Show HN: I got laid off from Meta and created a minor hit on Steam
Winners of the $10k ISBN visualization bounty
annas-archive.org
Show HN: Libredesk – Open-source customer support desk. Single binary app
github.com
TypeScript types can run DOOM [video]
youtube.com
DualPipe: Bidirectional pipeline parallelism algorithm
github.com
Teslas monitor everything – including you [video] from WIRED
youtube.com
US examining whether UK's encryption demand on Apple broke data treaty
reuters.com
Launch HN: Maritime Fusion (YC W25) – Fusion Reactors for Ships
Show HN: Tach – Visualize and untangle your Python codebase
github.com
Flawed Diamonds Make Perfect Quantum Sensors
spectrum.ieee.org
Show HN: A Database Written in Golang
github.com
Simulating Time in Square-Root Space
eccc.weizmann.ac.il
The man who spent forty-two years at the Beverly Hills Hotel pool (1993)
newyorker.com
Replace OCR with Vision Language Models
github.com
Tom Stevenson on the deciphering of Linear Elamite
lrb.co.uk
Show HN: LLM plays Pokémon (open sourced)
github.com
The FFT Strikes Back: An Efficient Alternative to Self-Attention
arxiv.org
Show HN: Breakout with a roguelite/vampire survivor twist
breakout.lecaro.me
A new proposal for how mind emerges from matter
noemamag.com
Chartist: Task-Driven Eye Movement Control for Chart Reading
arxiv.org
DARPA Large Bio-Mechanical Space Structures
sam.gov
(2016)
> When proving the security of OAuth in our model, we discovered four attacks which break the security of OAuth. The vulnerabilities can be exploited in practice and are present also in OpenID Connect.
> We reported all attacks to the OAuth and OpenID Connect working groups who confirmed the attacks. The OAuth working group invited us to present our findings to them and prepared a draft for an RFC that mitigates the IdP mix-up attack (using the fix described in Section 3.2) [24]. Fixes regarding the other attacks are currently under discussion. We also notified nytimes.com, Facebook, and the developers of mod_auth_openidc and pyoidc.
The burning question is what has happened since. I couldn't find an RFC or errata about the other issues.
(Aside from formal analyses being cool research. :)
[24] https://datatracker.ietf.org/doc/html/draft-ietf-oauth-mix-u...