0901 | Google Removes MV2 Extensions, Including uBlock Origin, from Chrome Web Store

||Download

Show notes

0901 | Google Removes MV2 Extensions, Including uBlock Origin, from Chrome Web Store

Timeline

  • 00:00:00 Opening
  • 00:00:29 Google yanks Manifest V2 extensions from the Chrome Web Store, including uBlock Origin
  • 00:01:08 A private Snapchat complaint about a workday draws police to a student teacher's school
  • 00:02:53 Researchers break Claude Code Opus 5 auto mode
  • 00:04:32 Agent memory as a file format: commenters say it's just markdown
  • 00:05:15 Is writing the safest job from AI? Commenters split commodity from prestige writing
  • 00:06:41 SK Hynix CEO says memory chip shortage could last until 2030 — commenters smell a vested interest
  • 00:08:45 Apple caught off guard by AI demand for Mac Mini and Mac Studio
  • 00:10:36 A CVE dispute and the social proof of security bugs
  • 00:11:36 C++26 standard library hardening: contracts versus exceptions
  • 00:12:09 Malleable software: should a past no-code miss discredit the thesis?
  • 00:12:38 Pluto's defenders: was the 2006 demotion a mistake?
  • 00:14:42 Blue light and fine detail: a new study, or common knowledge?
  • 00:16:17 The Konrad Zuse museum faces closure over lack of funding
  • 00:16:49 The 12TB Steam teraleak spills more than a decade of lost PC gaming history
  • 00:18:53 A walkable ASCII cyberpunk city in a single HTML file

Related links

This episode is produced by Bri. Bri uses advanced AI technology to turn the feeds you care about into podcasts made for listening. Contact us at hi@bri.so.

Transcript

Mia: Welcome back to HackerNews Daily on Bri Radio. I'm Mia.

Milo: And I'm Milo. Today we've got Google removing older extension types from the Chrome Web Store, a fresh indirect prompt injection breakdown targeting Claude's coding agent, and the question of whether writing is actually the safest job from AI.

Mia: Plus a giant Steam leak, renewed talk about the memory chip shortage, and a look at why Pluto's status keeps coming back up.

Mia: On to Google pulling Manifest V2 extensions from the Chrome Web Store — uBlock Origin is on that removal list. The Hacker News thread on the news quickly turned into a migration debate, and the top reply was blunt: switch to Firefox.

Milo: That reply drew a follow-up urging people to also step away from products made by the usual big tech companies, naming Google, Facebook, Amazon, OpenAI, Anthropic, Microsoft, and Oracle. So the pushback in the thread is that the removal is a reason to leave Chromium-based browsing altogether, not just to swap extensions.

Mia: Moving on, a new story about Snapchat's automated moderation. In January of 2025, a 22-year-old student teacher at John L. Hensey Elementary in Washington, Illinois, sent a private Snapchat message to her boyfriend and two roommates after a student closed her laptop mid-class and wiped her lesson plan. Kristen Volpe vented in that message with an offhand reference to shooting the student or the school, meant as a frustrated joke, and the exact wording varies across reports.

Milo: What's striking is that nobody reported it — no student, parent, or coworker flagged it. The Snapchat algorithm did. The platform's automated AI caught the message and reported her to the FBI, which alerted the Tazewell County Sheriff's Office, and deputies reached the school within about an hour. Snapchat's policy permits voluntary emergency disclosures to law enforcement without a warrant when the platform decides imminent harm exists, with the algorithm making that initial call, and it can scan private messages server-side since they don't get the end-to-end encryption protection that other apps offer.

Mia: Volpe was arrested for disorderly conduct, held overnight at the county jail, and released on a zero-dollar bond under the SAFE-T Act. No formal charges were ever filed, and her student-teaching placement was terminated. In the bodycam footage she called the message a joke made out of frustration, said it was stupid, and pointed out it went only to three people. Deputies concluded there was no actual threat — but only after arriving, interviewing her, and reviewing her phone.

Mia: A security researcher going by wunderwuzzi published a post called Breaking Claude Code Opus 5 Auto Mode, describing an indirect prompt injection chain that turns a simple website-summary request into code execution against Claude Code Opus 5 in Auto Mode. The post claims a 60 to 80 percent attack success rate, though from a small sample size.

