Hacker News Digest

Saturday, May 16, 2026

In This Issue

  • Hacker News
  • Mitchellh – I strongly believe there are entire companies now under AI psychosis
  • California bill would require patches or refunds when online games shut down
  • U.S. DOJ demands Apple and Google unmask over 100k users of car-tinkering app
  • Bun Rust rewrite: "codebase fails basic miri checks, allows for UB in safe rust"
  • A 0-click exploit chain for the Pixel 10
  • 'No Way to Prevent This,' Says Only Package Manager Where This Regularly Happens
  • The Siri for Families Apple Will Never Build
  • Frontier AI has broken the open CTF format
  • Too dangerous or just too expensive? The real reason Anthropic is hiding Mythos

Zipper Data Brief

May 16, 2026
Your daily digest of the best from Hacker News

Top 6 Trending

#1
1458 points · reasonableklout · comments
Discussion Summary
The discussion centers on "AI psychosis"—organizations blindly adopting AI tools for competitive pressure and ego rather than genuine need, leading to unmaintainable codebases, false productivity metrics, and potential future catastrophic failures. While AI tools offer real value when used judiciously by competent engineers, top-down mandates driven by management FOMO are creating a dangerous disconnect between token-burning metrics and actual software quality.
#2
502 points · Lihh27 · comments
Discussion Summary
The discussion centers on whether California's bill mandating patches or refunds for shut-down online games is effective policy, with commenters debating unintended consequences (like forcing subscription models) versus the genuine consumer harm from losing purchased digital content, while also noting the law's narrow scope and questioning why similar protections don't extend to other software.
#3
432 points · tencentshill · comments
Discussion Summary
The DOJ's demand to unmask 100k app users raises concerns about mass surveillance and privacy overreach, though some commenters acknowledge the app enables illegal emissions violations, highlighting the tension between right-to-repair freedoms and enforcement of environmental regulations.
#4
427 points · ndiddy · comments
Discussion Summary
The Bun project's AI-generated Rust rewrite of previously Zig code contains memory safety violations that should have been caught during review, sparking debate about whether AI-generated code at scale can be responsibly maintained and whether this represents reckless development or acceptable growing pains in a transition process.
#5
389 points · happyhardcore · comments
Discussion Summary
The discussion centers on a critical 0-click exploit in Android's kernel driver, prompting concerns about AI-powered features expanding attack surface, questions about Google's security response time compared to Apple, and broader frustrations with how manufacturers prioritize convenience features over security fundamentals.
#6
368 points · alligatorplum · comments
Discussion Summary
The discussion debates whether npm's supply chain attack vulnerability is uniquely endemic to JavaScript or a broader package manager problem, with proposed mitigations ranging from cooldown periods to better secrets management, while acknowledging that other ecosystems (Python, Ruby, Rust) also face similar risks.

AI / Machine Learning

90 points · rcarmo · comments
Discussion Summary
Users discuss why Apple hasn't built family-focused software despite clear demand, citing organizational fragmentation, privacy/liability concerns, and the technical difficulty of context-aware AI that respects boundaries without becoming surveillance. Meanwhile, some founders reveal they're filling this gap with specialized family apps like Life360 and Leto.
174 points · frays · comments
Discussion Summary
The discussion centers on whether AI has fundamentally broken CTF competitions by automating solutions, with commenters split between those viewing it as the death of a skill-based competition (preventing meaningful learning) and those seeing it as inevitable technological evolution requiring adaptation rather than existential threat.
146 points · chbint · comments
Discussion Summary
The discussion is divided between skeptics who believe Mythos is merely incrementally better than existing models and that the "too dangerous" narrative is marketing hype (possibly timed for an IPO), and those who accept that both cost constraints and genuine security risks are legitimate reasons for limited release. An Anthropic employee countered that the company plans eventual broad deployment once adequate safeguards exist, but critics remain suspicious of the framing.
97 points · dtnewman · comments
Discussion Summary
The discussion mocks a satirical tool that encourages wasteful AI token spending, with commenters drawing parallels to outdated productivity metrics like lines of code while highlighting the absurdity of companies measuring employee value by AI budget consumption rather than actual output quality.
351 points · tjek · comments
Discussion Summary
A company closed its bug bounty program because AI-generated submissions flooded it with low-quality reports, sparking debate about solutions like verification fees, reputation systems, and AI-assisted filtering rather than complete program elimination.

Startups / Business

278 points · boramalper · comments
Discussion Summary
Zulip's founder is joining Anthropic and donating the company to a newly created nonprofit foundation, drawing mixed reactions: some praise the sustainability move and foundation structure, while others criticize the timing, the AI company's impact on open source, and question whether the transition can maintain the project's quality without the core team.
177 points · tormeh · comments
Discussion Summary
The discussion reveals a satirical website mocking revenue fraud schemes where startups trade worthless transactions with each other to inflate financials—commenters note the parody brilliantly highlights real accounting fraud practices like VAT carousels and round-tripping, while several joke that it's indistinguishable from actual VC-backed startup behavior.
54 points · jorisw · comments
Discussion Summary
The article conflates annualized revenue run rate ($19B) with actual revenue to date ($5B+), creating a misleading headline about a discrepancy that doesn't actually exist. Commenters note this is standard practice for private companies to use vague figures in legal declarations, and the real numbers align fine once you understand what each metric represents.
18 points · YoungGato · comments
Discussion Summary
The project received criticism for being limited to New York City only while the title suggests nationwide coverage, and concerns were raised about the health and safety risks of raw dairy consumption, with some users reporting the site didn't work for their locations.
80 points · steveharing1 · comments
Discussion Summary
Users express deep concern about OpenAI gaining access to financial data through Plaid, citing privacy risks, potential for misuse of sensitive information, security vulnerabilities, and the normalization of surrendering personal data to corporations without adequate safeguards.

More Stories (34)

237 points · tcp_handshaker · comments
174 points · tosh · comments
90 points · mxfh · comments
40 points · jruohonen · comments
43 points · galfarragem · comments
195 points · bookofjoe · comments
40 points · Brajeshwar · comments
17 points · diodorus · comments
67 points · krunck · comments
33 points · mmcclure · comments
Created by Zipper Data Co.  · 2026-05-16 12:01 UTC  · Unsubscribe

Get digests like this delivered to your inbox every morning.

Subscribe Free