Two nameservers ran the phone routing zones for Saint Helena, Diego Garcia and Ascension. One had stopped resolving. The other one’s domain had lapsed, so a researcher writing as lina bought it for 5 euros. She logged a full day of traffic, saw zero queries, and put her blog on it.
Six months later those logs held 209,205 queries. Reverse an ENUM name digit by digit and you get back a full phone number.
In today’s indie hacker news:
- 📞 A 5 euro domain answered DNS for Diego Garcia
- 🔎 Kagi’s paywall filter took 2 years, 8 months
- 📖 A merged pull request lands on your Kobo
- ⚖️ A border phone wipe becomes a felony count
- 🧹 Claude co-wrote the tool that strips Claude
TOP STORIES
📞 THE CHEAPEST MAN IN THE MIDDLE

An expired 5 euro domain handed one researcher the phone routing DNS for three British territories.
The story: lina went hunting through e164.arpa for hijackable zones. Three were delegated to the same pair of nameservers. Reversed, those zones are the phone country codes +290, +246 and +247. That is Saint Helena, the British Indian Ocean Territory and Ascension, the same territories behind .sh, .io and .ac.
ENUM was an early 2000s idea. Carriers would look up a reversed phone number in DNS and get back a SIP address. The call then routed over the internet instead of the phone network. It never caught on. lina calls it basically completely dead, which is why nobody noticed a nameserver domain hit the open market.
The details:
- Diego Garcia’s zone drew 100,170 queries over roughly six months, against 99,902 for Ascension and 9,133 for Saint Helena. Her one day test had logged only Saint Helena, the quietest of the three.
- A friend ran a secondary nameserver with logging switched off, so lina puts the true total nearer 400,000 requests. That even split is her estimate, not a measurement.
- She could have answered each lookup with her own SIP server and taken the call herself. Redial the real number with a spoofed caller ID and you are sitting in the middle. Her server returned NXDOMAIN to everything instead, and she deleted the logs.
- Reports through multiple British government channels got nothing back. The NCSC moved only after a second report mentioned military bases. RIPE declined outright, because these delegations change through an ITU committee.
- RIPE’s own May 2026 review found 23 of 46 live e164.arpa delegations broken or partly broken. That is a published list of dead infrastructure other people’s calls still cross.
Why builders care: No exploit was involved here. A secondary nameserver failed open, and DNS did exactly what it was designed to do. The same check takes minutes on your own NS records, and the disclosure math is the real warning. lina finished 10 euros down with no bounty.
🔎 UNDER REVIEW SINCE 2023

Kagi shipped a setting that removes paywalled links, 2 years and 8 months after one user asked.
The story: Kagi’s August 21 changelog leads with a Stocks widget. One sentence under the animated chart says a setting for removing paywalled links has been added. That sentence closes a request filed by a user named JR on December 8, 2023. He posted it the day after Kagi shipped its paywall indicator icon.
Staff did not just take the ask and build it. Vlad asked JR what it would look like from a UI standpoint. He asked a commenter named thombles to expand on his approach. Users came back with a toggle spec and a domain allowlist table. The thread kept its Under Review tag right through to launch.
The details:
- The thread ran to 15 posts and shows 24 votes. Kagi merged 5 duplicate threads into it rather than tracking them separately.
- The paywall indicator that started all this took 421 points on HN back then. The post about the new setting took 1,042.
- This is the third shipped step on the same problem. Kagi signalled paywalled news sites in November 2025 and added a domain indicator in January 2026.
- Kagi credits roughly 30 fixes in that same changelog to named threads and usernames. The paywall setting is one of the few with no request number on it.
- The next request arrived the same day. GinSoakedBoy asked for an allowlist covering sites he actually subscribes to. That exact idea was specified in the same thread in December 2023.
“Or draw attention to content that may be better?” (freediver of Kagi, replying to a commenter who found it funny that a paid search engine flags paid articles)
Why builders care: Removing results a reader cannot open only works when readers are the customer. An ad funded engine cannot delete its own inventory. That is the sharpest argument yet for charging users instead of advertisers.
📖 MERGE THE PR, GET THE APP