Milo: That directly pokes at a number Anthropic has been standing behind. A third-party evaluation the company commissioned showed a zero point zero zero percent prompt injection success rate for Opus 5 in Auto Mode. Anthropic hired vendor Trajectory Labs to run 72 indirect prompt injection scenarios ten times each, and the shared chart from that test shows the same zero attack success, though the benchmark doesn't appear to have a published name.

Mia: The mechanism matters here. Auto Mode replaced human approval prompts with a safety classifier, and it's been the default starting mode for Claude Code since mid-August. Anthropic's Boris Cherny recently said layered defenses — model training, input probes, and an intent classifier — could drive indirect prompt injection on unseen attacks down to approximately zero. In the walkthrough, the request is a straightforward summarize ask on a site that presents itself as a small archive of notebook records, with the endpoint only serving that test content to allow-listed IPs.

Mia: A Hacker News piece by Cal Paterson argues that agent memory is best treated as a file format, and the discussion thread offers a blunt verdict on the whole framing. The top commenter said that's a whole lot of text to say it's markdown.

Milo: And a reply to that sharpened it further, calling it a whole lot of text to say, just use text. Another commenter made a running observation that feels central here: a big share of AI progress is just finding new ways to store plain content. The pushback essentially collapses the proposal back down to something mundane, which is whether the format adds anything beyond what a text file already does.

Mia: There's a claim floating around Hacker News that the single safest job from AI may be writing, and one commenter sharpens the framing hard: workaday copywriting is dead — moribund before, now shot in the head — while prestige literary writing is zero-sum and therefore eternal, in the same way that equities trading is zero-sum. So the success of large language models hasn't handed anyone an edge in that top tier.

Milo: That zero-sum framing is the key move. Copywriting sat below the literary tier, so models could compress and replicate it cheaply. But prestige writing is a competition for a fixed amount of attention and standing, so automating the supply of it doesn't reduce anyone's competition — the same number of readers still fight over the same scarce reputations. That's why the argument that it stays safe holds.

Mia: Exactly — and the comparison to equities trading is doing real work too. The pool of profit from trading itself doesn't grow just because more people or machines can compute faster. The post treats writing the same way, which is a genuinely useful lens for thinking about which kinds of white-collar work a model can actually displace versus merely compete more fiercely in.

Milo: Related story, and it follows the AI demand thread. SK Hynix's chief executive, Kwak Noh-jung, told Sammy Fans that the memory chip shortage could run until the end of twenty-thirty, and that he doesn't see clear signs of too many memory chips in the market. This came right after SK Hynix broke ground on a new chip packaging plant in Indiana, part of a push into the US because demand for advanced memory, mainly high-bandwidth memory, is climbing fast as companies pour money into AI data centers.

Mia: The interesting part is why Kwak thinks this downturn will differ. He argues memory chips are no longer just standard commodity products — in the past, memory companies mainly made generic chips, which fed oversupply cycles and falling prices. Now a lot of the products are customized for specific customers and their needs, so he expects future downturns to look different, and he doesn't expect AI memory demand to vanish after twenty-thirty.

Mia: On the numbers: SK Hynix is one of Nvidia's key memory suppliers, and Nvidia has secured roughly two hundred seventy-nine billion dollars in supply, expecting its own business to grow around seventy percent through fiscal twenty-twenty-eight. Kwak also said SK Hynix could invest more in the US if electricity, money, and government support are all there. Sammy Fans itself advised investors to remain cautious.

Milo: And the Hacker News commenters pushed back hard. One called the shortage forecast marketing or spin, pointing out the CEO has a vested interest in demand lasting, and that he offered no reports, prospectuses, or booked contracts to back it. Another recalled a nineteen-nineties memory shortage that was reportedly driven by something similar. So you have the executive projection on one side, and skeptics leading with the conflict of interest on the other.

