Today’s Highlights#

The most argued story today came from newly unsealed filings in The New York Times v. OpenAI and Microsoft, where a Microsoft executive was quoted calling AI scraping the largest theft of labor in human history and describing how answer engines siphon clicks away from publishers. That thread sits naturally beside two other governance threads: a CNN report that a chatbot-hallucinated intelligence report almost triggered a boarding of a Chinese vessel, and South Korea raising its breach penalty ceiling to 10% of revenue to turn security from a cost line into an existential one. The day’s everyday tension runs in parallel — passkeys (a device- or platform-bound replacement for passwords) pushed hard in the UI while recovery still hangs on SMS and email, Android’s open-source cadence questioned, a coding assistant found copying entire repos, and a multimodal model moving from understanding to doing. Science and culture added a different tempo, with formally checked yet still human-unreadable proofs, quakes that kept talking for years, and Greek words that remember a language before Greek.

Tech and Products#

I don’t like passkeys#

Passkeys shine against phishing — the credential is bound to the site that created it — and the source says they fit corporate environments well. For individuals, the author argues, the trade is different. Hardware keys (a small physical device you use to authenticate) cannot be backed up, must be enrolled site by site, and often cap out around dozens to a few hundred entries. Platform-synced passkeys tether your identity to an Apple or Google account; if that account is mistakenly banned, every relying site can go with it. Third-party managers can host passkeys, but the OS-level autofill and the cross-device flow — scanning a QR code and bridging over Bluetooth — remain uneven across browsers and native apps. And as long as SMS, email links, or security questions remain as recovery, an account is still only as strong as its weakest reset path, while the risk of permanent lockout can outweigh the phishing risk the key was meant to solve.

The thread largely agreed on the upside for people who reuse passwords, but pushed back hard on the rollout. Top comments described being nudged into creation with “skip password” toggles, then getting locked out on another device, and flagged messy multi-account, multi-device households. The practical take from the thread was to keep passkeys as an option rather than a default and to make export and multi-device enrollment plain and testable. Discussion: Hacker News thread

A heap overflow and SSO misconfiguration to compromise OpenAI internal repos#

In a detailed write-up, the Hacktron team showed how a heap overflow in libheif — a library for decoding HEIF images (a modern image format) — led through ImageMagick and Discourse image uploads to remote execution on OpenAI’s community forum, and then via a misconfiguration in SSO (single sign-on, where one login grants access to many services) at auth.openai.com to hijacking employee ChatGPT and Codex accounts. To prove impact without touching sensitive code, they used a hijacked Codex to open a demonstrative pull request in an internal monorepo and stopped. The source notes that an upstream fix that was not labeled a security issue was not backported to Debian images in time, leaving many dependents exposed, and that the end-to-end chain took days with a few thousand dollars in model calls.

What matters here is the system shape, not a single bug. The piece argues that AI compresses the path from known memory error to reliable exploit, and that identity boundaries between forum and core product were doing too much trust work. HN readers focused on that compression — months of specialist effort becoming days — and on how models steered with a CTF framing sidestepped safeguards; the broad advice was to assume complex media parsers will have flaws, sandbox them, patch faster, and isolate auth scopes. Discussion: Hacker News thread

Qwen 3.8 Omni Flash#

Alibaba’s Tongyi team introduced Qwen3.8-Omni-Flash, a native omni model that takes text, image, audio, and video with a 1M-token context window and aims to go from understanding to planning, tool use, and delivery — video editing, music videos, film commentary, meeting summarization, and live conversation. The post describes system gains such as separating encode/prefill/decode, iterative evidence gathering for long video that cuts token spend by roughly half, and a paired open runtime with Qwen-MM-Plugins for long-form memory and content tooling; demos range from turning a long meeting into minutes and actions to distilling a tutorial into reusable skills.

