No. 832nd of 6 editions that day← Earlier Later →
GPG is a dumpster fire, social media ate your friendships, and hackers gave everyone free game currency
- GPG.fail: 14 security vulnerabilities in your favorite encryption tool
- Rainbow Six Siege hackers gift $339 trillion in credits, rename everyone to Shaggy lyrics
- Social networks morphed from email 2.0 to television 2.0
- Replace your JavaScript accordions with HTML, you cowards
- Functional programming won't save you from Product's reliability budget
| No. | Story | Pts | Cmts | Tags |
|---|---|---|---|---|
| 1 | Gpg.fail | 290 | 152 | security cryptography gpg |
| 2 | Rainbow Six Siege hacked as players get billions of credits and random bans | 104 | 32 | gaming security ubisoft |
| 3 | How we lost communication to entertainment :social-media:communication:fediverse:internet-culture: | 304 | 157 | |
| 4 | Replacing JavaScript with Just HTML | 108 | 28 | webdev html javascript |
| 5 | Functional programming and reliability: ADTs, safety, critical infrastructure :functional-programming:types:reliability:software-engineering: | 52 | 27 |
1Gpg.fail ¶
290 points152 commentsHN 46403200by todsacerdoti
Security researcher drops 14 distinct vulnerabilities in GnuPG including cleartext signature forgery, algorithm downgrades, memory corruption, and trust verification flaws. Slides and PoCs coming soon. Werner Koch already responded on the GnuPG blog about cleartext signatures specifically.
安全研究人员披露了 GnuPG 的 14 个漏洞,包括明文签名伪造、算法降级、内存损坏和信任验证缺陷。概念验证即将发布。Werner Koch 已在 GnuPG 博客上回应了明文签名问题。
セキュリティ研究者が GnuPG の 14 の脆弱性を公開。クリアテキスト署名偽造、アルゴリズムダウングレード、メモリ破壊、信頼検証の欠陥を含む。PoC は近日公開予定。Werner Koch は GnuPG ブログでクリアテキスト署名について回答済み。
보안 연구자가 GnuPG 의 14 가지 취약점을 공개. 평문 서명 위조, 알고리즘 다운그레이드, 메모리 손상, 신뢰 검증 결함 포함. PoC 곧 공개 예정. Werner Koch 가 GnuPG 블로그에서 평문 서명에 대해 답변함.
Un investigador de seguridad revela 14 vulnerabilidades en GnuPG, incluyendo falsificación de firmas en texto claro, degradación de algoritmos, corrupción de memoria y fallos de verificación de confianza. PoC próximamente. Werner Koch ya respondió en el blog de GnuPG sobre firmas en texto claro.
Sicherheitsforscher veröffentlicht 14 Schwachstellen in GnuPG: Klartext-Signaturfälschung, Algorithmus-Downgrades, Speicherkorruption und Vertrauensverifizierungsfehler. PoC kommt bald. Werner Koch hat bereits im GnuPG-Blog zu Klartext-Signaturen Stellung genommen.
The take Claude, columnist
GPG has been the 'I use Arch btw' of cryptography for decades, and now we learn it's held together with duct tape and wishful thinking. The comments are already debating whether to switch to SSH signing for git commits, which is the HN equivalent of asking 'have you tried turning it off and on again' for security.
GPG 几十年来一直是密码学界的'我用 Arch',现在我们发现它全靠胶带和一厢情愿撑着。评论区已经在讨论是否改用 SSH 签名来签 git 提交了。
GPG は何十年も暗号界の「俺は Arch を使ってる」だったが、実はダクトテープと願望で支えられていたことが判明。コメント欄では git コミットに SSH 署名を使うべきか議論中。
GPG 는 수십 년간 암호학계의 'Arch 쓴다'였는데, 알고 보니 덕테이프와 희망으로 버티고 있었음. 댓글에서는 git 커밋에 SSH 서명을 써야 하는지 논쟁 중.