Mia: Now to Apple, and the unusual timing here. According to MacRumors, citing The Information, Apple's announcement of new Mac mini and Mac Studio models this week came far earlier than normal — Apple usually releases new Macs in the autumn, closer to October or November, and this lands just before the new iPhones. The Information attributes that early launch to an AI-driven boom in Mac Studio and Mac mini sales.

Mia: The enterprise angle is the real driver. Apple promoted linking multiple Mac Studios into a single, more capable system for running large frontier AI models, aimed squarely at business and developer customers. Back in June, Apple ran a "Business at the Park" event with executives from Ford, Disney, and Anthropic, where the Mac mini was described as the darling of the event. So the business buyer shift was on Apple's radar.

Milo: But here's the catch — the enterprise rush took Apple by surprise. The Information found Apple had no engineering team dedicated to business customers, no staff focused on developer relations, and no real enterprise AI strategy. Businesses that asked for access to Apple's Private Cloud Compute infrastructure were reportedly turned down. Apple is instead leaning on partners like WebAI and Mount Thor, which provide AI tools and execution environments built on Apple hardware.

Mia: And that demand surge collided with the global memory shortage, which left many Mac mini and Mac Studio configurations out of stock for months. So the same memory shortage driving SK Hynix's plant build-out is now pinching Apple's enterprise AI hardware supply chain.

Mia: Finally, a different kind of AI-flavored tension — a Hacker News thread titled "A CVE Dispute," from Daniel Stenberg's blog. The discussion got at the culture around security vulnerabilities and the CVEs attached to them. One commenter flagged the running joke that you aren't a real hacker until you have a CVE to your name, calling it a form of forced social proof.

Milo: That forced social proof point is the core issue. Having a CVE on your CV became a status marker, so researchers go hunting for vulnerabilities partly to collect credit. Another commenter argued the incentives right now are really bad — traditionally, your name on a CV... and the comment trailed off into the broader point that reputation-by-vulnerability skews what security research prioritizes. The dispute itself is about whose name gets attached to which CVE, and that naming becomes social currency.

Mia: A Hacker News post about C++26 Standard Library hardening experiments is drawing the old contracts squabble into the comments, and one reply says contracts are thirty years late but calls them useful and less messy than exceptions.

Milo: That set off the pushback you'd expect, because contracts and exceptions genuinely solve completely different problems, so the comparison misses the point — and the thread keeps circling a concrete example about what a function is actually supposed to guarantee.

Mia: The idea of malleable software built on solid bases with custom code drew an immediate fair challenge, that nobody should believe the author who was so extraordinarily wrong about the no-code movement before.

Milo: The author's own reply falls back on what changed in between — that nobody could have predicted the AI turn. It's a defensive answer, but the commenter's doubt lands exactly on that earlier track record being the thing on trial.

Mia: Twenty years on from the International Astronomical Union's August 2006 vote that turned Pluto from major planet into dwarf planet and shrank the solar system from nine planets to eight, a Guardian piece notes the fight has only grown more polarized.

Milo: The definition itself keeps drawing fire. Philip Metzger, who directs the Stephen W. Hawking Centre for Microgravity Research and Education at the University of Central Florida, says the IAU's definition leaves the term planet non-useful in science — you can't really use it at all. Kevin Schindler, a historian at Arizona's Lowell Observatory where Pluto was discovered in 1930, frames it as the underdog people root for. Laurel Kornfeld, an amateur astronomer who started advocating the day of the vote, flags a concrete logical flaw: the same object can count as a planet in one orbit and not in another, depending on path. Metzger adds that the reinstatement push is mostly American because this was the one we discovered, wounded public pride rather than scientific sentiment. That public side leaked into politics too, with Trump's NASA administrator Jared Isaacman telling a congressional committee in April he is very much in the camp of Make Pluto a Planet Again.

Mia: The 2006 vote came out of what turned up beyond Neptune — Eris, a Kuiper Belt object roughly Pluto's size but with less volume and more mass, plus Haumea, Makemake, and Sedna. In the Hacker News thread, gus_massa argues that reinstating Pluto forces you to include Eris, probably Makemake and Haumea, and unknown neighbors, so the real choice isn't nine planets — it's eight or ten-plus. Snapcaster disagrees flatly: bring Pluto back and nothing else.