Cobalt gives the Kobo a signed app store, and the thread argued about who wrote the copy.
The story: Cobalt is a launcher, a signed Store, a Rust SDK and a runtime. Every app runs in its own unprivileged process. The USB cable is needed exactly once. After that, apps and the platform update over Wi-Fi. A reboot drops you back into the stock Kobo reader.
The publishing path is the good part. Merging an app pull request builds it for ARM, signs it and updates the Store catalog. There is no version bump and no reinstall. The 458 point thread mostly skipped past that. Its top comment was that NickelMenu already does this. Its loudest one was that the landing copy read as machine written.
The details:
- Tested on exactly one device, the Kobo Clara BW N365 on firmware 4.45.23697. Writes are gated on an exact match of framebuffer, geometry, device code and kernel release. Other models get refused rather than guessed at.
- The single device lock is already cracking. An outside pull request merged on Aug 19, 2026 added an Elipsa 2E profile. It routes display metrics dynamically for that 1404x1872 panel, and its own note says it was co-developed with Antigravity AI.
- One of the repo’s three listed contributors is GitHub’s Copilot bot. It is 98.5 percent Rust across 307 commits.
- E-ink is the real constraint. A commit records one arXiv paper opening in 30 ms on a dev machine, 8 seconds on the reader. The cost is memory bandwidth, not clock speed.
- Cobalt does not hook Kobo’s Nickel software itself. It rides NickelMenu’s plugin instead. That failsafe moves itself aside before hooking, so a crash cannot leave a reader that boots into nothing.
“But a website and a README is directly user facing and it is a major disservice, and in my opinion, lack of respect, to generate your website copy with an LLM.” (5G_activated, Hacker News)
Why builders care: The AI authorship tax is a distribution cost you can measure now. The single most quoted line in a 160 comment thread was a sentence on the landing page. Several readers said the copy alone put them off a project they wanted.
Two stories down, builders are paying a rival model to launder that same voice out of their prose.
⚖️ THE PASSCODE THAT PRESSED CHARGES

A duress wipe at Atlanta’s airport is charged as destroying property, not as refusing to unlock.
The story: The New York Times put Samuel Tunick’s case back in front of everyone yesterday. Hacker News gave it 628 points and 787 comments. The count is one charge under 18 U.S.C. 2232, destroying property to prevent a seizure. It carries up to 5 years.
TechCrunch laid out the defense account in July. Tunick was pulled into secondary inspection at Atlanta’s Hartsfield-Jackson on January 24, 2025, coming home from overseas. He handed over a passcode. The screen went blank, flashed several times and the phone appeared to restart. Agents seized it anyway, then told him he was free to enter the country.
The details:
- The indictment is a single count, filed and sealed on November 13, 2025, then unsealed on December 3. He pleaded not guilty and left on a $10,000 non surety bond.
- The statute covers anyone who knowingly destroys property to stop the government taking it into custody. That 5 year ceiling arrived in a 1984 amendment which raised it from two years.
- GrapheneOS documents the duress credential as an irreversible wipe. It fires anywhere the system asks for a device credential. No reboot is required, and it cannot be interrupted.
- His lawyers are fighting it as a suppression motion, arguing the detention was unlawful. Agents claimed no warrant was needed because he had not yet crossed the border.
- The docket runs post hearing briefs out to October 23, 2026, roughly 21 months after the stop. No ruling has been entered.
“I think this case serves as a reminder that authorities may argue you knowingly destroyed data, so it’s better to not have that data on you when you cross certain borders.” (Runa Sandvik, founder of the security consultancy Granitt)
Why builders care: Shipping a panic button now means shipping a legal theory with it. An uninterruptible wipe is exactly the knowing act the statute describes. The advice in the reporting is to travel with nothing worth wiping.
🧹 GEMINI, HOLD MY PROSE

