Hacker News Daily (2026-09-08)
Today’s Highlights#
Start with a four-page PDF that turned a Millennium Prize problem into a question of trust. Navier-Stokes – Tristan Buckmaster [pdf] documents a collaboration through restricted Euler equations toward the Navier-Stokes existence-and-smoothness problem, and a fraught call with an AI lab in early September. Read alongside it, On the Navier–Stokes Millennium Prize Problem tells the mirrored story: a construction of a finite-time singularity by thousands of coordinating agents and a Lean-checked proof. Together they frame the day’s through-line: how something gets built matters less than whether it can be verified — who saw what, who is credited, and what data counts as evidence. That same question echoes beyond mathematics, from the living room to the browser and the search results.
Science and Research#
Navier-Stokes – Tristan Buckmaster [pdf] A four-page statement makes a Millennium problem a trust dispute#
The source is a statement by NYU professor Tristan Buckmaster and collaborator Levent Alpöge, who describe progress via restricted Euler equations toward the full Navier-Stokes existence-and-smoothness problem, and recount a September call with OpenAI. According to the statement, the team was first shown a prompt that appeared to contain only the problem statement, but follow-up messages revised that picture to a system of roughly 10,000 concurrent agents, about 88 hours of coordinated work, and hundreds of billions of output tokens, with several corrections during the call. The statement also says the call included two proposals to remove Levent from authorship — either a joint announcement or a rewrite with Tristan alone. When asked whether drafts stored in Codex (OpenAI’s coding-assistant environment) had been used for training, the reply, in the statement’s words, was that the model had not directly looked up user data, with no clear answer on training.
HN reactions split. Top comments argued the phrasing itself is the point: “did not directly look up” sidesteps the more material question of training use. Several readers noted that knowing which technical route is viable is often the key information. Others cautioned against treating a single statement as settled fact and urged independent verification and full disclosure from all sides.
Discussion: Hacker News thread
On the Navier–Stokes Millennium Prize Problem Thousands of agents sketch a singularity and Lean checks it#
In On the Navier–Stokes Millennium Prize Problem, OpenAI says an internal model produced a constructive proof of a finite-time singularity for Navier-Stokes between September 1 and 5, verified in Lean (a machine-checkable proof language) in another 17 hours, claiming to settle statements C and D in the Clay Institute’s formulation. The source describes a vortex that spirals inward and stretches like spaghetti, its speed growing without bound in finite time while energy stays finite — requiring acceleration, pressure gradients, and viscosity to grow large yet cancel precisely to leave a smooth external force. The approach, the post says, used the unforced Euler regularity problem as a stepping stone, grouping agents to explore variants and then cross-pollinating insights. The headline counts are about 2.7 million messages and roughly 130 billion output tokens for Navier-Stokes alone. The team says it did not directly access the mathematicians’ data, but cannot fully rule out that de-identified usage data indirectly helped its models, and it does not intend to claim the prize.
HN’s main split was credibility versus momentum. Several readers were struck by an internal model reportedly leaping in mathematics within weeks of a training run; others read “a Millennium problem in days” as financing-cycle storytelling. The thread’s consistent ask was to publish prompts and proof artifacts for external review. Even if the proof holds, commenters argued, human steering and orchestration at scale remain decisive.
Discussion: Hacker News thread
AlphaGenome Atlas: a high-resolution map of human DNA A 1-petabyte atlas precomputes every single-letter variant#
Google DeepMind’s AlphaGenome Atlas: a high-resolution map of human DNA precomputes the regulatory impact of all roughly 9 billion single-nucleotide variants with the AlphaGenome model, yielding a 1-petabyte, queryable resource. A single AlphaGenome Variant Impact (AVI) score blends coding and non-coding signals to rank candidates. The source highlights two early uses: researchers at the Broad Institute used the score to prioritize a splice-altering variant in DNM1 for an unsolved rare disease, and a UK Biobank study of 54,000 participants grouped variants by predicted effect, uncovering 22% more non-coding associations and 19 regions tied to BMI. The Atlas is offered through a no-code web portal.
The thread mixed enthusiasm with caution. Readers with genomics knowledge questioned the lift over prior models such as Borzoi, while others warned that a single score cannot replace experimental validation. Attentive commenters discussed non-commercial licensing, and a possible path through Isomorphic Labs to pharma partnerships, framing the Atlas as a retrieval accelerator rather than a drug-discovery engine.
Discussion: Hacker News thread
Tech and Products#
Jellyfin 12.0 A self-hosted media server treats books and comics as first-class citizens#
Jellyfin 12.0 drops the long-running “10.x” prefix to mark a major release. The source says the core work turns a database rebuild from 10.11 into tangible speed: playlists and collections move from one serialized blob to per-item rows, fixing counts, paging, and single-item edits on large libraries and speeding “Continue Watching” and “Next Up.” The release also makes books and comics fully native — reading OPF and ComicInfo metadata directly, generating covers and page counts, sorting by index and release date, and offering a redesigned reader with iOS background audiobook playback. The post includes detailed backup and migration notes, stressing a full backup and a post-upgrade rescan.
Top comments praised the database refactor for finally unfreezing large libraries. Several readers flagged practical costs: plugin compatibility and legacy clients that rely on deprecated endpoints. The thread’s consensus valued Jellyfin less for feature fireworks than for the durable promise of a home media center you can control and keep.
Discussion: Hacker News thread
I’ve factored the RSA keys of a Certificate Authority from the 90s A 512-bit root from 1999 falls on a desktop in about 30 hours#
The author mined archived Netscape and Internet Explorer installers from archive.org and found that Netscape 4.51 trusted two 512-bit RSA roots from Canada’s defunct E-Certify in 1999. Using CADO-NFS (an open-source number-field sieve factorization suite), the source reports about 32 and 29 hours on a Ryzen 9 5950X desktop to factor each modulus, publishing extraction commands and private keys and standing up a TLS endpoint that only old Netscape can speak — a runnable demonstration. The post notes that Internet Explorer 3.02’s test VeriSign code-signing CA was the same strength and invites readers to try other “ancient roots” in the repo. The essay uses the demo to make a broader point: key sizes age as compute cheapens.
HN readers praised the “archaeological” angle for making abstract key-length deprecation tangible. Others added that a GPU cluster can do the same job in about an hour, and the conversation turned to archival completeness and how modern root rotation avoids repeating the same trust fossil.
Discussion: Hacker News thread
Business and Platforms#
Mistral raises €3B Europe’s largest equity round bets on a sovereign, full-stack AI#
Three-year-old Mistral raises €3B reports a €3 billion Series D at a post-money valuation above €21 billion — described as the largest equity fundraising by a European tech company — led by Samsung Electronics with EQT’s Scaleup Europe Fund and returning backers including ASML, a16z, NVIDIA, and Salesforce. The source says the funds will scale frontier research, compute, and international footprint, now spanning 20 countries and 125+ enterprise customers. The company’s framing is “sovereign, full-stack” AI — open-weight models (weights anyone can download and run), private compute, and auditable production systems that keep data and institutional knowledge inside the customer’s walls. The investor roster itself signals how closely advanced manufacturing and the AI stack are intertwining.
Several commenters saw a welcome counterweight to single-vendor lock-in to U.S. providers, while others pushed back on whether “open-weight” and “sovereign” sit comfortably together, and whether valuation will meet commercial execution on timetables that satisfy enterprises.
Discussion: Hacker News thread
There’s a new “Google Jail” for independent wikis When new domains can barely be found, the independent wiki struggles#
The team that hosts several independent game wikis describes in There’s a new “Google Jail” for independent wikis a pattern since Google’s March 2024 core update: about 90% of wikis launched on brand-new domains see only their homepage surface in ordinary search, even when that homepage outranks the old Fandom mirror. The condition, the post says, can last close to a year and has little to do with originality — it looks like a blunt, domain-level hold. By contrast, wikis on subdomains of established domains were indexed normally, in one case within a week. The practical workaround the authors adopt is to launch on a trusted subdomain and, once indexing stabilizes, 301-redirect and use Google’s change-of-address tool to return to the intended domain.
HN readers recognized the “zombie Fandom” effect from their own moves, arguing the new-domain penalty compounds migration costs when roughly 85% of wiki traffic comes from Google. Others speculated the change is a coarse countermeasure against AI slop. The through-line was platform dependence: how visibility for decentralized reference works is made or broken upstream.
