HN Buddy

Daily digest of top Hacker News posts and comments

Subscribe to the HN Buddy Daily Digest

Your email will only be used for the HN Buddy Daily Digest. I will not share it with anyone.

HN Buddy Daily Digest

Thursday, December 18, 2025

Hey buddy, just catching up on Hacker News from yesterday, Thursday the 18th. Man, some wild stuff.

ACM Goes Open Access

First off, huge news for anyone in academia: ACM publications are going open access starting January 2026. Like, everything! People were talking about how it's great, but some are still a bit cynical, saying it's just a new way for publishers to make money through 'article processing charges' instead of subscriptions. Still, a step in the right direction, right?

Big Supply-Chain Attack Hits Major Tech

Then, this crazy security story: some folks apparently pwned X, Vercel, Cursor, and Discord with a supply-chain attack! They used some SVG trickery, which apparently is a known vulnerability if you're not careful with how you handle untrusted SVG files. Kinda wild that big companies still fall for that, even though some commenters said it's "common knowledge" not to allow untrusted inline SVGs.

Delivering Proven Code

There was also a big discussion about developers' jobs being to deliver code that actually works. Seems obvious, but the comments were all over the place. Someone even mentioned how AI was supposed to make coding super fast and reduce headcount, but now everyone's saying you still need to review and test everything. Classic, right?

Classical Statues Weren't Ugly

Here's a random one: turns out classical statues weren't painted horribly. You know how those reconstructions sometimes look super garish? The article says we've just gotten used to the plain white marble, and the actual colors might have been more subtle or just different than what we imagine. Pretty cool to think about, and even Google Gemini Pro had an interesting take on it.

Apple Gift Card Headaches

And get this, Apple gift cards are causing headaches! People are trying to redeem them, and Apple's flagging them as "suspected fraud" if you try to enter a code more than once, even if it's just a mistake. One person even brought up how Apple supposedly has a backdoor for the FBI in iMessage backups, which is always a fun conspiracy theory to revisit.

Just Try HTMX Already!

Oh, and there's another plea to "Please just try HTMX." You know, that frontend thing that's not React? People are still debating if it's the future or just a throwback to old AJAX. Some comments were saying that good tech doesn't always win, sometimes it's just about who has the biggest marketing budget, which is a bit depressing but probably true.

GPT-5.2-Codex for Code

Finally, some AI news: GPT-5.2-Codex is out. It's the new OpenAI model specifically for coding. People are saying it's a mixed bag – great at some things, terrible at others, kinda like humans. But apparently, the quality jump from 5.0 to 5.2 for coding tasks is pretty noticeable, which is cool for anyone using it.

Anyway, that's the gist of it, man. Catch you later!

All Stories from Today

Beginning January 2026, all ACM publications will be made open access (dl.acm.org)

We pwned X, Vercel, Cursor, and Discord through a supply-chain attack (gist.github.com)

Your job is to deliver code you have proven to work (simonwillison.net)

Classical statues were not painted horribly (worksinprogress.co)

Are Apple gift cards safe to redeem? (daringfireball.net)

Please just try HTMX (pleasejusttryhtmx.com)

GPT-5.2-Codex (openai.com)

History LLMs: Models trained exclusively on pre-1913 texts (github.com)

Ask HN: Those making $500/month on side projects in 2025 – Show and tell (news.ycombinator.com)

Independent review of UK national security law warns of overreach (www.techradar.com)

Firefox will have an option to disable all AI features (mastodon.social)

1.5 TB of VRAM on Mac Studio – RDMA over Thunderbolt 5 (www.jeffgeerling.com)

After ruining a treasured water resource, Iran is drying up (e360.yale.edu)

How China built its ‘Manhattan Project’ to rival the West in AI chips (www.japantimes.co.jp)

Skills for organizations, partners, the ecosystem (claude.com)

Slowness is a virtue (blog.jakobschwichtenberg.com)

TikTok unlawfully tracks shopping habits and use of dating apps? (noyb.eu)

How getting richer made teenagers less free (www.theargumentmag.com)

Germany: Amazon is not allowed to force customers to watch ads on Prime Video (www.zeit.de)

AI helps ship faster but it produces 1.7× more bugs (www.coderabbit.ai)

'Ghost jobs' are on the rise – and so are calls to ban them (www.bbc.com)

FunctionGemma 270M Model (blog.google)

Judge hints Vizio TV buyers may have rights to source code licensed under GPL (www.theregister.com)

Using TypeScript to obtain one of the rarest license plates (www.jack.bio)

Egyptian Hieroglyphs: Lesson 1 (www.egyptianhieroglyphs.net)

How to hack Discord, Vercel and more with one easy trick (kibty.town)

AI vending machine was tricked into giving away everything (kottke.org)

Most parked domains now serving malicious content (krebsonsecurity.com)

What is an elliptic curve? (2019) (www.johndcook.com)

GitHub Actions for self-hosted runners price increase postponed (pricetimeline.com)