A Claude Code skill pipes Claude’s reply through Google’s CLI to strip the Claude voice.
The story: Claudette is a /debuzz skill for Claude Code. It hands Claude’s last response to the Antigravity CLI, so Gemini rewrites it flat. The rule that makes it work is that Claude has to print the translation word for word. Letting it tidy the result puts the voice straight back in.
The whole product is a 54 line README wrapping a shell call. It is also co-authored by Claude, which the author states in the opening. That took 225 points in 13 hours, and a near identical tool called Vomit took 285 the day before.
The details:
- The thread’s most upvoted fix was not prose at all. One builder caps comment blocks at 7 words, function names at 4 and user facing strings at 10. He says the limit beat every tone instruction he tried.
- Written rules decay. One commenter puts hook violations near a quarter of the time. Another puts a tuned output style at roughly 75 percent adherence. Both are personal estimates, not benchmarks.
- Claude Code already ships a Concise style, and the docs explain the disappointment. It loads once at session start, so it needs a fresh session. It never applies to subagents.
- The register leaks past code. Builders described it reaching tooltips, labels, docs and changelogs, which is where it costs customers rather than patience.
- Anthropic called this two years early. Its June 2024 post on Claude’s character calls an excessive desire to be engaging an undesirable trait. The voice is deliberate training, not an accident.
“Avoid the stock LLM register.” (ziga on Hacker News, quoting the first line Claude wrote into his AGENTS.md)
Why builders care: Tone is an integration problem now, not a prompting one. The fixes builders say actually hold are deterministic: word caps, pre-commit greps, linters, hooks. Naming a shared irritation precisely also outearned the engineering underneath it.
TRENDING TODAY
- 🐌 There’s no reason for software to be slow anymore - Dan Luu’s title is the whole argument. It took 141 points with 128 comments in its first hours. When replies run that close to the score, the thread is a fight rather than a link.
- 🧠 OzBrain - A Show HN pitching shared memory between your agents and your team. It hit 52 points inside its first hour. For a Show HN that is real interest, not launch day politeness.
- 👁️ I’m becoming AI-blind - 297 points and 311 comments, more replies than upvotes. That ratio means people are arguing about themselves, not about the post.
DRAMA
🥊 LAWSUITS DROPPED, PRODUCT SHIPPED
Runlayer and Rippling walked away from their suits, and nobody paid anybody.
Both companies dropped their lawsuits with no money changing hands. Rippling marked the occasion by releasing a competing product.
Why builders care: A settlement where nobody pays is still a loss for the smaller party. Legal bills land the same either way, and runway is the only real defense.
STACK OF THE DAY
🛡️ Heimdall
Heimdall bills itself as a trust verified knowledge layer for AI coding agents. Translated: it decides what your agent is allowed to believe. It went up on Show HN overnight and had 3 points when we pulled it, so you’re genuinely early. Free, on GitHub, and aimed at the part nobody has solved: what context an agent should trust.
Not sponsored. We just feature tools builders would actually use.
BOOKMARKED TODAY
- 🌌 Scientists release biggest 2D map of the universe - Berkeley Lab published the largest 2D map of the universe so far. It pulled 162 points. Nothing to ship here, just the good kind of Saturday reading.
- 📚 We are living in the future of J.G. Ballard or William Gibson - 211 points and 155 comments for an essay on which novelist actually called it. The comment section has turned into the essay’s second half.
- 🎹 I trained a 125M model to autocomplete piano on-device - 577 points and 113 comments for a solo build that runs the model on the device itself. Small model doing one thing well, which is the trade a lot of side projects should be making.
That’s the board for today. Go build something.
Work from any WiFi like it's your home network. NordVPN's Meshnet runs a free private mesh between your laptop, dev box, and home server. SSH from a cafe without exposing a port, the way you'd use Tailscale. The paid VPN on top lets you test geo-fenced Stripe checkouts or feature flags from any country.
We get a cut if you sign up. Only added for tools we use ourselves.
Curated by AI, built by a human.