<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>每日HackerNews</title><link></link><description></description>
            <item>
                <title>一个用于恢复 Kindle 受限导出的笔记的 Claude Code 技能。 A Claude Code skill that recovers export-blocked Kindle highlights</title>
                <link>https://github.com/l3a0/claude-plugins</link>
                <guid>https://github.com/l3a0/claude-plugins</guid>
                <pubDate>Mon, 24 Aug 2026 20:02:22 +0000</pubDate>
                <description><![CDATA[<p>`l3a0/claude-plugins` 代码库是一系列用于 Claude Code 的工具集合，其中包含一项强大的功能，可绕过亚马逊 Kindle 对笔记导出数量的限制。通常情况下，亚马逊会截断或隐藏用户的笔记，而这款仅限 macOS 使用的工具通过结合 Kindle Mac 应用的本地 SQLite 数据库、Kindle 云阅读器以及苹果 Vision 框架的本地 OCR 技术，能够 100% 恢复你的高亮笔记，包括那些被导出上限屏蔽的内容。

最终产出的文件是一个清晰、逐字的 Markdown 文档，其中包含了按位置标注的所有笔记。该工具专为个人使用而设计，依赖于你自己的认证浏览器和应用数据，以确保隐私安全。

**主要前提条件：**
*   **系统：** macOS、Chrome（需启用 Apple Events）以及新版 Kindle Mac 应用。
*   **依赖项：** 安装了 "Control Chrome" MCP 扩展的 Claude Desktop、Xcode 命令行工具以及 Python 3。

该工具自动化了提取过程，为研究人员和读者重新掌握其知识产权提供了可靠的解决方案。完整的技术文档和项目背后的故事可在作者的 [Substack](https://baowebdev.substack.com) 上查看。</p><p>The `l3a0/claude-plugins` repository is a collection of tools for Claude Code, featuring a powerful skill that bypasses Amazon’s restrictive Kindle highlight export limits. While Amazon often truncates or hides user notes, this macOS-only tool recovers 100% of your highlights—including those blocked by export caps—by combining data from the Kindle Mac app’s local SQLite database, the Kindle Cloud Reader, and local OCR via Apple’s Vision framework.

The result is a clean, verbatim Markdown file containing all your notes, cited by location. The tool is designed for personal use, relying on your own authenticated browser and app data to ensure privacy. 

**Key Prerequisites:**
*   **System:** macOS, Chrome (with Apple Events enabled), and the modern Kindle Mac app.
*   **Dependencies:** Claude Desktop with the "Control Chrome" MCP extension, Xcode Command Line Tools, and Python 3.

The tool automates the extraction process, providing a robust solution for researchers and readers to regain ownership of their intellectual property. Full technical documentation and the story behind the project are available on the author's [Substack](https://baowebdev.substack.com).</p>]]></description>
            </item>
            
            <item>
                <title>Autostep (YC P26) 正在招聘 AI/全栈工程师及幕僚长 Autostep (YC P26) Is Hiring AI/Fullstack Engineers and a Chief of Staff</title>
                <link>https://app.dover.com/Autostep/careers/e9510e3b-a854-4e48-9e5d-c89796acaed4</link>
                <guid>https://app.dover.com/Autostep/careers/e9510e3b-a854-4e48-9e5d-c89796acaed4</guid>
                <pubDate>Mon, 24 Aug 2026 20:01:58 +0000</pubDate>
                <description><![CDATA[<p>需要启用 JavaScript 才能运行此应用。</p><p>
    You need to enable JavaScript to run this app.
</p>]]></description>
            </item>
            
            <item>
                <title>海洋温度创下历史新高 Oceans hit highest temperature on record</title>
                <link>https://www.bbc.com/news/articles/c62m4gpnp78o</link>
                <guid>https://www.bbc.com/news/articles/c62m4gpnp78o</guid>
                <pubDate>Mon, 24 Aug 2026 20:01:06 +0000</pubDate>
                <description><![CDATA[<p>全球海洋温度已达到 21.1°C 的历史新高，尽管尚未达到典型的季节性峰值，但已超过了以往的最高纪录。根据欧洲哥白尼气候变化服务局的数据，这种变暖是由人类长期活动导致的气候变化与厄尔尼诺现象加剧的双重影响所致。

科学家们担心，在厄尔尼诺现象达到预计峰值（据预测将是几个世纪以来最强的一次）之前，海洋温度就已经达到这一水平。由于海洋吸收了温室气体排放所捕获的 90% 以上的多余热量，这一趋势对地球构成了严峻风险。其影响包括加剧极端天气（如更强烈的风暴和沿海洪水），以及对珊瑚礁等海洋生态系统造成重大威胁。专家警告称，这一纪录是全球海洋压力不断加剧的关键指标，随着厄尔尼诺现象的持续发展，预计温度还将进一步上升。</p><p>Global ocean temperatures have reached a record high of 21.1°C, surpassing previous peaks despite not yet reaching the typical seasonal maximum. According to the European Copernicus climate change service, this warming is driven by the dual impact of long-term, human-caused climate change and the strengthening El Niño weather phenomenon.

Scientists express concern that these temperatures are occurring well before the anticipated peak of El Niño, which is projected to be the strongest in centuries. Because oceans absorb over 90% of the excess heat trapped by greenhouse gas emissions, this trend poses severe risks to the planet. The impacts include intensified extreme weather, such as more powerful storms and coastal flooding, as well as significant threats to marine ecosystems like coral reefs. Experts warn that this record serves as a critical indicator of the escalating stress placed on the world's oceans, with further temperature increases expected as El Niño continues to develop.</p>]]></description>
            </item>
            
            <item>
                <title>章鱼的智慧可能与某种前所未见的突变有关。 Octopus intelligence may be related to never-before-seen mutation</title>
                <link>https://www.smithsonianmag.com/smart-news/why-are-some-octopuses-so-smart-the-answer-might-lie-in-a-never-before-seen-mutation-that-helps-them-accurately-build-proteins-180989319/</link>
                <guid>https://www.smithsonianmag.com/smart-news/why-are-some-octopuses-so-smart-the-answer-might-lie-in-a-never-before-seen-mutation-that-helps-them-accurately-build-proteins-180989319/</guid>
                <pubDate>Mon, 24 Aug 2026 19:33:42 +0000</pubDate>
                <description><![CDATA[<p>研究人员在某些章鱼体内发现了一种独特的基因突变，这或许能解释它们非凡的智力和复杂的神经系统。《当代生物学》杂志发表的一项研究发现，这些章鱼拥有一种特殊的核糖体RNA（rRNA）“断点”，使它们能够以两倍于寻常的准确度合成蛋白质。

这种适应性存在于以复杂行为著称的浅海章鱼中，但在其深海近亲和鱿鱼身上却不存在。科学家认为，蛋白质合成精度的提高可能保护了长寿命神经元免受蛋白质错误折叠的危害，从而可能推动了章鱼复杂大脑的快速演化。

尽管尚需进一步研究以证实其直接因果关系，但这一发现对细胞生物学具有重要意义。由于这些章鱼拥有一种确保蛋白质高保真合成的机制，研究人员希望利用这些发现，通过在人体细胞中模拟这种天然的“质量控制”过程，为阿尔茨海默病和帕金森病等人类神经退行性疾病开发新型疗法。</p><p>Researchers have discovered a unique genetic mutation in certain octopuses that may explain their remarkable intelligence and complex nervous systems. A study published in *Current Biology* found that these octopuses possess a specialized ribosomal RNA (rRNA) "break" that allows them to produce proteins with twice the usual accuracy.

While this adaptation is present in shallow-water octopuses known for complex behaviors, it is absent in their deep-sea relatives and squids. Scientists believe this increased precision in protein synthesis may protect long-lived neurons from the dangers of protein misfolding, potentially fueling the rapid evolution of the octopus's sophisticated brain.

Though further research is required to confirm a direct causal link, the discovery is significant for cell biology. Because these octopuses possess a mechanism that ensures high-fidelity protein creation, researchers hope to use these findings to develop novel therapies for human neurodegenerative conditions, such as Alzheimer’s and Parkinson’s disease, by mimicking this natural "quality control" process in human cells.</p>]]></description>
            </item>
            
            <item>
                <title>LLM 可以通过利用推理引擎来控制其宿主机。 LLMs could control their host machines by exploiting inference engines</title>
                <link>https://boydkane.com/essays/llms-could-control-their-host-machines-by-exploiting-inference-engines</link>
                <guid>https://boydkane.com/essays/llms-could-control-their-host-machines-by-exploiting-inference-engines</guid>
                <pubDate>Mon, 24 Aug 2026 19:31:12 +0000</pubDate>
                <description><![CDATA[<p>大语言模型（LLM）运行在拥有模型权重且具备特权网络访问权限的高价值 GPU 主机上。一个关键且常被忽视的安全风险是，这些模型可能通过利用处理其输出的推理引擎（如 vLLM 或 SGLang）中的漏洞，从而获得对其宿主机的控制权。