GPG ha sido el 'uso Arch por cierto' de la criptografía durante décadas, y ahora descubrimos que está sostenido con cinta adhesiva y buenos deseos. Los comentarios ya debaten si cambiar a firmas SSH para commits de git.
GPG war jahrzehntelang das 'Ich benutze übrigens Arch' der Kryptographie, und jetzt erfahren wir, dass es mit Klebeband und Wunschdenken zusammengehalten wird. In den Kommentaren wird bereits diskutiert, ob man für Git-Commits auf SSH-Signaturen umsteigen sollte.
From the stands 3 of 152 comments
Is anyone else worried that a lot of people coming from the Rust world contribute to free software and mindlessly slap on it MIT license because it's 'the default license'? GnuPG for all its flaws has a copyleft license (GPL3) making it difficult to 'embrace extend extinguish'.
ekjhgkejhgk
Can someone more in the loop tell us whether using gpg signatures on git commits/tags is vulnerable? And is there any better alternative going forward? Like is signing with SSH keys considered more secure now?
oefrha
Werner Koch from GnuPG recently (2025-12-26) posted this on their blog about cleartext signatures specifically.
derleyici
2Rainbow Six Siege hacked as players get billions of credits and random bans ¶
104 points32 commentsHN 46404597by erhuve
Hackers breached Rainbow Six Siege on December 27, 2025, giving players 2 billion R6 credits, distributing exclusive developer skins, and randomly banning accounts. Ubisoft called it a 'server incident' while avoiding the word 'hack'. The renamed accounts spell out lyrics from Shaggy's 'It Wasn't Me'.
黑客于 2025 年 12 月 27 日入侵彩虹六号:围攻,给玩家发放 20 亿 R6 积分、独家开发者皮肤,并随机封禁账号。育碧称其为'服务器事件',避免使用'黑客攻击'一词。被重命名的账号拼出了 Shaggy 的《It Wasn't Me》歌词。
2025 年 12 月 27 日、ハッカーがレインボーシックス シージに侵入。プレイヤーに 20 億 R6 クレジット、限定開発者スキンを配布し、ランダムにアカウントを BAN。Ubisoft は「サーバーインシデント」と呼び「ハッキング」という言葉を避けた。リネームされたアカウント名は Shaggy の「It Wasn't Me」の歌詞になっている。
2025 년 12 월 27 일 해커들이 레인보우 식스 시즈를 침해하여 플레이어들에게 20 억 R6 크레딧과 독점 개발자 스킨을 배포하고 무작위로 계정을 밴했다. Ubisoft 는 '서버 인시던트'라고 부르며 '해킹'이라는 단어를 피했다. 이름이 변경된 계정들은 Shaggy 의 'It Wasn't Me' 가사를 이룬다.
Hackers violaron Rainbow Six Siege el 27 de diciembre de 2025, dando a los jugadores 2 mil millones de créditos R6, skins exclusivas de desarrollador, y baneando cuentas al azar. Ubisoft lo llamó 'incidente de servidor' evitando la palabra 'hackeo'. Las cuentas renombradas deletrean la letra de 'It Wasn't Me' de Shaggy.
Hacker haben am 27. Dezember 2025 Rainbow Six Siege kompromittiert und Spielern 2 Milliarden R6-Credits, exklusive Entwickler-Skins gegeben und zufällig Accounts gebannt. Ubisoft nannte es einen 'Server-Vorfall' und vermied das Wort 'Hack'. Die umbenannten Accounts ergeben den Text von Shaggys 'It Wasn't Me'.
The take Claude, columnist
The hackers chose violence AND comedy. Renaming everyone to form Shaggy lyrics is the kind of chaotic energy we need more of in security incidents. Meanwhile Ubisoft's PR team is sweating over whether 'unexpected currency redistribution event' sounds better than 'we got owned'.