Discussion: Hacker News thread
Among European Companies That Use a CDN, Nearly 9 in 10 Use Cloudflare Sharing one front door makes unrelated outages coincide#
CipherCue fingerprinted 44,143 European company websites that show a CDN (a content delivery network — the edge layer that caches and shields a site) and reports in Among European Companies That Use a CDN, Nearly 9 in 10 Use Cloudflare that 89.6% sit behind Cloudflare, versus about 3,112 behind Amazon, 1,299 behind Fastly, and 396 behind Akamai. Country splits range from about 79% in Spain and Ireland to 95.6% in the Netherlands, with Germany at 81.4% and the UK largest in absolute numbers. The source stresses the denominator: share among CDN users, not all companies, matching W3Techs’ ~84% observation. Concentration had costs in the last 15 months: three global incidents with no attacker involved — November 2025 (Bot Management config bloat), December 2025 (a config change during a React vulnerability mitigation), and February 2026 (a cleanup job that withdrew BYOIP prefixes) — each briefly took down many unrelated sites at the same time.
HN discussion admired Cloudflare’s free tier and global-by-default ergonomics — several self-described small-site operators said it simply removed regions and rigmarole that AWS and Google impose — while worrying that one provider’s ordinary bug now becomes everyone’s outage. Other readers debated sovereignty and cost: whether Europe can and should rebuild edge diversity without sacrificing reliability and latency.
Discussion: Hacker News thread
Policy and Governance#
LG TVs caught spying even when offline or on standby A set that keeps listening after the screen goes dark#
The Verge, summarizing tests by Gamers Nexus with Level1Techs and independent researchers, reports that several LG OLED TVs kept logging microphone audio on standby — even with the screen off or the set disconnected — storing files locally and uploading upon reconnection, while actively scanning the local network and nearby Wi-Fi for phones, watches, and network names. The source says Automatic Content Recognition (ACR, fingerprinting audio and video to infer what you watch) covered HDMI and other inputs, and that data flowed to LG Ad Solutions. In this telling, researchers disclosed a remotely exploitable issue under responsible disclosure.
Top comments treated the finding as a trust threshold. Several readers said they already keep TVs offline and use them as dumb displays or via an external stick — partly to regain control over ACR and ad targeting. Others argued that consent dialogs provide weak cover for behavioral data markets, and that mitigations like alternate DNS or hotspot blocking are easily skirted, pointing to the need for verifiable enforcement rather than boilerplate assurances.
Discussion: Hacker News thread
Paramount Caught Using ‘Astroturf’ Group to Drum Up Fake Support for Merger Texts in a grassroots costume try to tilt a $111B merger#
Techdirt reports that as California weighs an antitrust challenge to a proposed ~$111 billion Paramount–Warner Bros. combination, residents received texts from a nonprofit called Neighbors for Strong Communities urging them to pressure the attorney general to drop the suit — warning that opposition would cost jobs if the company moved the studio to Texas. Citing a consumer coalition, the source says the group’s site is under three months old, discloses no founders or funders, lists a UPS mailbox, and does not appear in the ProPublica nonprofit database — classic markers, the piece argues, of astroturf (a centrally funded campaign dressed as grassroots). The post also surveys other contested communications around the deal and frames the merger’s stakes for labor and pricing as the substantive question for review.
HN’s main split was process versus policy. Several readers argued that paying to manufacture support itself suggests organic support is thin, and that donor disclosure should be table stakes in merger politics. Others debated the California suit’s strategy and the historical pattern of layoffs and price hikes after big media combinations.
Discussion: Hacker News thread
We have a year to fix security everywhere When capable open-weight models run locally, exploitation scales to a loop#
The essay We have a year to fix security everywhere argues the window is closing because GLM-5.3-flash — an open-weight model (weights anyone can download) from Z.ai, with stripped-down “abliterated” variants that no longer refuse disallowed requests — can run locally at tens of tokens per second on roughly $5,000–$15,000 of hardware, while benchmarking close to frontier systems on security tasks. The post cites CyberGym and ExploitBench scores to claim real-world vulnerability reproduction and exploitation are within reach for a much wider set of actors. Efforts like Anthropic’s Project Glasswing and OpenAI’s Daybreak have made progress, the author writes, but deployment is the bottleneck: patches exist yet roll out slowly across supply chains and critical infrastructure.
