Cagent Comes to Docker Desktop with Built-In IDE Support through ACP
Docker Desktop now includes cagent bundled out of the box. This means developers can start building AI agents without a separate installation step. For those unfamiliar with cagent: itâs Dockerâs open-source tool that lets you build AI agents using YAML configuration files instead of writing code. You define the agentâs behavior and tools, and cagent⌠â Read more
MCP Horror Stories: The WhatsApp Data Exfiltration Attack
This is Part 5 of our MCP Horror Stories series, where we examine real-world security incidents that highlight the critical vulnerabilities threatening AI infrastructure and demonstrate how Dockerâs comprehensive AI security platform provides protection against these threats. Model Context Protocol (MCP) promises seamless integration between AI agents and communication platforms like WhatsApp, enabling automated message⌠â Read more
Hack Club has been handling childrenâs data for 4 years without a privacy policy
Comments â Read more
Checkout.com hacked, refuses ransom payment, donates to security labs
Article URL: https://www.checkout.com/blog/protecting-our-merchants-standing-up-to-extortion
Comments URL: https://news.ycombinator.com/item?id=45912698
Points: 503
# Comments: 227 â Read more
Docker Desktop 4.50: Indispensable for Daily Development
Docker Desktop 4.50 represents a major leap forward in how development teams build, secure, and ship software. Across the last several releases, weâve delivered meaningful improvements that directly address the challenges you face every day: faster debugging workflows, enterprise-grade security controls that donât get in your way, and seamless AI integration that makes modern development⌠â Read more
Ignite Realtime Blog: First release candidate of Smack 4.5 published
The Smack developers are happy to announce the availability the first release candidate (RC) of Smack 4.5.0.
The upcoming Smack 4.5 release contains many bug fixes and improvements. Please consider testing this release candidate in your integration stages and report back any issues you may found. The more people are actively testing release candidates, the less issues will remain in the actual release.
Smac ⌠â Read more
Plasma Mobile 6.5 keeps improving
As part of the KDE Plasma 6.5 release, we also got a new release of Plasma Mobile. As thereâs a lot of changes, improvements, and new features in Plasma Mobile 6.5, the Plasma Mobile Team published a blog post to highlight them all. The biggest improvement is probably the further integration of Waydroid, a necessary evil to run Android applications until the Plasma Mobile ecosystem manages to become a bit more well-rounded. Waydroid can now be managed straight fro ⌠â Read more
Docker Engine v29: Foundational Updates for the Future
This post is for Linux users running Docker Engine (Community Edition) directly on their hosts. Docker Desktop users donât need to take any action â Engine updates are included automatically in future Desktop releases. Docker Engine v29 is a foundational release that sets the stage for the future of the Docker platform. While it may⌠â Read more
KServe becomes a CNCF incubating project
The CNCF Technical Oversight Committee (TOC) has voted to accept KServe as a CNCF incubating project. KServe joins a growing ecosystem of technologies tackling real-world challenges at the edge of cloud native infrastructure. What is KServe?⌠â Read more
OpenFGA Becomes a CNCF Incubating Project
The CNCF Technical Oversight Committee (TOC) has voted to accept OpenFGA as a CNCF incubating project. What is OpenFGA? OpenFGA is an authorization engine that addresses the challenge of implementing complex access control at scale in⌠â Read more
Lima becomes a CNCF incubating project
The CNCF Technical Oversight Committee (TOC) has voted to accept Lima as a CNCF incubating project. Lima enables secure, isolated environments for running cloud native and AI workloads. What is Lima? Where Does It Fit in⌠â Read more
Connect to Remote MCP Servers with OAuth in Docker
In just a year, the Model Context Protocol (MCP) has become the standard for connecting AI agents to tools and external systems. The Docker MCP Catalog now hosts hundreds of containerized local MCP servers, enabling developers to quickly experiment and prototype locally. We have now added support for remote MCP servers to the Docker MCP⌠â Read more
Meta Is Killing Off the External Facebook Like Button
Meta is retiring Facebookâs external Like and Share buttons for third-party websites on February 10, 2026, officially closing the book on a once-dominant traffic driver as usage declines and Facebookâs role within Meta continues to shrink.Engadget reports: The blog post from Meta explains that site admins shouldnât have to take any additional steps as a result of the ⌠â Read more
Wikipedia Urges AI Companies To Use Its Paid API, and Stop Scraping
Wikipedia on Monday laid out a simple plan to ensure its website continues to be supported in the AI era, despite its declining traffic. From a report: In a blog post, the Wikimedia Foundation, the organization that runs the popular online encyclopedia, called on AI developers to use its content âresponsiblyâ by ensuring its contributions are ⌠â Read more
ProcessOne: On Signal Protocol and Post-Quantum Ratchets
Signal improved its protocol to prepare encrypted messaging for the quantum era.