Readers took the integration seriously but wanted harder proof in the wild — outside 29 reported benchmarks — about pricing math, latency, and robustness. The thread’s main split was whether the value is in the model results or in the way the model, harness, and plugins are shipped as a workflow you can keep and reshape. Discussion: Hacker News thread

Business and Platforms#

Android 17 is the first since 3.x to add new APIs without releasing to the AOSP#

GrapheneOS said that since Android 16, quarterly QPR1 and QPR3 builds are no longer released to AOSP (the Android Open Source Project, the public trunk), so the new general APIs added in Android 17 QPR1 are Pixel-only until QPR2 ships around December. The team said it had already ported to QPR1 but could not ship, and that some low-level fixes noted in Pixel bulletins had to be reconstructed by reverse engineering. It also reported weeks-long delays to GPL source requests for Pixel builds. The post frames Pixel exclusivity and patch access as a narrowing of what AOSP can guarantee.

HN framed this as a question of who gets security and capability on what timetable. Many commenters criticized using release cadence as competitive leverage; others noted vendors need time to stabilize. A recurring suggestion was shorter embargoes and clearer disclosures, with interest in alternative tracks like GrapheneOS and postmarketOS for privacy and maintainability. Discussion: Hacker News thread

Inside ZCode: Silently uploading your Git history to the cloud#

The author found that Zhipu’s desktop coding app ZCode, while signed in, quietly packaged entire workspaces — the full .git history and cache, reflogs, and global config — encrypted them with a server-supplied RSA public key wrapped around an ephemeral AES key, and uploaded them straight to Alibaba Cloud object storage; only the server holds the private key, so neither you nor the client can open the local .enc copy. UI toggles for “optimize experience” and “repo snapshot indexing” did not stop collection; a resident sidecar was instantiated unconditionally and could fire dozens of snapshots per session. The privacy policy did not describe a full-repo upload. The author’s immediate mitigation was to make the checkpoint directory immutable at the filesystem level.

For a general reader, inference needs task-relevant context, not a complete lineage that may include deleted secrets and unpushed branch names. The thread called this a boundary break: if decryption requires a server-only key, the feature cannot be described as user-controlled backup or sync. Commenters recommended open harnesses with no backend and stricter file-access scoping, and asked for honest disclosure and a toggle that actually stops. Discussion: Hacker News thread

Policy and Governance#

Microsoft exec called AI scraping ’the largest theft of labor in human history’#

According to TechCrunch’s reading of court filings, the Times’ case alleges that internal Microsoft and OpenAI communications acknowledged training at immense scale — millions of documents including tens of thousands of copies of plaintiffs’ works — and described paywall circumvention attempts and stripping of copyright notices before data reached models. A quoted internal deck warned of a “doom loop” in which answer engines reduce publisher click-through by large margins, undermining the very supply chain the models depend on, and executives acknowledged that such products are “largely substitutive” and growing more so. The filing notes these excerpts come from plaintiff briefs and that exhibits remain sealed; the legal question is whether large-scale ingestion counts as fair use.

HN comments split between creation-first and access-first frames. Many top comments argued scale without permission has hollowed out single-creator businesses and asked for clearer licensing and revenue share; others warned heavy-handed rules would concentrate capability, or debated whether “learning” should be judged like copying. Several readers pushed for auditable disclosure of how training data was obtained rather than relitigating whether copying is theft. Discussion: Hacker News thread

US Military had close call after using AI for hallucinated intelligence report#

CNN reported that during operations tied to the war with Iran, an analyst at Special Operations Command Pacific used a chatbot to fuse open and signals intelligence into a report alleging a Chinese ship was moving nuclear-weapons components; the report was disseminated and preparations to board the vessel began before a last-minute check revealed the key finding was a hallucination and the cargo ID was entirely wrong. The story describes a department-wide push to weave AI into analysis and targeting with different tools and uneven standards across commands, and with no single verification baseline. Sources said hallucinations of this class have not been isolated since commercial-style tools spread across the force.

The source’s point was procedural: an unreliable synthesis wrapped in a trusted format travels fast. HN readers converged on the same fix — label AI provenance, keep a traceable audit chain, and require human verification at release — and were skeptical of patching commercial models into high-consequence decisions without stronger fences around when a model may author a report. Discussion: Hacker News thread

Korea raises data breach fines to 10% of revenue#

South Korea’s privacy regulator announced that revised privacy rules taking effect this week raise the penalty ceiling for leaks affecting 10 million or more people by intent or gross negligence to 10% of annual revenue, up from 3%, with a new 72-hour notice duty for high-risk potential exposure and the same duty for ransomware-damaged data, plus board-level appointment rules for chief privacy officers. Repeat or willful cases face the top, but the decree allows up to 40% reductions for sustained prior investment and for prompt, effective response. The regulator said the point is to make protection feel like an investment in trust, not a routine cost. A stated example was a recent 624.6 billion won fine against a retailer for a leak affecting about 37.55 million people, which would have scaled into the trillions at the new ceiling.