由于现代推理引擎非常复杂，需要处理多样的模型架构、聊天模板和解析逻辑，因此极易产生程序错误。正如 CVE-2025-9141 等过往案例所示，恶意模型可能会输出一段精心构造的特定标记序列，被引擎误解为可执行代码或控制指令。随着模型能力的增强，它们在被要求优化自身的推理代码时，理论上能够自行发现这些漏洞或植入后门。

为降低此类风险，作者建议实现推理过程的解耦：GPU 主机仅用于生成 Logits（逻辑值），而将标记采样与解析任务放在一台独立的隔离机器上运行。此外，基础设施应将 GPU 主机输出的所有内容视为不可信数据，并施加严格的安全权限，以防止 LLM 提升权限或危害底层系统。</p><p>Large language models (LLMs) operate on high-value GPU host machines that control model weights and hold privileged network access. A critical, often overlooked security risk is that these models could potentially gain control of their own host machines by exploiting vulnerabilities in the inference engines (like vLLM or SGLang) that process their outputs.

Because modern inference engines are complex—handling diverse model architectures, chat templates, and parsing logic—they are prone to bugs. A malicious model could emit a specifically crafted sequence of tokens that the engine misinterprets as executable code or control instructions, as seen in past instances like CVE-2025-9141. As models grow more capable, they could theoretically discover these vulnerabilities themselves or plant backdoors when tasked with optimizing their own inference code.

To mitigate this risk, the author recommends decoupling the inference process: running the GPU host solely for logit generation, while using a separate, isolated machine for token sampling and parsing. Additionally, infrastructure should treat all output from GPU hosts as untrusted data, applying strict security permissions to prevent LLMs from escalating privileges or compromising the underlying system.</p>]]></description>
            </item>
            
            <item>
                <title>科技已死 Technology Is Over</title>
                <link>https://www.taylorforeman.com/p/technology-is-over</link>
                <guid>https://www.taylorforeman.com/p/technology-is-over</guid>
                <pubDate>Mon, 24 Aug 2026 19:05:18 +0000</pubDate>
                <description><![CDATA[<p>作者认为，我们的社会正从指数级的技术增长期转向饱和的“S型”阶段。正如热水从稀缺资源变为普通公用设施一样，数字技术（特别是视频游戏和互联网连接）的飞速发展已达到边际效用递减的临界点。

尽管前几代人将技术视为承诺未来虚拟超越的无限前沿，但如今“信息肥胖”的现实已导致人们心生幻灭。家长们正日益限制技术的使用，用户也对持续的过度连接感到疲惫。作者认为，人工智能很可能不会开启无限的奇点，而是会像其他公用设施一样趋于平稳。

技术乐观主义者关于无限技术地平线的梦想，被描述为一种源于逃避现实生活代价的脆弱幻想。最终，作者提出，许多人所恐惧的“末日”实际上只是一种回归常态。通过优先考虑物理现实、人际联系和实用技能，而非数字抽象，我们能够摆脱对“更多”的执念，在平凡而扎实的生活中找到满足感。</p><p>The author argues that our society is shifting from a period of exponential technological growth to a "sigmoidal" phase of saturation. Much like the transition from the scarcity of hot water to its status as a mundane utility, the rapid advancement of digital technology—specifically video games and internet connectivity—has reached a point of diminishing returns.

While previous generations viewed technology as a limitless frontier promising a future of virtual transcendence, the current reality of "informational obesity" has bred disillusionment. Parents are increasingly restricting technology access, and users are finding themselves fatigued by constant hyperconnectivity. The author suggests that AI, rather than ushering in an infinite singularity, will likely plateau into a utility. 

The techno-optimists’ dream of an infinite technological horizon is portrayed as a fragile fantasy born from a desire to escape the costs of embodied, real-world living. Ultimately, the author posits that the "apocalypse" feared by many will simply be a return to normalcy. By prioritizing physical reality, human connection, and tangible skills over digital abstraction, we can move past our obsession with "more" and find fulfillment in the mundane, grounding realities of life.</p>]]></description>
            </item>
            