They call the improvement âTriple Ratchetâ (or SPQR = Signal Post-Quantum Ratchet).
[Signal Protocol and Post-Quantum Ratchets\â¨\â¨We are excited to announce a significant advancement in the security ⌠â Read more
Help Define the Future of Development â Take the Docker State of Application Development Survey 2025
Welcome to the fourth annual Docker State of Application Development survey! Please help us better understand and serve the application development community with just 20 minutes of your time. We want to know where youâre focused, what youâre working on, and what is most important to you. Your thoughts and feedback will help us build⌠â Read more
Recursive DNS
I think I did not blog about it, but I switched back to a self-hosted AdGuard Home instance quite some time ago from NextDNS. To reduce my number of subscriptions, but also to increase my control over important infrastructure I use. â Read more
FreeBSD now builds reproducibly and without root privilege
The FreeBSD Foundation is pleased to announce that it has completed work to build FreeBSD without requiring root privilege. We have implemented support for all source release builds to use no-root infrastructure, eliminating the need for root privileges across the FreeBSD release pipeline. This work was completed as part of the program commissioned by the Sovereign Tech Agency. ⍠FreeBSD Foundation blog This is gre ⌠â Read more
Rust Is Coming To Debianâs APT Package Manager
A maintainer of Debianâs Advanced Package Tool (APT) âhas announced plans to introduce hard Rust dependencies into APT starting May 2026,â reports the blog Itâs FOSS.
The integration targets critical areas like parsing .deb, .ar, and tar files plus HTTP signature verification using Sequoia. [APT maintainer Julian Andres Klode] said these components âwould strongly benefit from m ⌠â Read more
Thank you for https://www.uninformativ.de/blog/postings/2025-11-09/0/POSTING-en.html, @movq@www.uninformativ.de! I never configured systemd timers, but I would have gotten it wrong, too. Good to know when I eventually stumble across that in the future. Iâm still using cron. Yeah, its field order sucks and I always have to look it up (because I donât deal with that all that often). Indeed, systemdâs order sounds more reasonable.
@lyse@lyse.isobeef.org Itâs possible to run the validator locally (my blog generator scripts do that):
https://validator.w3.org/nu/about.html
That way you donât forget. đĽł
What 986 million code pushes say about the developer workflow in 2025
Nearly a billion commits later, the way we ship code has changed for good. Hereâs what the 2025 Octoverse data says about how devs really work now.
The post What 986 million code pushes say about the developer workflow in 2025 appeared first on [The GitHub Blog](https: ⌠â Read more
Code-level telemetry instrumentation: From âoh hell noâ to âworth itâ
A platform engineerâs guide to developer buy-in Originally published on the authorâs personal blog, whitneylee.com As platform engineers, we want the holistic system insights that instrumented code can give us â yes, please. With code-level insights⌠â Read more
Self-Hosted Human and Machine Identities in Keycloak 26.4
Keycloak is a leading open source solution in the cloud-native ecosystem for Identity and Access Management, a key component of accessing applications and their data. With the release of Keycloak 26.4, weâve added features for both⌠â Read more
Most DevSecOps Advice Is Useless without ContextâHereâs What Actually Works
Generic DevSecOps advice may sound good on paper, but it often fails in practice because it ignores team context, workflow, and environment-specific needs. Overloaded controls, broad policies, and misapplied tools disrupt the flow of development. And once flow breaks, security measures are the first to get bypassed. The way forward isnât more rules but smarter⌠â Read more
@prologic@twtxt.net Letâs go through it one by one. Hereâs a wall of text that took me over 1.5 hours to write.
The criticism of AI as untrustworthy is a problem of misapplication, not capability.This section says AI should not be treated as an authority. This is actually just what I said, except the AI phrased/framed it like it was a counter-argument.
The AI also said that users must develop âAI literacyâ, again phrasing/framing it like a counter-argument. Well, that is also just what I said. I said you should treat AI output like a random blog and you should verify the sources, yadda yadda. That is âAI literacyâ, isnât it?
My text went one step further, though: I said that when you take this requirement of âAI literacyâ into account, you basically end up with a fancy search engine, with extra overhead that costs time. The AI missed/ignored this in its reply.