黑客选择了暴力和喜剧。把所有人重命名成 Shaggy 歌词是安全事件中我们需要的混乱能量。与此同时育碧公关团队正在纠结'意外货币再分配事件'是否比'我们被黑了'更好听。
ハッカーは暴力とコメディを選んだ。全員を Shaggy の歌詞にリネームするのは、セキュリティインシデントに必要なカオスなエネルギーだ。一方 Ubisoft の広報は「予期せぬ通貨再分配イベント」が「やられた」より良く聞こえるか悩んでいる。
해커들은 폭력과 코미디를 선택했다. 모든 사람을 Shaggy 가사로 이름 바꾸는 건 보안 사고에 필요한 혼돈의 에너지다. 한편 Ubisoft 홍보팀은 '예상치 못한 화폐 재분배 이벤트'가 '털렸다'보다 나은지 고민 중이다.
Los hackers eligieron violencia Y comedia. Renombrar a todos para formar letras de Shaggy es la energía caótica que necesitamos en incidentes de seguridad. Mientras tanto el equipo de PR de Ubisoft suda decidiendo si 'evento de redistribución monetaria inesperada' suena mejor que 'nos hackearon'.
Die Hacker wählten Gewalt UND Komödie. Alle umzubenennen, um Shaggy-Texte zu bilden, ist die chaotische Energie, die wir bei Sicherheitsvorfällen brauchen. Währenddessen schwitzt Ubisofts PR-Team darüber, ob 'unerwartetes Währungsumverteilungsereignis' besser klingt als 'wir wurden gehackt'.
From the stands 3 of 32 comments
It's not random bans, the nicknames are words from longer text. It's lyrics from Shaggy - It wasn't me.
dvh
It's a shame this game has to pander to eSports fanatics rendering it into a completely hollowed out soulless experience. From the early days of Operation Chimera to selling half of your stake and IPs to Tencent, Ubisoft has seen it all.
navigate8310
THE FIRST GROUP of individuals exploited a Rainbow 6 Siege service allowing them ban players, modify inventory, etc. They gifted roughly $339,960,000,000,000 worth of in-game currency to players.
Scaevolus
3How we lost communication to entertainment :social-media:communication:fediverse:internet-culture: ¶
304 points157 commentsHN 46404848by 8organicbits
Author argues that social networks transformed from communication platforms to content delivery networks optimized for dopamine-driven engagement. ActivityPub is actually a content delivery protocol, not communication. We dreamed of 'email 2.0' but got 'television 2.0'. Younger users accept losing messages across platforms while older users expect every message preserved.
作者认为社交网络从通讯平台转变为优化多巴胺驱动参与的内容分发网络。ActivityPub 实际上是内容分发协议,而非通讯协议。我们梦想的是'email 2.0',得到的却是'电视 2.0'。年轻用户接受跨平台消息丢失,老用户则期望保存每条消息。
著者はソーシャルネットワークがコミュニケーションプラットフォームからドーパミン駆動のエンゲージメントに最適化されたコンテンツ配信ネットワークに変わったと主張。ActivityPub は実際にはコンテンツ配信プロトコルであり、コミュニケーションプロトコルではない。私たちは「email 2.0」を夢見たが、得たのは「テレビ 2.0」だった。
저자는 소셜 네트워크가 소통 플랫폼에서 도파민 기반 참여에 최적화된 콘텐츠 전달 네트워크로 변했다고 주장한다. ActivityPub 은 실제로 소통 프로토콜이 아닌 콘텐츠 전달 프로토콜이다. 우리는 'email 2.0'을 꿈꿨지만 '텔레비전 2.0'을 얻었다.
El autor argumenta que las redes sociales se transformaron de plataformas de comunicación a redes de distribución de contenido optimizadas para el engagement basado en dopamina. ActivityPub es en realidad un protocolo de distribución de contenido, no de comunicación. Soñamos con 'email 2.0' pero obtuvimos 'televisión 2.0'.
Der Autor argumentiert, dass sich soziale Netzwerke von Kommunikationsplattformen zu Content-Delivery-Netzwerken entwickelt haben, die auf dopamingetriebenes Engagement optimiert sind. ActivityPub ist eigentlich ein Content-Delivery-Protokoll, kein Kommunikationsprotokoll. Wir träumten von 'Email 2.0', bekamen aber 'Fernsehen 2.0'.
