Author's EHTML "framework" reminds me of HTMX. https://e-html.org/html/vs-others.html misses comparison with HTMX. Curious on the similarities and differences.
HN user
uzyn
https://uzyn.com
The site has a hidden webauthn trigger[1], an anti-pattern that automatically logs user in via passkey if it exists. A better approach, IMO, would be requiring user to click "log in".
[1]: `<input type="text" autocomplete="username webauthn" style="position:fixed;top:0;left:0;width:1px;height:1px;opacity:0;pointer-events:none" aria-hidden="true" />`
The security issue aside, seeing more companies push announcements like these on X as the only official source is a trend I'm not sure I like.
I can understand the rationale, this feels lighter and not something that belongs on status.github.com or the blog. Maybe what's actually missing is an official channel for ephemeral stuff on a domain they own, somewhere between a status page and a tweet? Just sharing an observation.
Hi HN, author here.
AIMX is a self-hosted, open-source mail server for AI agents. MCP over stdio for mailbox and mail management, OS-based auth, mail stored as Markdown on disk. Roughly how I imagine Postfix would look like if it were built for AI agents from scratch.
My AIMX intro blog, with a short 40-second demo GIF: https://uzyn.com/2026/introducing-aimx/
Happy to talk through any of the design decisions.
This is so sick!
Revision faded out the credits part, which is still really cool on its own. The full version (10m 16s) can be viewed at https://www.youtube.com/watch?v=2AnbYNudAyM
It seems our fingers have gotten thinner, or more skillful at tapping at relatively tinier buttons now. Look at how huge those buttons are.
I am aware screen size has increased tremendously, even then I think the buttons were still quite huge compared to the size of today's tappable links.
Impressive! Feels really responsive. I feel the controls are a little unusual though: WASD corresponds to actual map orientation rather than to where the character is facing. I find it confusing when playing together with a mouse, where I would expect I can hold W to move forward while using the mouse to control the character's orientation and direction.
If C uses it without the knowledge of the original owner (A or B). With proper signCount check, C would have to increment it at its end; A or B would not have known.
When A logs in with an unincremented signCount. A and the relying party are now aware of a potential cloned authenticator and disable the compromised passkey.
Same reason how signCount is useful in a non-shared passkey. Yubikeys are not supposed to be cloneable afaik, but this helps to detect if somehow it got done.
Also, why not.
You made a good point, esp. if your passkey vault is comprosed, e.g. Apple iCloud's credentials are leaked. signCount, incremented or not, would not help here in informing you of your hacked iCloud account – that would be dependent on iCloud's service itself for detecting and informing you of your compromised account.
I would still like to see big tech passkey providers implement signCount for the following 2 reasons:
1. It helps to push relying parties to implement signCount verification. Right now most relying parties do not implement it as many providers are returning `0` for `signCount`.
2. This would be an odd one, it helps against detecting leaked private keys of passkeys, if a malicious attacker, internal or external, manages to obtain the private key.
Loved the site and the companion book. Borrowed it at my local library and kept renewing it. Taught me CSS, coming out of hacking CSS with all the weird tricks at that time, and made me realize that you _can_ make beautiful semantic websites without the crazy hacks.
It's the other way around. HTMX is not suitable for client-side scripting heavy app like SPA. It's more for "traditional" AJAX-style web app.
Fair point. I wouldn't say it's by a lot because I am getting quite good results with ChatGPT's models too. A part of it could also just be confirmation bias too.
In-game sniper that you have to aim inches above the head is just not as fun, especially for an extremely fast-paced game like Unreal Tournament.
Surprised that Claude (the app, not model) not only has done well for so long, but has somewhat consistently clinched the top spot in coding, all without a feature that is considered somewhat of a basic feature for most consumer-facing AI apps.
Impressive. Would Apple be able to simply block non-Apple usage of Find My network usage simply by refusing to relay non-Apple BLE ID?
RSS was a key protocol in syndication a widely free and open web before the domination of big tech/social media. We now have new internet generation that has never known RSS, relying largely on "the algorithm" of the big tech in content syndication.
Thank you for your effort in advocating RSS support. I hope RSS makes a major come back especially with the recent events.
Very clear pitch at https://pagecord.com. The video explains it all in a few seconds. Clear distinction from being yet another minimalist blogigng platform or static site.
A 1-time fixed cost will not deter spam, it only encourages more spamming to lower the averaged per-spam cost. Email spamming requires some system set up, that's a 1-time fixed cost above $10/year but it does not stop spam.
Interaction/comment syndication would be very interesting. This is, I feel, what makes proprietary social media so addictive.
Search suggestions are hardly ever useful, but cause a massive privacy leak.
They are shipped on by default for most browsers (Chrome, Firefox, Safari), but at lease they can be disabled (search for "search suggestions" in config).
I would assume it's most browsers. You can see Google suggestions popping under the address bar as you type on many browsers: Safari, Firefox, etc.
I agree. I have been on Pivotal Tracker for over a decade. Still am. Tried Jira and a few others, usually feeling like they are too taxing on the management part.
What are alternatives that are light on the customization and day-to-day management?
Due to the public backlash, Malaysia has changed their stance and not proceeding with mandating of DNS redirection. https://www.nst.com.my/news/nation/2024/09/1102836/updated-m...
It is a terminal app. Web is only a demo. You can compile and run it on a terminal. Source: https://github.com/ggerganov/hnterm
It runs on PGlite. https://supabase.com/blog/postgres-new#how-it-works
The homepage comes with a nice video on the invention of ramen: https://www.youtube.com/watch?v=WNbb9qixsRQ
(Turn on the subtitles)
Part of the draw of WSOP is that it turns poker into somewhat of a spectator sport, especially during ESPN's coverage.
With solvers now it may need to segregate players from spectators just like chess and esports of games with fog of war. May not all be a bad thing as you can possibly start introducing live commentary to live audience.
I have always believed this to be the reason.
Just sharing, there's a live real money poker room that implements mental poker with an actual gaming license implemented on Ethereum. https://virtue.poker