Latest Tech News

Stay updated with the latest in technology, AI, cybersecurity, and more

Filtered by: tp Clear Filter

Show HN: unsafehttp – tiny web server from scratch in C, running on an orange pi

Unsafe HTTP unsafehttp is an extremely minimal HTTP server written in C from scratch, to practice C, *nix socket programming, and C compilation. It just served this webpage to you! Yes, that's a marquee tag. Backward-compatibility is a beautiful thing. You can find the source here. Hosting It's running on a tiny Orange Pi SBC in my office: There's no HTTP proxy between you, just a port-forward through my VPS. You're connect ing right to the socket that the code is accept ing on. Fun Stuff

HTTP/1.1 must die: the desync endgame

HTTP/1.1 must die: the desync endgame James Kettle Director of Research @albinowax Published: 06 August 2025 at 22:20 UTC Updated: 12 August 2025 at 09:50 UTC Abstract Upstream HTTP/1.1 is inherently insecure and regularly exposes millions of websites to hostile takeover. Six years of attempted mitigations have hidden the issue, but failed to fix it. This paper introduces several novel classes of HTTP desync attack capable of mass compromise of user credentials. These techniques are demo

I let LLMs write an Elixir NIF in C; it mostly worked

This post documents how I built a cross-platform Elixir NIF in C to get on-demand up-to-date disk-usage stats without relying on os_mon and its disksup service. I had Grok 3 generate the initial C code and Makefile, then iterated through multiple code reviews by Gemini 2.5 Flash and GPT-5 to make it work on Linux, macOS, Windows, and the BSDs (except DragonFlyBSD). Along the way, I ran into typical LLM hiccups that speak volumes about the breathless hyperbole often peddled by LLM vendors, comput

Show HN: I built a free alternative to Adobe Acrobat PDF viewer

EmbedPDF Open‑Source JavaScript PDF Viewer EmbedPDF is a framework‑agnostic, MIT‑licensed PDF viewer that drops into any JavaScript project. Whether you build with React, Vue, Svelte, Preact, or vanilla JS, EmbedPDF delivers a smooth, modern reading experience and a clean developer API. 📚 Documentation Full docs, installation guides, API reference, and examples: 👉 https://www.embedpdf.com 🚀 Live Demo Try it now — load your own PDF or use the sample: 👉 https://app.embedpdf.com ✨ Features

I Tested a $250 Budget Phone and It Didn't Make Me Look Like a Cheapskate

CNET’s expert staff reviews and rates dozens of new products and services each month, building on more than a quarter century of expertise. 7.0 / 10 SCORE TCL 60 XE NxtPaper 5G $250 at Amazon Pros Quality display for the price E-reader mode extends already-solid battery life NxtPaper Color Ink mode is perfect for night owls Cons Grainy picture quality on main camera Slight delay when multitasking Gets uncomfortably hot when gaming The TCL 60 XE NxtPaper 5G is an impressive budget phone th

Topics: 5g 60 nxtpaper tcl xe

AWS launches AI agent marketplace with a hackathon and $100k in prizes for developers

Kmatta ZDNET's key takeaways The new agents marketplace will launch in beta next month. The companies will also launch an educational hub for IT clients. Developers could win a chunk of $100,000 for building agents. As is often the case with hyped-up new technologies, interest in AI agents among business leaders is soaring -- some CFOs report committing 25% of their AI budgets to them. However, practical understanding of how to implement and use them effectively remains somewhat fuzzy. A ne

Hands-on: We ran full desktop Linux apps on an Android phone!

Mishaal Rahman / Android Authority TL;DR An upcoming Android update will significantly upgrade the Linux Terminal app, enabling it to run full-fledged graphical Linux programs on supported devices. The feature is currently experimental, requiring a Pixel 6 or newer on a specific Android Canary build and manual steps to enable both the terminal and hardware acceleration for better performance. This guide details how to install and run graphical apps like GIMP or LibreOffice using Flatpak, eith

I Tested a $200 Budget Phone and It Didn't Make Me Look Like a Cheapskate

CNET’s expert staff reviews and rates dozens of new products and services each month, building on more than a quarter century of expertise. 7.0 / 10 SCORE TCL 60 XE NxtPaper 5G Pros Quality display for the price E-reader mode extends already-solid battery life NxtPaper Color Ink mode is perfect for night owls Cons Grainy picture quality on main camera Slight delay when multitasking Gets uncomfortably hot when gaming The TCL 60 XE NxtPaper 5G is an impressive budget phone that meets or exc

Topics: 5g 60 nxtpaper tcl xe

The top 3 smartphone gimbals on the market right now

Smartphone gimbals have become a dime a dozen at this point, but who are the leaders right now? Here are our top three gimbals that you should be looking at if you are in the market for one. Who is using a smartphone gimbal? It feels like smartphone gimbals were all the rage with the rise of social media a decade or so ago. Back then, the only option was really just DJI, and they’re still the leader. However, with corporate America realizing they need a bigger social media team and being an “i

Why I recommend this $200 Android phone with a paper-like display over competing models

