Published on February 21, 2026 at 06:01 CET (UTC+1)
Keep Android Open (1241 points by LorenDB)
The F-Droid team warns that Google's planned restrictions on sideloading apps on Android are still active, despite public perception that Google backtracked. They argue a misleading PR campaign has created a false sense of security, and the changes will effectively make Google the gatekeeper of all Android devices. They are launching a campaign (keepandroidopen.org) to rally users who care about Android's open platform before it's too late.
Turn Dependabot Off (350 points by todsacerdoti)
The author argues that Dependabot generates excessive noise and misguided security alerts, using a case study of a minor, rarely-used library fix that triggered thousands of pointless pull requests. They claim Dependabot's compatibility scores and CVSS assessments can be nonsensical, creating busywork instead of real security. The recommendation is to turn it off and replace it with scheduled, more targeted actions like govulncheck and dependency update tests.
I found a Vulnerability. They found a Lawyer (423 points by toomuchtodo)
A diving instructor and platform engineer discovered a critical vulnerability in a major diving insurer's member portal during a trip. After responsibly disclosing it with a standard embargo, the organization's response involved legal threats rather than collaboration. The author waited over eight months post-embargo to publish the story, noting the bug is now fixed but expressing concern that affected users may not have been notified.
CERN rebuilt the original browser from 1989 (2019) (126 points by tylerdane)
CERN has created a working simulation of the original WorldWideWeb browser from 1990 within a modern web browser. This 2019 project celebrates the 30th anniversary of the web's invention, allowing users to experience the primitive, NeXTSTEP-based interface. It serves as an interactive historical artifact to demonstrate the humble origins of today's web technology.
Facebook is cooked (856 points by npilk)
The author describes logging into Facebook after years to find the main News Feed dominated by AI-generated thirst traps, sloppy memes, and low-quality, engagement-bait content not from followed friends or pages. This illustrates Facebook's perceived decline into a "slop conveyor belt" that relies on AI-generated and lizard-brain-targeting content to fill the void left by departing real users, damaging its core product.
Ggml.ai joins Hugging Face to ensure the long-term progress of Local AI (693 points by lairv)
The founder of ggml.ai and llama.cpp announces the team is joining Hugging Face to ensure the long-term, open progress of Local AI (running models locally). The core libraries will remain open-source and community-driven, with the team gaining resources to scale support. This move aims to solidify the ecosystem for on-device AI against the backdrop of increasing centralization by large corporations.
Wikipedia deprecates Archive.today, starts removing archive links (356 points by nobody9999)
Wikipedia has deprecated and blacklisted the archive site Archive.today after it was used to execute a DDoS attack against a blogger and was caught altering the content of archived web pages. Editors concluded the site is unreliable and violates Wikipedia's external link policies. The decision triggers the massive task of removing over 695,000 links to the archive from Wikipedia pages.
Cord: Coordinating Trees of AI Agents (48 points by gfortaine)
The author introduces "Cord," a conceptual framework for coordinating trees of AI agents that focuses on dynamic task decomposition. It critiques existing multi-agent frameworks (LangGraph, CrewAI, AutoGen, OpenAI Swarm) for being too rigid, role-bound, unstructured, or minimal. Cord proposes a system where an orchestrator agent dynamically breaks work into a tree of dependent sub-tasks, which are then executed and synthesized, allowing for more flexible and complex workflows.
What Is OAuth? (63 points by cratermoon)
The original author of OAuth provides a high-level explanation to demystify the protocol, framing it around the "magic link" authentication metaphor. He focuses on the core historical rationale: allowing a user to grant a third-party application limited access to a resource without sharing their credentials. The post aims to cut through the accumulated complexity and explain the simple, foundational use-case that motivated OAuth's design.
Show HN: PIrateRF – Turn a $20 Raspberry Pi Zero into a 12-mode RF transmitter (19 points by metadescription)
PIrateRF is an open-source project that transforms a Raspberry Pi Zero W into a portable, multi-mode RF transmitter controlled via a web browser. It spawns a WiFi hotspot, allowing users to generate various signals like FM radio, digital modes, and more. The project positions itself as a low-cost "RF Swiss Army knife" for experimentation and hacking the airwaves.
Trend: The Strategic Consolidation of Open-Source Local AI.
Trend: Multi-Agent Systems Shifting from Static to Dynamic Coordination.
Trend: AI-Generated Content Flooding User Feeds and Eroging Platform Quality.
Trend: AI-Powered DevTools Creating Alert Fatigue and Requiring Sophistication.
Trend: Increasing Legal Risks for Security Research, Including in AI Systems.
Trend: Data Provenance and Integrity Becoming Critical for AI/Web Ecosystems.
Analysis generated by deepseek-reasoner