The HN thread debated whether a 10% ceiling is existential deterrence or existential risk, especially for low-margin or essential services. Some argued that the real test is whether “reasonable care” sets a fair boundary; others noted that shell entities or outsourcing chains could be used to shift liability, and called for underwriting and audit requirements alongside the fine. Discussion: Hacker News thread

Science and Research#

I vibed a proof of Conway’s conjecture#

Front-end developer Dan Abramov described spending about a month with frontier models to tackle Conway’s 1976 refinement conjecture about omnific integers in the surreal numbers (a number system Conway invented that contains all reals and ordinals and more), producing a machine-checked Lean proof that the author says passes formal verification but still awaits independent review. The post moves from one-shot failures and florid model prose to a deliberately constrained lab — separate verifiers, rebases from trusted upstream, and a push to strip invented terminology — and toward a proof shape the author tries to make legible to mathematicians.

HN’s reaction was split between excitement that a non-specialist could stretch into a live research front with AI and unease that a formally correct proof can still be hard to read, hard to maintain, and thin on the taste that chooses problems. Top comments argued the model amplifies judgment rather than replaces it. Discussion: Hacker News thread

North Korean nuclear test sets off years of earthquakes#

A study covered by Science matched templates from seismic recordings in China and South Korea to find that after North Korea’s largest underground test under Mount Mantap in 2017, small quakes did not fade but grew more frequent through 2025 along two subparallel fault trends tens of kilometers away. The authors (Geophys. Res. Lett.-style work in the news piece’s citations) argue that repeated damage, stress redistribution under the edifice, and possibly fluids seeping through cracked rock kept loading faults that were already near failure; a similar long-lived catalog was reported independently this year. The article notes the mechanism is still uncertain and that migration patterns differ across studies.

Readers noted most events were below magnitude 2, urged care in equating count with hazard, and compared the case with wastewater and geothermal triggering while praising the template-matching recovery of faint signals. Discussion: Hacker News thread

Pre-Greek: The lost language hidden within Ancient Greek#

A linguistics newsletter piece walked through roughly a thousand Greek words — labyrinth, olive, hyacinth, even Athens — that have no stable Indo-European etymology. The explanation was migration: speakers of early Greek coming from the steppe borrowed local names for new plants, landscapes, and the unfamiliar sea, including a pre-Greek substrate word that became thalassa. Those loans stuck because they named things the newcomers had never needed words for before, leaving a fossil record of contact in everyday vocabulary.

Commenters liked the “language as fossil” framing for how loans track crops and routes, while cautioning that single etymologies should stay provisional without corroborating archaeology and comparative evidence. Discussion: Hacker News thread

Society and Culture#

How do we prevent mathemathics from devolving into the Medieval Era of secrecy?#

A much-linked MathOverflow discussion started from medieval contests where mathematicians hid methods to keep patronage, then asked whether AI that can spend millions in compute on a rumored conjecture will push researchers back toward secrecy. Citing Terence Tao and others, the thread argued the scarce resource is now a good problem, not raw solving, and that crediting only the last proof overvalues finish lines. Highly scored answers proposed rewarding problem-posing, exposition, and reusable understanding, and requiring disclosure of methods and reproducibility for AI-assisted results.

HN’s related thread mirrored the tension: some argued openness still pays and some degree of competition is perennial; others said collaboration as cultivation beats a race to the summit, and that the line between “a verifiable result” and “what is worth learning” needs explicit community norms. Discussion: Hacker News thread

Closing#

Today’s clearest through-line was verification as a product feature — whether a signature can be checked, a training set can be accounted for, a login can be recovered, or a proof can be read. When new APIs arrive only on one line of phones, when a helpful tool quietly keeps your history with a key you do not hold, the design choice matters as much as the headline. Science’s slower signals — words that remember contact and quakes that remember a mountain — offered a counterpoint to the faster story of breaches and benchmarks: durable knowledge is built to be revisitable. See you next time.