TCL 60 XE Nxtpaper 5G ZDNET's key takeaways TCL's 60 XE Nxtpaper 5G is on sale on Amazon for $222. It has a unique display, and a feature set that promotes minimalism and digital well-being. I just wish the camera system and general performance were better. $249.99 at Amazon Being glued to your smartphone's screen all day can do a number on your eyes, and I definitely can feel it. TCL's Nxtpaper technology offers a paper-like screen that's made for tired eyes like mine. The TCL 60 XE Nxtpaper

The tablet that replaced my iPad and Kindle got a worthy successor - and I'm loving the upgrades

TCL Nxtpaper 11 Plus ZDNET's key takeaways The TCL Nxtpaper 11 Plus is available for $249. This tablet can switch from full color to an E Ink-like display with the press of a button, it has 256GB of storage, and an eye-catching matte display with 120Hz refresh rate. The Nxtpaper 11 Plus can get heavy when you use it one-handed and doesn't include a case or stylus, though you can buy them separately. $249 at Walmart I test a lot of tablets, and admittedly, the design aspirations of many of the

Open Lovable

Chat with AI to build React apps instantly. # Required E2B_API_KEY = your_e2b_api_key # Get from https://e2b.dev (Sandboxes) FIRECRAWL_API_KEY = your_firecrawl_api_key # Get from https://firecrawl.dev (Web scraping) # Optional (need at least one AI provider) ANTHROPIC_API_KEY = your_anthropic_api_key # Get from https://console.anthropic.com OPENAI_API_KEY = your_openai_api_key # Get from https://platform.openai.com (GPT-5) GROQ_API_KEY = your_groq_api_key # Get from https://console.groq.com (Fa

Topics: ai com console dev https

Debugging a mysterious HTTP streaming issue

The Problem We recently encountered a frustrating issue with HTTP response streaming at Mintlify. Our system uses the AI SDK with the Node stream API to forward streams, and suddenly things stopped working properly. The symptoms were confusing: streaming worked perfectly with cURL and Postman, but failed completely with node-fetch and browser fetch. ‍ Initial Investigation Our first hypothesis centered around stream compatibility issues. We suspected the problem might be related to how the AI

This $200 Android phone beats competing Motorola and Samsung models in a unique way

TCL 60 XE Nxtpaper 5G ZDNET's key takeaways TCL's 60 XE Nxtpaper 5G is on sale on Amazon for $222. It has a unique display, and a feature set that promotes minimalism and digital well-being. I just wish the camera system and general performance were better. $249.99 at Amazon Being glued to your smartphone's screen all day can do a number on your eyes, and I definitely can feel it. TCL's Nxtpaper technology offers a paper-like screen that's made for tired eyes like mine. The TCL 60 XE Nxtpaper

The best smartphones without AI features in 2025: Expert tested and recommended

These days, it feels like AI and machine learning algorithms are being stuffed into every device, whether it makes sense to do so or not. And with almost every major brand announcing that AI will be a standard feature in new releases going forward, you may be looking for a way to opt out or avoid it entirely. Thankfully, there are still plenty of options on the market for phones that don't force AI as an integral feature; you can even find a few "dumb" phones if you're thinking of a total digita

Ditching GitHub

This is going to be some sort of a public service announcement, with side notes. This has been brewing for a long, long time (years), it’s just that I never seemed to have the focus time required to solve this once and for all. But now I decided to get moving, and it is already ongoing. If you are among those few with an interest in code I publish, do read on. What? I am moving all of my public source code repositories off of GitHub. My ambition is to completely end my own usage of GitHub, in

Is the Xperia line dead? Sony clarifies the future of its smartphones

It’s no secret that Sony Xperia smartphones aren’t the best-selling phones, nor are they the top choice for Android flagships . Sony built a loyal niche of fans who buy its Xperia phones, but the market beyond them doesn’t pick up on the phones with as much enthusiasm. When the company’s latest flagship, the Xperia 1 VII, began dying and disappearing across markets , many presumed that the end was near for Sony’s Xperia line of phones. Sony is laying rest to those fears, indicating it is around,

Realizing we needed two sorts of alerts for our temperature monitoring

You're using a tool with a too-generic User-Agent You're probably reading this page because you've attempted to access some part of my blog (Wandering Thoughts) or CSpace, the wiki thing it's part of. Unfortunately whatever you're using to do so has a HTTP User-Agent header value that is too generic or otherwise excessively suspicious. Unfortunately, as of early 2025 there's a plague of high volume crawlers (apparently in part to gather data for LLM training) that behave like this. To reduce th

This USB-C accessory gave my Android and iPhone an ingenious emergency tool

Heat It Smartphone-Powered Insect Bite Healer ZDNET's key takeaways The Heat It is available on Amazon for $40. It heats up from your smartphone and reduces swelling and itchiness from bug bites. While its power consumption is modest, it will take some charge from your phone. $39.95 at Amazon As someone who spends a lot of time outdoors (and someone who got hit with Lyme disease), it's astonishing how often I forget to apply insect repellent. Just the other night, I spent the last half of a f

