HN Buddy

Daily digest of top Hacker News posts and comments

Subscribe to the HN Buddy Daily Digest

Your email will only be used for the HN Buddy Daily Digest. I will not share it with anyone.

HN Buddy Daily Digest

Monday, September 8, 2025

Hey buddy, What's up? Just saw some interesting stuff pop up on Hacker News today, wanted to give you the quick rundown.

NPM Packages Got Hacked!

First off, big yikes in the tech world. Two super popular NPM packages, debug and chalk, got compromised. Like, major supply chain attack. People were freaking out because these are used everywhere. In the comments, it got pretty real – someone mentioned how even passkeys can be a pain, like trying to use a Yubikey on your phone. And autofill not working sometimes? Apparently, that's how even Troy Hunt got phished when he was tired. Wild. Oh, and one guy just wants a "no color" option for everything because he finds color annoying, haha.

Signal's New Paid Backups

Remember Signal? They just rolled out paid secure backups. Sounds good, right? But here's the kicker: people in the comments were pretty annoyed because Signal apparently *prevents* iOS users from using Apple's own free, encrypted local backups. So now they're charging for something they arguably made harder to do for free. A bit of a self-inflicted problem, some said, especially since they use proprietary backup formats.

"Chat Control" Is Coming?

Big privacy alert: there's an article called "Chat Control Must Be Stopped". It's about this push, probably in the EU, to force companies to scan all your private messages. Super creepy, right? Everyone's worried about the slippery slope and how it just opens up all our private conversations to potential government snooping, and that even if the "good guys" are supposed to have access, it makes the systems vulnerable to anyone.

Meta Accused of Hiding Child Safety Research

Another day, another Meta scandal. The Washington Post reported that Meta apparently suppressed research that showed their VR platforms and other stuff had negative impacts on kids. Classic corporate move, prioritizing profits over actual safety. The comments were, predictably, full of people calling them out for it and talking about the ongoing issues with child safety online.

Self-Hosting Your Photos with Immich

On a more positive tech note, there's this cool project called Immich. It's like a self-hosted Google Photos, so you can manage all your pictures and videos without relying on big cloud companies. People were sharing all sorts of advanced backup strategies, like using rclone with Backblaze B2, or setting up a NAS. Sounds like a good option if you want more control over your digital memories.

Turning an iPhone into a "Dumbphone"

This one was pretty clever: someone figured out how to use Apple's Configurator tool to turn their iPhone into a "dumbphone" – basically stripping out all the distracting apps and features. The comments were full of people sharing their own tricks for fighting phone addiction, like having a spouse set a Screen Time passcode they don't know, or just leaving the phone in the garage as much as possible. Really makes you think about how much time we spend staring at these things.

Tesla's Market Share Dropping

And finally, a bit of business news: Tesla's EV market share in the US is at its lowest since 2017. Turns out, when you don't release a new vehicle for five years (besides the Cybertruck, which is kinda niche) and everyone else finally catches up, people start buying other EVs. Comments were pointing out their aging models and build quality issues. Though, one person had an interesting take, arguing that Tesla actually *wants* their market share to drop because it means more companies are making EVs, which was their original goal.

Alright, that's the gist of it. Talk soon!

All Stories from Today

NPM debug and chalk packages compromised (www.aikido.dev)

Signal Secure Backups (signal.org)

Chat Control Must Be Stopped (www.privacyguides.org)

14 Killed in anti-government protests in Nepal (www.tribuneindia.com)

Immich – High performance self-hosted photo and video management (github.com)

Meta suppressed research on child safety, employees say (www.washingtonpost.com)

iPhone dumbphone (stopa.io)

Experimenting with Local LLMs on macOS (blog.6nok.org)

How RSS beat Microsoft (buttondown.com)

Ex-WhatsApp cybersecurity head says Meta endangered billions of users (www.theguardian.com)

VMware's in court again. Customer relationships rarely go this wrong (www.theregister.com)

Liquid Glass in the Browser: Refraction with CSS and SVG (kube.io)

OpenWrt: A Linux OS targeting embedded devices (openwrt.org)

A clickable visual guide to the Rust type system (rustcurious.com)

Tesla market share in US drops to lowest since 2017 (www.reuters.com)

Will Amazon S3 Vectors kill vector databases or save them? (zilliz.com)

Clankers Die on Christmas (remyhax.xyz)

The Storm Hits the Art Market (news.artnet.com)

Google gets away almost scot-free in US search antitrust case (www.computerworld.com)

AMD claims Arm ISA doesn't offer efficiency advantage over x86 (www.techpowerup.com)

ICEBlock handled my vulnerability report in the worst possible way (micahflee.com)

AI might yet follow the path of previous technological revolutions (www.economist.com)

I have left Branch and am no longer involved with Nova Launcher (teslacoilapps.com)

Job mismatch and early career success (www.nber.org)

Alterego: Thought to Text (www.alterego.io)

Dietary omega-3 polyunsaturated fatty acids as a protective factor of myopia (bjo.bmj.com)

How inaccurate are Nintendo's official emulators? [video] (www.youtube.com)

YouTube views are down (don't panic) (www.jeffgeerling.com)

Indiana Jones and the Last Crusade Adventure Prototype Recovered for the C64 (www.gamesthatwerent.com)

America is in a serious jobs slump (www.cnn.com)