Hacker Newsnew | past | comments | ask | show | jobs | submit | l2dy's commentslogin

The Italian version of this https://www.vatican.va/content/leo-xiv/it/encyclicals/docume... uses en dashes instead. Could the em- or en- dashes be a side-effect of the translation?


Public POC at https://github.com/orinimron123/CVE-2026-40369-EXPLOIT, allowing browser sandbox escape from render process sandbox.


Author of that PR doesn't seem to be a Microsoft employee. Keep in mind that anyone on GitHub can create PRs against VSCode.



The linked revert PR is not from Microsoft (and also isn't merged)


It is merged


dmitriv recreated in a separate PR and merged that. The linked revert PR by a user was closed.


Yep - Says he's got a Microsoft.com email address:

> "feel free to reach me directly (my alias @microsoft.com) or"


Even if that would be so, the person who approved it certainly is.


The PR linked to in https://news.ycombinator.com/item?id=47992431 is not yet approved as of May 3 4:08 GMT.


The AI features are not fully open, and there are some forking attempts to fix that. https://github.com/warpdotdev/warp/issues/9303


Related:

* What’s new in security for Ubuntu 26.04 LTS? https://ubuntu.com/blog/ubuntu-26-04-lts-security-updates

* From Jammy to Resolute: how Ubuntu’s toolchains have evolved https://ubuntu.com/blog/from-jammy-to-resolute-how-ubuntus-t...


FYI, screenshot for the "Search and download Gemma 4" step on your guide is for qwen3.5, and when I searched for gemma-4 in Unsloth Studio it only shows Gemma 3 models.


We're still updating it haha! Sorry! It's been quite complex to support new models without breaking old ones


Speaking of which, do you think Step 3.5 Flash is going to happen or should I stop holding my breath?


Oh quants - haha I can re-investigate it - just totally forgot about them


Clients are supposed to check. For example, Apple requires a varying number of SCTs in order for Safari to trust server certificates. https://support.apple.com/en-us/103214

And yes, it does break MITM use cases, for example on Chrome: https://httptoolkit.com/blog/chrome-android-certificate-tran...


So how does that work with middleboxes? Corporate isn't about to forgo egress security (nor should they).

I don't currently MITM my LAN but my general attitude is that if something won't accept my own root certificate from the store then it's broken, disrespecting my rights, and I want nothing to do with it. Trust decisions are up to me, not some third party.


Corporate managed machines can control the software running on the computer to do anything. I'm not sure the details, but chrome certainly can support corporate MITM. There's likely some setting you have to configure first.

The default should be to reject certificates which aren't being logged, and if you as a user or corporation have a reason to use private certificates, you just configure your computer to do that. Which fully protects against the risk of normal CAs signing fraudulent certificates.



Recovering as of October 20, 2025 09:43 UTC

> [Monitoring] We are seeing error rates recovering across our SaaS services. We continue to monitor as we process our backlog.



Comments moved thither. Thanks!


Yep, this should be merged with that discussion. I’ve flagged it, hopefully the mods will take action, no point in having two identical threads.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: