source&pool
A daily wire of long-form journalism, video, and discourse — filed, tagged, and laid out flat.
VOL. I·NO. 01
THURSDAY, SEPTEMBER 17, 2026
Hacker News3767X 主题热门3646CNBC79MacRumors69YahooFinance589to5Mac57Kotaku44Verge389to5Google32aihot32IGN32NintendoLife31Gematsu27Engadget26TechCrunch26BusinessInsider25Eurogamer25Guardian18Polygon17NBC15CNET14Fortune13FoxBusiness13NPR13Wccftech13bgr12Mashable12SeekingAlpha12Gizmodo11PushSquare11USAToday11Notebookcheck10WIRED10TechPowerUp9AppleInsider8CNN8GameInformer8Investor'sBusinessDaily8NewYorkPost8VideoGamesChronicle8WindowsCentral8ABC7CBS7Fox7ArsTechnica6NintendoEverything6CrudeOilPricesToday6BleepingComputer5GamesIndustry.biz5PureXbox5SamMobile5Variety5AlJazeera4AndroidPolice4CoinDesk4DigitalFoundry4GameRant4GSMArena4PetaPixel4SlashGear4Register4CTech3ChromeUnboxed3DW3Jalopnik3Lifehacker3Motor13Blizzard3XBOXWire3PCMag3PCWorld3RockPaperShotgun3RPGSite3Space3Hacker3TweakTown3VideoCardz3WarhammerCommunity3WindowsLatest3Yahoo3ZDNET3404Media2Aftermath2AndroidCentral2AOL2AwfulAnnouncing2BleedingCool2BuzzFeed2CanonRumors2CyberSecurityNews2Deadline2DroidLife2DualShockers2Euronews2EventHubs2MotleyFool2FratelloWatches2Futurism2GameDeveloper2GearPatrol2Hodinkee2KITCO2LosAngelesTimes2MassivelyOverpowered2Maxroll2MP1st2MyNintendo2Newser2PaulKrugman2PokémonGOHub2RoadtoVR2SouthChinaMorningPost2SeattleTimes2SFGATE2Conversation2Intercept2NextWeb2Tom'sGuide2UploadVR2YourTango280Level1ABC111AboveLaw1ageofempires1AVClub1Benzinga1Billboard1BloodyDisgusting1Borderlands1Boston1Bungie1Yahoo!FinanceCanada1CineD1CnEVPost1comicbook1CreativeBloq1Cyclingnews1DailyKos1Defector1DenverPost1derekthompson1DigitalCameraWorld1Draftsim1CNN1flatpanelshd1FrequentMiler1GAMINGbible1garymarcus.substack1GeekWire1GeekyGadgets1Hackaday1HollywoodReporter1Independent1InsiderGaming1InterconnectsAI1InterestingEngineering1KSL1Lloyd'sList1WPLGLocal101Macworld1Mediaite1Mercury1MonochromeWatches1MortgageDaily1MPR1Nature1SemiAnalysis1Newsweek1nylon.com.sg1NYT1OregonLive1PageSix1PCGamesN1Pokemon1PittsburghPost-Gazette1QuantaMagazine1qz1SammyGuru1CultureMapSanAntonio1ScienceAlert1ScientificAmerican1Semafor1YahooFinanceSingapore1YahooSingapore1SportsIllustrated1SimpleFlying1supercarblondie1YahooTech1Tedium1TelecomTalk1GameBusiness1TheGamer1TimeExtension1LongmontTimes-Call1TmoNews1TopGear1TwistedVoxel1YahooFinanceUK1UnHerd1WhatHi-Fi?1WOWT1WPBF1WRAL1YGOrganization1
  1. 001Hacker NewsSEP · 17English

    A Third of European Companies Turned DMARC on and Get No Reports Back

    A third of European companies with DMARC records lack reporting addresses, leaving their email authentication policies blind to spoofing and misconfigurations. Among those with reporting configured, most send feedback to external domains rather than their own, distributed across thousands of providers.

    By Chris McCabe
  2. 002Hacker NewsSEP · 17English

    Device Bound Session Credentials in Asp.net Core

    Device Bound Session Credentials (DBSC) is an experimental web standard implemented in ASP.NET Core that ties session cookies to a device's private key, preventing cookie replay attacks. When a stolen cookie is copied to another machine, it becomes useless for session refresh since only the original device can sign the cryptographic challenge. This significantly reduces the attack window from weeks to minutes by forcing short-lived cookies that require device-based proof to refresh.

    By Maarten Balliauw
  3. 003Hacker NewsSEP · 17English

    Shodan indexes over 47.000 exposed Ollama instances

    Shodan has indexed over 47,000 exposed Ollama instances without authentication, allowing attackers to run prompts, steal models, and exploit vulnerabilities on systems including cloud GPUs.

    By soltanov
  4. 004Hacker NewsSEP · 17English

    I gave my agents a heartbeat

    A construction company founder describes implementing a "heartbeat" monitoring system for AI agents to detect unauthorized changes to their core identity and behavior. The system creates cryptographic fingerprints of agent prompts and verifies them before each run, and the founder is extending this approach outward as a lens for external agents to verify the company's claims and values.

    By ML Systems LLC; Sal Parvez
  5. 005Hacker NewsSEP · 16English

    Signal Enables Phone Number-Less Registration in Beta

    Signal has launched phone number-less registration in beta for Android 8.28, addressing a long-requested feature. The $2.99 one-time fee prevents spam while protecting user privacy through zero-knowledge proofs, with accounts secured via Account ID, Account Key, and optional 2FA.

    By Fria Reyes
  6. 006Hacker NewsSEP · 16English

    Cookie converter and Claude session check I use

    A browser-based tool that converts cookies between Netscape cookies.txt and JSON formats (Cookie-Editor, Puppeteer, key-value, or raw headers), with an additional feature to check whether Claude session cookies are still active and display account plan and usage limits.

    By kirill_orlov
  7. 007Hacker NewsSEP · 16English

    Fee of $3 for a Signal account without a number in new Android beta

    Signal 8.28 beta introduces optional phone-number-free registration for $3 USD via in-app purchase, using zero-knowledge proofs to prevent payment-account linkage. Users receive an Account ID and Account Key for access, with optional username and two-factor authentication support via TOTP, though account recovery is impossible if credentials are lost.

    By Greyson-Signal
  8. 008GizmodoSEP · 16English

    Apple Explains How Its New iPhone 18 Photo Verification Actually Works

    Apple is launching a photo verification feature for iPhone 18 Pro that cryptographically signs sensor data to prove authenticity and prevent deepfake tampering. The system uses a secure camera mode that signs pixel data at capture, processes it through Apple's Private Cloud Compute with quantum-resistant encryption, and produces a verifiable digital certificate for the final image.

    By Bruce Gil
  9. 009Hacker NewsSEP · 16English

    What is LLMjacking, and why should IT pros care?

    LLMjacking is a cybersecurity threat where attackers use stolen cloud credentials to gain unauthorized access to victims' paid AI model services and computing resources. The tactic has evolved from simple freeloading to building offensive attack tools, with threat actors now leveraging compromised LLMs for malicious purposes rather than just personal use. IT professionals should implement defenses like short-lived credentials, least-privilege access, usage monitoring, and strong authentication practices.

    By Billy Hurley
  10. 010Hacker NewsSEP · 16English

    Show HN: LaunchPad-Lite – Open-Source Next.js 15 with Better Auth and Drizzle

    LaunchPad-Lite is a free, open-source Next.js 15 starter template featuring authentication via Better Auth, Drizzle ORM with PostgreSQL, and a pre-built dashboard with dark mode support. Built by BZDevelopments and MIT licensed, it provides a foundation for full-stack applications with no additional dependencies or costs.

    By BZDevelopments
  11. 011Hacker NewsSEP · 16English

    Residential proxies as the next front in the AI wars

    AI providers face obstacles accessing fresh internet data as publishers monetize access and domains block scraper bots. Authentication requirements emerge as a solution, but raise privacy concerns similar to UK age-verification laws. Residential proxies—IP addresses from ordinary broadband users—offer a workaround to bypass VPN detection and access restrictions.

    By Martin Anderson
  12. 012Hacker NewsSEP · 16English

    Signal registration without a phone number now available in Android beta

    Signal has launched Signal Login, an optional registration method allowing users to create accounts without phone numbers, first on Android then iOS. The feature requires a one-time $2.99 payment to prevent spam, uses zero-knowledge proofs for privacy, and remains optional alongside traditional phone-number-based registration.

    By AboutSignal