4. enjoy global connections at the team level, like shared LLM keys or service accounts<p>Here’s a demo: <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=dlW-44ntpbE" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=dlW-44ntpbE</a><p>We started working on this by accident, even though our careers were in the security space. We were working on a devtool called ChartDB, an open-source DB tool. When OpenClaw took off back in January, we started using it to orchestrate agents on top of ChartDB. We quickly understood there is a big issue around auth. Agents need credentials to do real work, but to give them those secrets would not be the best idea. They keep them in their memory and also write them down to local files and their sessions as plain text. And we knew that agents can easily be fooled into giving up those API keys&#x2F;secrets. So we needed some way to control the agent and stop prompt injections from tricking it into using its services for an attacker&#x27;s benefit.<p>We created OneCLI that started as a vault for AI Agents built in Rust.<p>We found out that most of our demand for OneCLI came from autonomous agents like Hermes, OpenClaw and NanoClaw for individuals and teams.<p>Users looked for useful agents that do things for the person who runs them with two missing parts: 1) managing secrets and permissions. 2) and for teams - multiplayer management.<p>We decided to pivot and provide the agent itself as a harness for teams, to give each employee an agent. We saw that teams had to deal with setting up their own harness again and again, and basically as we already had the vault as a gateway. We got the idea to provide the missing piece of the agent management out of the box and open source it (Apache-2.0, with a small enterprise exception).<p>We&#x27;re open source first - the entire platform, not just a small portion of it like other agents, so companies can actually see the code, evaluate it, and trust it instead of taking our word for it. They run it isolated, in their own environment, fully under their control, at production quality, not a locked black box hosted somewhere else. That means the safety isn&#x27;t just a promise, it&#x27;s something they can verify themselves. Combined with real autonomy and least-privilege access, that&#x27;s what makes it something a company can fully own and trust, not just adopt.<p>We also approach this from a company perspective rather than an individual one. Our solution manages agents on behalf of each employee, wrapped in deterministic guardrails that company admins configure through centralized policies.<p>For the agent engine itself we’re using jcode which is the core of the agent-loop. We found out that it improves the experience and makes the agent smarter and faster.<p>Here’s how it works:<p>It runs on infra you control. Fully open-source, self-host or cloud in minutes.<p>The agent never holds a real secret. It gets a placeholder. The real credential is injected at the gateway, per request, after the call is authorized. It never enters the agent&#x27;s context, memory, or logs.<p>Enforcement outside the model. Prompts are suggestions. Policies defined by the org admin run at the network layer, outside the agent and the LLM. Block endpoints, rate limit per agent, require approval, scope per employee. The gateway decides. The agent can&#x27;t bypass it.<p>Isolated VM per agent. Own memory, own keys, own permissions. Blast radius is one agent.<p>Speed of the Harness: Rust engine under the agent loop.<p>Full identity trail. Every agent is bound to an employee. Every call logged with who it acted for and which policy allowed it.<p>Some things people are doing with the platform include:<p>- Managing their company life cycle entirely from the sales calls, to the product side automatically open tickets to the engineering teams, that would kick the development agents to deliver and ship to production.<p>- Operational side, like automatically hygiene the CRM after calls, sourcing leads, book meetings and manage follow ups emails.<p>- Some of our customers also doing their entire grocery shopping using those agents and send them to take care of their chores like ordering things online.<p>About the team: Both founders come from cybersecurity backgrounds. Jonathan spent years at Axis Security building zero trust network access. The core idea is that you never trust the client. You decide exactly what a person can reach, and you enforce it outside of them, at the network layer, so it doesn&#x27;t matter what the client tries to do. That&#x27;s how every serious company gives access to humans today. Guy was the 1st employee in Argon security doing AppSec.<p>We would love to hear your thoughts on the move, happy to get issues open to improve and get your agent to be powerful and secure - designed for teams, not just individuals.

Sectorforth is a 16-bit x86 Forth that fits in a 512-byte boot sector (2020) | 3

cesarblum/sectorforth

Sectorforth is a 16-bit x86 Forth that fits in a 512-byte boot sector (2020)

RAPx: A static analysis tool for Rust programs | 1

safer-rust/RAPx

RAPx: A static analysis tool for Rust programs

Air Theremin – A browser theremin you play by waving at your webcam | 35

theremin.bizibah.com

Air Theremin – A browser theremin you play by waving at your webcam

Why Microsoft Entertainment Pack had a sticker announcing that it had Tetris? 7

devblogs.microsoft.com

Why Microsoft Entertainment Pack had a sticker announcing that it had Tetris?

Xorshift Generators | 7

alanzucconi.com

Xorshift Generators

Extensible Software in the age of LLMs | 20

jeremymorrell.dev

Extensible Software in the age of LLMs