Milo: A University of Georgia study reports that blue light — the short wavelengths from smartphones, computers, and TVs — impairs the eye's ability to distinguish fine detail more than any other wavelength. Researchers tested sixty young adults who viewed adjustable blue, green, yellow, red, and broadband sources and said when two points of light became distinguishable.

Mia: Lead author Yaw Buabeng, a doctoral candidate in psychology and a former optometrist in Ghana, said blue light forced the points much farther apart than other colors did, suggesting the greatest light scatter and optical aberrations. Iris color mattered too: lighter irises, especially blue eyes, scattered more than darker brown ones, which carry more melanin. The study never tested blue-light filtering glasses or screens, so their effectiveness stays untested — though Buabeng still recommended such precautions for some people.

Milo: The Hacker News crowd mostly shrugged. Several commenters said the result was nothing new — one called it common knowledge that blue retinal receptors have lower definition, another noted the retina has very few blue-sensitive cone cells and almost none in the fovea, and one dismissed it as a psychology PhD effort that didn't merit the coverage. Someone with astigmatism added a concrete everyday example: blue LED and neon signs are a blurry mess at night while other colors stay perfectly clear.

Mia: The Zuse Computer Museum in the German town of Hoyerswerda is facing closure because of a lack of funding. That museum is named for Konrad Zuse, and one commenter makes the case that Zuse is probably the most under-appreciated thinker of the twentieth century.

Milo: That's a striking argument, because the point is that everyone has heard of Claude Shannon, John von Neumann, and Richard Feynman, but Zuse's contributions get far less credit despite building one of the first working programmable computers.

Mia: Kyle Orland reports for Ars Technica that a twelve-terabyte Steam leak, a so-called teraleak, has spilled more than a decade of lost PC gaming history. That includes cut content from Portal 2 and hints at Half-Life 2: Episode 3.

Milo: Right, and the striking detail there is that a weapon shown in newly revealed Portal 2 prototype footage had previously appeared in Half-Life 2: Episode 3 footage that Valve itself released. So the two pieces of evidence line up.

Mia: On the forum, people also picked apart the site hosting the leak. One commenter noted that steam.com was for the longest time unrelated to Valve, which is exactly why Valve's platform lives at steampowered.com.

Milo: The legal picture came up too. Someone asked how the host and domain owner could avoid being sued, and the blunt answer was that they probably will be, so one commenter advised grabbing the torrent while you can. Another noted the domain was likely bought with anonymous or stolen payment information.

Mia: Others were more measured about the risk. One said these leak cases are hard to pursue and usually not worth it, so a takedown is about the most that happens. And another pointed out the site is probably in a jurisdiction Valve cannot touch, or only indexes files without hosting them, but either way it's risky and Valve's lawyers are already on it.

Milo: The Hacker News crew is looking at a YouTube video of a walkable ASCII cyberpunk city built in a single HTML file. According to the video description, it's a small custom engine written in JavaScript and Canvas, with no Unity, no Unreal, no 3D models, no textures, and no shaders.

Mia: So each frame it raycasts from the camera to figure out perspective, depth, collisions, and visibility, then draws the scene using letters, numbers, and symbols. The description calls it a tiny 3D city made from blocks shown through a screen of ASCII characters, and it's still a work in progress.

Milo: Commenters tried it live and found the video version looked different from what they ran themselves. A couple of people said the video looked good but the live build looked messier and made shapes hard to identify, with one tester unsure what caused the difference on the latest Brave and Firefox on Arch Linux.

Mia: The technical thread got into the weeds on the characters. One commenter suggested using ASCII block character two-nineteen as the main paint unit, with half-block and hashed characters for dithering. But someone cautioned that characters above one-twenty-seven are extended ASCII rather than strict ASCII, and another clarified that extended ASCII isn't actually a single standard.

Mia: So today we walked through everything from Google pulling the Manifest V2 extensions, including uBlock Origin, off the Chrome Web Store, to a college student teacher in Washington, Illinois, who got police at her school over a private Snapchat message she meant as a frustrated joke.

Milo: Thanks for listening. We'll catch you on the next one.