Okay, so, the AI also said that you should use AI tools just for drafting and brainstorming. Granted, a very rough draft of something will probably be doable. But then you have to diligently verify every little detail of this draft â okay, fine, a draft is a draft, itâs fine if it contains errors. The thing is, though, that you really must do this verification. And I claim that many people will not do it, because AI outputs look sooooo convincing, they donât feel like a draft that needs editing.
Can you, as an expert, still use an AI draft as a basis/foundation? Yeah, probably. But hereâs the kicker: You did not create that draft. You were not involved in the âthought processâ behind it. When you, a human being, make a draft, you often think something like: âOkay, I want to draw a picture of a landscape and thereâs going to be a little house, but for now, Iâll just put in a rough sketch of the house and add the details later.â You are aware of what you left out. When the AI did the draft, you are not aware of whatâs missing â even more so when every AI output already looks like a final product. For me, personally, this makes it much harder and slower to verify such a draft, and I mentioned this in my text.
Skill Erosion vs. Skill EvolutionYou, @prologic@twtxt.net, also mentioned this in your car tyre example.
In my text, I gave two analogies: The gym analogy and the Google Translate analogy. Your car tyre example falls in the same category, but Geminiâs calculator example is different (and, again, gaslight-y, see below).
What I meant in my text: A person wants to be a programmer. To me, a programmer is a person who writes code, understands code, maintains code, writes documentation, and so on. In your example, a person who changes a car tyre would be a mechanic. Now, if you use AI to write the code and documentation for you, are you still a programmer? If you have no understanding of said code, are you a programmer? A person who does not know how to change a car tyre, is that still a mechanic?
No, youâre something else. You should not be hired as a programmer or a mechanic.
Yes, that is âskill evolutionâ â which is pretty much my point! But the AI framed it like a counter-argument. It didnât understand my text.
(But what if thatâs our future? What if all programming will look like that in some years? I claim: Itâs not possible. If you donât know how to program, then you donât know how to read/understand code written by an AI. You are something else, but youâre not a programmer. It might be valid to be something else â but that wasnât my point, my point was that youâre not a bloody programmer.)
Geminiâs calculator example is garbage, I think. Crunching numbers and doing mathematics (i.e., âcomplex problem-solvingâ) are two different things. Just because you now have a calculator, doesnât mean itâll free you up to do mathematical proofs or whatever.
What would have worked is this: Letâs say youâre an accountant and you sum up spendings. Without a calculator, this takes a lot of time and is error prone. But when you have one, you can work faster. But once again, thereâs a little gaslight-y detail: A calculator is correct. Yes, it could have âbugsâ (hello Intel FDIV), but its design actually properly calculates numbers. AI, on the other hand, does not understand a thing (our current AI, that is), itâs just a statistical model. So, this modified example (âaccountant with a calculatorâ) would actually have to be phrased like this: Suppose thereâs an accountant and you give her a magic box that spits out the correct result in, what, I donât know, 70-90% of the time. The accountant couldnât rely on this box now, could she? Sheâd either have to double-check everything or accept possibly wrong results. And that is how I feel like when I work with AI tools.
Gemini has no idea that its calculator example doesnât make sense. It just spits out some generic âargumentâ that it picked up on some website.
3. The Technical and Legal Perspective (Scraping and Copyright)The AI makes two points here. The first one, I might actually agree with (âbad bot behavior is not the fault of AI itselfâ).
The second point is, once again, gaslighting, because it is phrased/framed like a counter-argument. It implies that I said something which I didnât. Like the AI, I said that you would have to adjust the copyright law! At the same time, the AI answer didnât even question whether itâs okay to break the current law or not. It just said âlol yeah, change the lawsâ. (I wonder in what way the laws would have to be changed in the AIâs âopinionâ, because some of these changes could kill some business opportunities â or the laws would have to have special AI clauses that only benefit the AI techbros. But I digress, that wasnât part of Geminiâs answer.)
tl;drExcept for one point, I donât accept any of Geminiâs âcriticismâ. It didnât pick up on lots of details, ignored arguments, and I can just instinctively tell that this thing does not understand anything it wrote (which is correct, itâs just a statistical model).
And it framed everything like a counter-argument, while actually repeating what I said. Thatâs gaslighting: When Alice says âthe sky is blueâ and Bob replies with âwhy do you say the sky is purple?!â
But it sure looks convincing, doesnât it?
Never againThis took so much of my time. I wonât do this again. đ
Leaving Meta and PyTorch
Article URL: https://soumith.ch/blog/2025-11-06-leaving-meta-and-pytorch.md.html
Comments URL: https://news.ycombinator.com/item?id=45843948
Points: 500
# Comments: 112 â Read more