Every fucking website: 2026 edition

(op.tngl.io)

92 points | by nerdypepper 20 hours ago

18 comments

  • tripdout 18 hours ago
    This is almost exactly this website [0] which is also on the frontpage of HN. Wow.

    0: https://news.ycombinator.com/item?id=49297469

  • m132 15 hours ago
    It's not a Claude generated website without at least one `backdrop-filter: blur(1000px)` element that slows older machines to a crawl
  • addandsubtract 4 hours ago
    It's missing the captcha that fails to load and then makes you retry three times.
  • possan 4 hours ago
    Needs a cookie banner, 3s delayed sign up to our newsletter and enable push request
  • JK-Swizzle 17 hours ago
    It is missing the fade in on scroll.
  • Bolwin 17 hours ago
    Love the X logo that goes to bluesky
  • noman-land 17 hours ago
    This needs bluish dark mode with accent color and pills with a little rounded colored border on just the left side.
  • walrus01 16 hours ago
    > $ curl -fsSL install.sh | sh # you'd be stupid to run that, slop or not

    I wish more people would point this out.

    • Akronymus 11 hours ago
      I've legitimately seen one project that basically says to do that, but with "your ai agent". At least piping to sh is deterministic and, you can pipe to a filw and check the script

      https://github.com/0xeb/ghidrasql

      • walrus01 9 hours ago
        "Claude, install these 215 npm dependencies from unvetted repositores, make no mistakes"
    • xigoi 7 hours ago
      I still haven’t seen anyone point out how this is more dangerous than running an executable that you obtain any other way.
      • ffsm8 7 hours ago
        you can detect `curl | bash` server-side and serve a different payload for those (compared to curl -O file, wget etc), hence its an effectively undetectable attack vector.

        Executables on the other hand can be inspected and prodded, so the likelihood of something going amiss and consequently security agencies finding out about it is significantly higher.

        neither of those is secure of course, we're just discussing different levels of dangers. And curl|bash being worse, albeit not that much

        (and the -L here is the extra cherry on top. piping a redirect to a shell is just monkas)

      • esafak 16 minutes ago
        Because this way does not run security scanners.
  • chunkyguy 7 hours ago
    What is wrong with this layout?
    • addandsubtract 4 hours ago
      There's nothing wrong with it, per se. It's just that it's overused and filled with random garbage stats that no one cares about.
  • devin 17 hours ago
    Missing a flashy nonsense ASCII art animation. Check out https://performative-ui.cncl.co/ if you need an easy one to add.
  • willturman 16 hours ago
    The GitHub and X logos are chefs kiss
  • cigarettestshir 20 hours ago
    This is one of my favorite things I've ever seen.
  • TacticalCoder 16 hours ago
    > Trusted by... six companies from the same YC cohort.

    I giggled.

  • spottedmarley 19 hours ago
    * <- tiny logo
  • BoingBoomTschak 16 hours ago
    The fact that I can see it with JS disabled really breaks immersion here.
    • tosti 15 hours ago
      I expected cloudflare turnstile and if that happens to work, flashing gray bars to "compensate" for an absurdly long loading time.
  • doublerabbit 18 hours ago
    If the layout is intentionally LLM generated, heh.
  • arodenmaxxing 18 hours ago
    oh yeah I worked there
  • angoragoats 17 hours ago
    Why does the HN title say “2026 edition” when the page itself says “Slop edition”? We aren’t supposed to editorialize titles here.[0]

    https://news.ycombinator.com/newsguidelines.html