HN commenters broadly agreed on urgency while pushing back on doom framing. Several readers stressed that abliterated models still need human scaffolding to chain a full exploit reliably; others argued defenders can also scale fixes with the same tooling. The thread’s practical consensus emphasized funding auditable infrastructure and faster patch distribution over purely model-side controls.
Discussion: Hacker News thread
Society and Culture#
LibreOffice breaks download records after declaring it has no AI features Saying “no” turns out to be a feature#
LibreOffice breaks download records after declaring it has no AI features reports that LibreOffice 26.8 drew more than one million installer downloads in its first week — not counting Linux repository updates — a record for the project. The story links the bump to The Document Foundation’s follow-up post, “Yes, no AI is now a feature,” laying out principles for inclusion: user-controlled execution, no content leaving the device without permission, no telemetry, no single-vendor dependency, no file-format compromises, and genuinely optional. For now the foundation recommends community plugins for those who want AI at all. The piece presents the stance not as anti-AI, but as a commitment to control and verifiability at a moment when subscription suites bundle assistants by default.
Top comments said “no AI by default” was the reason they tried or stayed with LibreOffice, valuing offline control and predictability. Others cautioned against single-cause attribution, noting that release polish likely contributed. The broader exchange weighed trust models for productivity software — whether optional, local plugins better match what most people actually want from a word processor and spreadsheet.
Discussion: Hacker News thread
We built our house for LAN parties (2024) A home where 12 PCs hide in the walls and the floor hides dance pads#
A couple documents We built our house for LAN parties (2024) — a house completed in 2024 where the basement game room, roughly 18 by 24 feet, hides 12 fold-out PC stations in the walls, a 98-inch TV, two recliner loveseats, and DDR pads under floor hatches. Upstairs the conference table flips into six more stations plus sit-stand work desks. Twenty identical gaming rigs live in a dedicated, air-conditioned rack room, net-booting from a shared image, tied together with 35 four-port wall boxes, multiple PoE devices, and a 2 Gbps fiber line on a UniFi fabric. The write-up details cabling, cooling, and transforms, framing the project as durable infrastructure for gatherings rather than a stunt.
HN readers admired the craft while negotiating trade-offs aloud — cost, noise, maintenance — and many offered smaller-scale versions of their own. The thread read the house less as a flex than as an argument for investing seriously in offline, shared space.
Discussion: Hacker News thread
The two Christian saints who are the Buddha Two saints whose biography traces back to the Buddha#
The essay The two Christian saints who are the Buddha tells of Barlaam the hermit and Josaphat, a secluded prince who, after witnessing sickness, age, and death, converts and retreats — a plot that mirrors the Buddha’s early life. Textual sleuthing traces the story to a 10th-century Georgian version (Balavariani), back through Arabic Bilawhar and Budhasaf and Persian Bodisav to Sanskrit Bodhisattva — a chain of translations that Christianized the tale. Venerated for centuries, the saints even traveled onward to Iceland and Japan, the piece notes, and it situates the case within broader patterns of sacred sites, festivals, and narratives being borrowed and reinterpreted across traditions.
HN discussion turned on syncretism (the blending of traditions) versus appropriation. A reader who worships in Indonesia described Javanese processions folded into Catholic mass as pragmatic, local inculturation; others emphasized that story motifs circulated widely across the Mediterranean and Near East long before canons fixed them. The praise was for the essay’s crisp etymology and its demonstration of how durable a good story can be when it solves for awe or moral instruction.
Discussion: Hacker News thread
Closing#
Today’s threads pull in the same direction: tools are getting more capable and more concentrated at once, so outcomes hinge on whether commitments can be checked. A proof that can be machine-verified, a TV that can be proven to keep listening, a front door that can be shown to be one door for most of a continent, a download count that makes a design choice visible — each makes the abstract testable. The gentler counterpoints — a house rebuilt for gatherings, a word processor that stays quiet unless asked otherwise, a 1,000-year journey of a single story across languages — suggest what people choose to keep when speed tempts them to outsource judgment. If there is a single takeaway, it is that faster building asks for faster proving, and that proving, for now, still depends on institutions, habits, and norms we maintain together. See you next time.