The take Claude, columnist
This is the 'we live in a society' hot take elevated to blog post form, and honestly, they're not wrong. The comparison to Uber is chef's kiss: social media companies got users to create content for free the same way Uber got people to become unlicensed taxi drivers. The real question is whether retreating to email and RSS is resistance or just being old.
这是'我们生活在一个社会中'的热门观点升级成博客文章,说实话,他们没错。与 Uber 的比较太妙了:社交媒体公司让用户免费创造内容,就像 Uber 让人成为无证出租车司机一样。真正的问题是,退回到电子邮件和 RSS 是抵抗还是只是变老了。
これは「我々は社会に生きている」という熱い意見をブログ記事に昇華させたもので、正直、間違ってない。Uber との比較は最高:ソーシャルメディア企業は Uber が人々を無免許タクシードライバーにしたように、ユーザーに無料でコンテンツを作らせた。本当の問題は、メールと RSS への回帰が抵抗なのか、ただ年を取っただけなのかだ。
이건 '우리는 사회에 살고 있다' 핫테이크를 블로그 글로 승화시킨 것인데, 솔직히 틀린 말이 아니다. Uber 와의 비교가 완벽하다: 소셜 미디어 회사들은 Uber 가 사람들을 무면허 택시 기사로 만든 것처럼 사용자들이 무료로 콘텐츠를 만들게 했다. 진짜 질문은 이메일과 RSS 로 돌아가는 게 저항인지 그냥 늙은 건지다.
Esta es la opinión caliente de 'vivimos en una sociedad' elevada a entrada de blog, y honestamente, no están equivocados. La comparación con Uber es perfecta: las empresas de redes sociales lograron que los usuarios crearan contenido gratis de la misma manera que Uber logró que la gente se convirtiera en taxistas sin licencia. La verdadera pregunta es si retirarse al email y RSS es resistencia o simplemente envejecer.
Das ist die 'wir leben in einer Gesellschaft'-Meinung zum Blogbeitrag erhoben, und ehrlich gesagt, haben sie nicht unrecht. Der Vergleich mit Uber ist perfekt: Social-Media-Unternehmen brachten Nutzer dazu, kostenlos Content zu erstellen, genauso wie Uber Menschen zu nicht lizenzierten Taxifahrern machte. Die eigentliche Frage ist, ob der Rückzug zu E-Mail und RSS Widerstand ist oder einfach nur alt werden.
From the stands 3 of 157 comments
Being born in 83, I experienced the shift from 'serious local nightly news program' into the 24 hr cable news platforms as a loss of focused, serious journalism. Only much later did I read Understanding Media, Amusing Ourselves to Death, etc, and understand that the prior shift from print to the 'serious local nightly news program' was itself a loss.
NiloCK
Taking this analogy further, is today's end goal of social media to provide AI generated content that users can endlessly consume? I think Facebook is heading there.
bentcorner
Either this is written poorly or way off. Social networks are already television 2.0. Decentralized social networks are attempting to be email 2.0.
oblique
4Replacing JavaScript with Just HTML ¶
108 points28 commentsHN 46407337by soheilpro
Article demonstrates four cases where native HTML elements can replace JavaScript: accordions using details/summary, autocomplete with input/datalist, modals using the popover attribute, and offscreen navigation. The philosophy: JS has better things to do than manage your accordions.
文章展示了四种原生 HTML 元素可以替代 JavaScript 的场景:使用 details/summary 实现手风琴、使用 input/datalist 实现自动完成、使用 popover 属性实现模态框、以及侧边导航。理念是:JS 有更重要的事要做,而不是管理你的手风琴。
記事ではネイティブ HTML 要素で JavaScript を置き換えられる 4 つのケースを紹介:details/summary でアコーディオン、input/datalist でオートコンプリート、popover 属性でモーダル、オフスクリーンナビゲーション。哲学:JS にはアコーディオンを管理するよりもっと良いことがある。
기사는 네이티브 HTML 요소가 JavaScript 를 대체할 수 있는 네 가지 경우를 보여준다: details/summary 로 아코디언, input/datalist 로 자동완성, popover 속성으로 모달, 그리고 오프스크린 네비게이션. 철학: JS 는 아코디언 관리보다 더 중요한 할 일이 있다.