Consider using Zstandard and/or LZ4 instead of Deflate

One of the issues we have with .PNG is slow read/write times. There are now new lossless open source codecs without patent concerns, such as Zstandard (maintained by Facebook) or LZ4: https://facebook.github.io/zstd/ https://github.com/lz4/lz4 Zstandard is used by the new Khronos KTX2 GPU texture format specification. I propose that it be added as an option to a future version of .PNG. The possible speedups are quite significant, and for users that read and write a lot of .PNG's as part of th

Lunar Outpost celebrates release of Lego Moon Rover Space Vehicle

Browsing the toy aisle at Target, Ari and Aiden were in for a surprise. There, among the newly stocked Lego sets, was a box with an image of a familiar-looking space vehicle. "I pointed at the box and said, 'Hey, what's that?' and they said, 'It's MAPP!'" said Andrew "AJ" Gemer, Ari and Aiden's father. "They didn't even know we had a Lego set until the day it was released." "It was cool to see their faces light up like that," he said in an interview with collectSPACE. The box for the new Lego

The Revolution of Token-Level Rewards

Training large language models (LLMs) to master complex tasks, especially those requiring structured outputs like generating precise code or engaging in multi-step reasoning, is challenging even for current state of the art (SOTA) models. Reinforcement Learning (RL) offers a powerful theoretical framework for teaching models to do "what works", but applying these techniques to LLMs has been messy to execute in practice. We’ve run into this problem at our startup, Levro. We want to be the easies

Proton fixes Authenticator bug leaking TOTP secrets in logs

Proton fixed a bug in its new Authenticator app for iOS that logged users' sensitive TOTP secrets in plaintext, potentially exposing multi-factor authentication codes if the logs were shared. Last week, Proton released a new Proton Authenticator app, which is a free standalone two-factor authentication (2FA) application for Windows, macOS, Linux, Android, and iOS. The app is used to store multi-factor authentication TOTP secrets that can be used to generate one-time passcodes for authenticatio

Why I recommend this budget phone with a paper-like screen over 'minimalist' devices

TCL 60 XE Nxtpaper 5G ZDNET's key takeaways TCL's 60 XE Nxtpaper 5G is on sale on Amazon for $222. It has a unique display, and a feature set that promotes minimalism and digital well-being. I just wish the camera system and general performance were better. $249.99 at Amazon Being glued to your smartphone's screen all day can do a number on your eyes, and I definitely can feel it. TCL's Nxtpaper technology offers a paper-like screen that's made for tired eyes like mine. The TCL 60 XE Nxtpaper

LastPass can now warn or block logins to shadow SaaS apps - here's how

LastPass ZDNET's key takeaways: The LastPass plug-in can now prevent access to unapproved SaaS apps. Feature extends plug-in's monitoring of SaaS access attempts. Passkey authentication coming by month's end -- not yet supported. Earlier this year, LastPass announced it was adding the ability for administrators of its password management solution to monitor employee usage of SaaS or web-based applications. Today at the Black Hat security conference in Las Vegas, the company announced it has

People still use our old-fashioned Unix login servers

You're using a tool with a too-generic User-Agent You're probably reading this page because you've attempted to access some part of my blog (Wandering Thoughts) or CSpace, the wiki thing it's part of. Unfortunately whatever you're using to do so has a HTTP User-Agent header value that is too generic or otherwise excessively suspicious. Unfortunately, as of early 2025 there's a plague of high volume crawlers (apparently in part to gather data for LLM training) that behave like this. To reduce th

Telo MT1

We redesigned the EV truck footprint and function from the ground up by marrying the state of the art in electrification and advanced safety technology. With Toyota Tacoma capability, Tesla-like range and efficiency, in the footprint of a MINI Cooper, the TELO MT1 is the most compact, practical and technically advanced truck. Meeting the need for a highly functional and powerful EV pickup equally suited to navigating downtown and hauling people and gear out of town. RESERVE YOURS

When Flatpak's Sandbox Cracks

Introduction Flatpak promises a secure runtime for Linux applications through container-like isolation, relying on bubblewrap namespaces, syscall filtering, and portal interfaces. In theory, each app should operate inside a strong sandbox, disconnected from the host system. But in reality, experience shows gaps, tiny cracks through which apps may escape with serious consequences. The Sandbox Promise… and the Reality Flatpak applications begin life in a highly-restricted environment: no networ

Ask HN: Who is hiring? (August 2025)

Please state the location and include REMOTE for remote work, REMOTE (US) or similar if the country is restricted, and ONSITE when remote work isan option. Please only post if you personally are part of the hiring company—no recruiting firms or job boards. One post per company. If it isn't a household name, explain what your company does. Please only post if you are actively filling a position and are committed to responding to applicants. Commenters: please don't reply to job posts to compla

GPT-5 is already (ostensibly) available via API

Using the model gpt-5-bench-chatcompletions-gpt41-api-ev3 via the Chat Completions API will give you what is supposedly GPT-5. Conjecture: The "gpt41-api" portion of the name suggests that there's new functionality to this model that will require new API parameters or calls, and that this particular version of the model is adapted to the GPT-4.1 API for backwards compatibility. Here you can see me using it via curl : https://preview.redd.it/glxute607egf1.png?width=1181&format=png&auto=webp&s=

Topics: api gpt https model png