By BY MICHAEL ROSTON from NYT Science https://ift.tt/39wKKDC
Tuesday, December 31, 2019
New top story on Hacker News: Chinese Scientist Accused of Smuggling Samples, Amid Crackdown on Research Theft
Chinese Scientist Accused of Smuggling Samples, Amid Crackdown on Research Theft
6 by jonas21 | 0 comments on Hacker News.
6 by jonas21 | 0 comments on Hacker News.
New top story on Hacker News: Ask HN: How do you responsibly report security bugs to open-source projects?
Ask HN: How do you responsibly report security bugs to open-source projects?
18 by WinonaRyder | 7 comments on Hacker News.
I found a DOS vulnerability in an Open Source project whose maintainer seems to be MIA at the moment. I found it in-the-wild, but not as an exploit so I've only made minimal effort to contact said maintainer - no surprise I haven't gotten a response so far. I don't want to draw any attention to it in a bug report and I'm not sure it's OK to dig up email addresses from commit logs either. It also got me thinking: why don't we have a Bug Bounty-like program for Open Source projects as a whole. What I mean is somewhere where we can post sensitive bugs (even for no pay) and have someone who knows what they're doing guide the process of reporting it responsibly. I know some big projects have this, but e.g. look at the mountain of dependencies that most projects are built on - many of them barely maintained.
18 by WinonaRyder | 7 comments on Hacker News.
I found a DOS vulnerability in an Open Source project whose maintainer seems to be MIA at the moment. I found it in-the-wild, but not as an exploit so I've only made minimal effort to contact said maintainer - no surprise I haven't gotten a response so far. I don't want to draw any attention to it in a bug report and I'm not sure it's OK to dig up email addresses from commit logs either. It also got me thinking: why don't we have a Bug Bounty-like program for Open Source projects as a whole. What I mean is somewhere where we can post sensitive bugs (even for no pay) and have someone who knows what they're doing guide the process of reporting it responsibly. I know some big projects have this, but e.g. look at the mountain of dependencies that most projects are built on - many of them barely maintained.
New top story on Hacker News: Rhasspy is an open source, fully offline voice assistant toolkit
Rhasspy is an open source, fully offline voice assistant toolkit
27 by reedlaw | 2 comments on Hacker News.
27 by reedlaw | 2 comments on Hacker News.
New top story on Hacker News: U.S. Goods Trade Deficit Declines to Smallest in Three Years
U.S. Goods Trade Deficit Declines to Smallest in Three Years
17 by whack | 6 comments on Hacker News.
17 by whack | 6 comments on Hacker News.
New top story on Hacker News: Measuring mutexes, spinlocks and how bad the Linux scheduler is
Measuring mutexes, spinlocks and how bad the Linux scheduler is
28 by bazzargh | 5 comments on Hacker News.
28 by bazzargh | 5 comments on Hacker News.
New top story on Hacker News: Movie Theater in town created by Disney World closed for almost a decade (2018)
Movie Theater in town created by Disney World closed for almost a decade (2018)
12 by bryanrasmussen | 2 comments on Hacker News.
12 by bryanrasmussen | 2 comments on Hacker News.
Monday, December 30, 2019
New top story on Hacker News: The battle to save America’s undercover spies in the digital age
The battle to save America’s undercover spies in the digital age
19 by carrozo | 1 comments on Hacker News.
19 by carrozo | 1 comments on Hacker News.
New top story on Hacker News: The Private and External Costs of Germany's Nuclear Phase-Out
The Private and External Costs of Germany's Nuclear Phase-Out
3 by sampo | 0 comments on Hacker News.
3 by sampo | 0 comments on Hacker News.
New top story on Hacker News: Huawei’s Revenue Hits Record $122B in 2019 Despite U.S. Campaign
Huawei’s Revenue Hits Record $122B in 2019 Despite U.S. Campaign
18 by vo2maxer | 6 comments on Hacker News.
18 by vo2maxer | 6 comments on Hacker News.
New top story on Hacker News: Deep learning approach demonstrates improved accuracy of screening mammography
Deep learning approach demonstrates improved accuracy of screening mammography
41 by rusht | 14 comments on Hacker News.
41 by rusht | 14 comments on Hacker News.
Sunday, December 29, 2019
New top story on Hacker News: The Linux codebase has over 3k TODO comments, many from over a decade ago
The Linux codebase has over 3k TODO comments, many from over a decade ago
11 by patrickdevivo | 1 comments on Hacker News.
11 by patrickdevivo | 1 comments on Hacker News.
New top story on Hacker News: Andrew Taylor: I’m on Medicare, but I still got stuck with a $25k hospital bill
Andrew Taylor: I’m on Medicare, but I still got stuck with a $25k hospital bill
43 by jelliclesfarm | 7 comments on Hacker News.
43 by jelliclesfarm | 7 comments on Hacker News.
New top story on Hacker News: How writing began, and other unexpectedly funny stories about cuneiform [video]
How writing began, and other unexpectedly funny stories about cuneiform [video]
7 by jelliclesfarm | 1 comments on Hacker News.
7 by jelliclesfarm | 1 comments on Hacker News.
New top story on Hacker News: Taking a look at a covert CIA virtual fencing solution [video]
Taking a look at a covert CIA virtual fencing solution [video]
17 by Jerry2 | 0 comments on Hacker News.
17 by Jerry2 | 0 comments on Hacker News.
Saturday, December 28, 2019
New top story on Hacker News: Uncover, Understand, Own – Regaining Control over Your AMD CPU [video]
Uncover, Understand, Own – Regaining Control over Your AMD CPU [video]
10 by DyslexicAtheist | 0 comments on Hacker News.
10 by DyslexicAtheist | 0 comments on Hacker News.