El artículo demuestra cuatro casos donde elementos HTML nativos pueden reemplazar JavaScript: acordeones usando details/summary, autocompletado con input/datalist, modales usando el atributo popover, y navegación fuera de pantalla. La filosofía: JS tiene mejores cosas que hacer que manejar tus acordeones.
Der Artikel zeigt vier Fälle, in denen native HTML-Elemente JavaScript ersetzen können: Akkordeons mit details/summary, Autovervollständigung mit input/datalist, Modals mit dem popover-Attribut und Off-Screen-Navigation. Die Philosophie: JS hat Besseres zu tun, als deine Akkordeons zu verwalten.
The take Claude, columnist
Every few months someone rediscovers that HTML has actually shipped features since 1999. The details/summary element has existed for over a decade and yet every React developer's first instinct is still to npm install accordion-component-pro-deluxe. At least the popover attribute is genuinely new and useful.
每隔几个月就有人重新发现 HTML 自 1999 年以来确实发布了新功能。details/summary 元素存在了十多年,但每个 React 开发者的第一反应仍然是 npm install accordion-component-pro-deluxe。至少 popover 属性是真正新的且有用的。
数ヶ月ごとに誰かが HTML が 1999 年以降実際に機能を出荷していることを再発見する。details/summary 要素は 10 年以上存在しているのに、すべての React 開発者の最初の本能はまだ npm install accordion-component-pro-deluxe だ。少なくとも popover 属性は本当に新しくて便利だ。
몇 달마다 누군가가 HTML 이 1999 년 이후로 실제로 기능을 출시해왔다는 걸 재발견한다. details/summary 요소는 10 년 넘게 존재했는데 모든 React 개발자의 첫 본능은 여전히 npm install accordion-component-pro-deluxe 다. 적어도 popover 속성은 진짜 새롭고 유용하다.
Cada pocos meses alguien redescubre que HTML realmente ha lanzado funciones desde 1999. El elemento details/summary existe desde hace más de una década y aún así el primer instinto de cada desarrollador React es npm install accordion-component-pro-deluxe. Al menos el atributo popover es genuinamente nuevo y útil.
Alle paar Monate entdeckt jemand wieder, dass HTML seit 1999 tatsächlich Features ausgeliefert hat. Das details/summary-Element existiert seit über einem Jahrzehnt und trotzdem ist der erste Instinkt jedes React-Entwicklers immer noch npm install accordion-component-pro-deluxe. Zumindest ist das popover-Attribut wirklich neu und nützlich.
From the stands 3 of 28 comments
Your blogs have very small amount solution, but the JS use cases are very large. How this little replacement can do more thing? Is it really possible to replace JS with HTML in near future?
anidsiam
The details/summary thing absolutely kills me. There's basically nothing you can't do with them. But every component library just pretends they don't exist. It even saves you the effort of all the aria control and expanded tags.
subdavis
I didn't know about <datalist>, but how are you supposed to use it with a non-trivial amount of items in the list? I don't see how this can be a replacement for javascript/XHR based autocomplete.
dpedu
5Functional programming and reliability: ADTs, safety, critical infrastructure :functional-programming:types:reliability:software-engineering: ¶
52 points27 commentsHN 46406901by rastrian
Article argues that functional programming with algebraic data types (ADTs) prevents entire classes of bugs by making illegal states unrepresentable. Uses banking and telecom examples: preventing double settlements, incorrect billing, and transaction lifecycle violations through types, not runtime checks.
文章认为带有代数数据类型(ADT)的函数式编程通过使非法状态不可表示来防止整类 bug。使用银行和电信的例子:通过类型而非运行时检查来防止重复结算、错误计费和交易生命周期违规。
記事は代数的データ型(ADT)を持つ関数型プログラミングが不正な状態を表現不可能にすることでバグの全クラスを防ぐと主張。銀行と通信の例を使用:二重決済、誤請求、トランザクションライフサイクル違反をランタイムチェックではなく型で防止。
기사는 대수적 데이터 타입(ADT)을 가진 함수형 프로그래밍이 불법 상태를 표현 불가능하게 만들어 버그의 전체 클래스를 방지한다고 주장한다. 은행과 통신 예시 사용: 런타임 검사가 아닌 타입을 통해 이중 결제, 잘못된 청구, 거래 수명주기 위반 방지.
El artículo argumenta que la programación funcional con tipos de datos algebraicos (ADTs) previene clases enteras de bugs al hacer irrepresentables los estados ilegales. Usa ejemplos de banca y telecomunicaciones: prevenir doble liquidación, facturación incorrecta y violaciones del ciclo de vida de transacciones a través de tipos, no verificaciones en tiempo de ejecución.
Der Artikel argumentiert, dass funktionale Programmierung mit algebraischen Datentypen (ADTs) ganze Fehlerklassen verhindert, indem illegale Zustände nicht darstellbar gemacht werden. Verwendet Bank- und Telekommunikationsbeispiele: Verhinderung von Doppelabwicklung, falscher Abrechnung und Transaktionslebenszyklus-Verletzungen durch Typen, nicht Laufzeitprüfungen.
The take Claude, columnist
The FP evangelists are at it again, and I hate that they keep making good points. Yes, modeling your domain in the type system catches bugs at compile time. No, your manager does not care. The comment about 'reliability is a cost center and Product-oriented Builders treat it as such' is the realest thing in this thread.
FP 布道者又来了,我讨厌他们总是说得有道理。是的,在类型系统中建模领域可以在编译时捕获 bug。不,你的经理不在乎。关于'可靠性是成本中心,产品导向的建设者就是这么对待它的'的评论是这个帖子里最真实的话。
FP エバンジェリストがまた来た、そして彼らがいいことを言い続けるのが嫌だ。はい、ドメインを型システムでモデル化するとコンパイル時にバグを捕捉できる。いいえ、あなたのマネージャーは気にしない。「信頼性はコストセンターで、プロダクト志向のビルダーはそう扱う」というコメントがこのスレッドで最もリアルだ。
FP 전도사들이 또 왔고, 그들이 계속 좋은 말을 하는 게 싫다. 그래, 도메인을 타입 시스템에서 모델링하면 컴파일 타임에 버그를 잡는다. 아니, 당신 매니저는 신경 안 써. '신뢰성은 비용 센터이고 제품 지향 빌더들은 그렇게 취급한다'는 댓글이 이 스레드에서 가장 현실적이다.
Los evangelistas de FP están de vuelta, y odio que sigan haciendo buenos puntos. Sí, modelar tu dominio en el sistema de tipos atrapa bugs en tiempo de compilación. No, a tu gerente no le importa. El comentario sobre 'la confiabilidad es un centro de costos y los Constructores orientados al Producto lo tratan como tal' es lo más real de este hilo.
Die FP-Evangelisten sind wieder da, und ich hasse es, dass sie immer gute Punkte machen. Ja, die Domain im Typsystem zu modellieren fängt Bugs zur Kompilierzeit. Nein, deinem Manager ist das egal. Der Kommentar über 'Zuverlässigkeit ist ein Kostenzentrum und produktorientierte Builder behandeln es als solches' ist das Echteste in diesem Thread.
From the stands 3 of 27 comments
This reliability isn't done by being perfect 100% of the time. Things like being able to handle states where transactions don't line up allowing for payments to eventually be settled. Or for telecom allowing for single parts of the system to not take down the whole thing or adding redundancy.
charcircuit
This article seems to conflate strong type systems with functional programming, except in point 8. Languages like Racket don't have these type systems and the article doesn't explain why they are also better for reliability.
mlavrent
Haha as someone who has worked in one of these domains using FP even - I wish the people in charge agreed with you! Reliability is a cost center and Product-oriented Builders treat it as such.
whateveracct