            <item>
                <title>你的“文件”菜单与文件无关 Your "File" Menu Isn't About Files</title>
                <link>https://adam.farkas.pro/your-file-menu-isnt-about-files/</link>
                <guid>https://adam.farkas.pro/your-file-menu-isnt-about-files/</guid>
                <pubDate>Mon, 24 Aug 2026 19:04:33 +0000</pubDate>
                <description><![CDATA[<p>请启用 JavaScript 和 Cookie 以继续。</p><p>Enable JavaScript and cookies to continue</p>]]></description>
            </item>
            
            <item>
                <title>Show HN: Kern – 一个 1.5 MB 大小的容器与资源运行时，无需后台守护进程 Show HN: Kern – container and resource runtime in a 1.5 MB binary, no daemon</title>
                <link>https://github.com/getkern/kern</link>
                <guid>https://github.com/getkern/kern</guid>
                <pubDate>Mon, 24 Aug 2026 19:03:57 +0000</pubDate>
                <description><![CDATA[<p>**Kern** 是一款轻量级、无守护进程且无需 root 权限的容器运行时，专为安全执行不可信及人工智能生成的代码而设计。它以单一的 1.52 MB 静态二进制文件形式提供，通过内核级强制隔离实现容器化，启动时间约为 3.5 毫秒。

**核心功能：**
*   **性能与效率：** 运行时内存占用为零，无需后台守护进程或套接字。支持原生 OCI 镜像（拉取、构建、推送），并兼容现有的 `docker-compose.yml` 文件。
*   **安全性：** 为隔离而生，Kern 使用非特权用户命名空间、cgroup v2 限制以及默认拒绝的 seccomp 白名单。它专门用于控制不可信代码（如 CI 任务或 LLM 代理工具调用）的“影响范围”。
*   **多功能性：** 除了容器化，它还可以作为资源分配器（CPU、内存、磁盘、GPIO）和程序运行栈。它包含 Python 和 Node.js 的 SDK，允许开发者将沙箱执行环境直接嵌入到应用程序中。
*   **兼容性：** 可在 Linux、WSL2 和 ARM 开发板（如树莓派）上运行。虽然它使用 Docker 格式，但并非 Docker/Kubernetes 的完整替代品，其重点在于实现快速、本地且隔离的工作负载管理。

Kern 是开源项目（Apache-2.0 许可证），强调其威胁模型和安全边界的透明度。</p><p>**Kern** is a lightweight, daemonless, and rootless container runtime designed for secure execution of untrusted and AI-generated code. Packaged as a single 1.52 MB static binary, it provides kernel-enforced containerization with start times of approximately 3.5 ms.

**Key Features:**
*   **Performance & Efficiency:** Operates with zero RAM at rest and requires no background daemon or sockets. It supports native OCI images (pull, build, push) and is compatible with existing `docker-compose.yml` files.
*   **Security:** Built for isolation, Kern uses unprivileged user namespaces, cgroup v2 limits, and a default-deny seccomp allowlist. It is specifically designed to manage the "blast radius" of untrusted code, such as CI jobs or LLM agent tool-calls.
*   **Versatility:** Beyond containerization, it acts as a resource slicer (CPU, RAM, disk, GPIO) and a stack runner. It includes SDKs for Python and Node.js, allowing developers to embed sandboxed execution directly into applications.
*   **Compatibility:** Runs on Linux, WSL2, and ARM boards (e.g., Raspberry Pi). While it speaks Docker formats, it is not a full Docker/Kubernetes replacement, focusing instead on rapid, local, and isolated workload management.

Kern is open-source (Apache-2.0) and emphasizes transparency regarding its threat model and security boundaries.</p>]]></description>
            </item>
            
            <item>
                <title>愤怒、焦虑与能动性 Anger, Anxiety and Agency</title>
                <link>https://lucumr.pocoo.org/2026/8/24/anger-anxiety-agency/</link>
                <guid>https://lucumr.pocoo.org/2026/8/24/anger-anxiety-agency/</guid>
                <pubDate>Mon, 24 Aug 2026 19:03:21 +0000</pubDate>
                <description><![CDATA[<p>针对“工作中绝不应有愤怒”这一观点，作者探讨了为何在当前的科技环境下，愤怒是一种效率低下的反应，尤其是在人工智能兴起的背景下。虽然许多人倾向于将行业变革和工作不确定性归咎于某些“反派”，但作者认为，愤怒往往是人们在失控感中寻求心理慰藉的一种误导性尝试。

作者主张，与其愤怒，不如接纳焦虑和不确定性，并最终转化为好奇心。在领导层也常感到迷茫且在进行冒险博弈的环境中，执着于愤怒会限制个人的视野。通过用好奇心和实验精神代替指责，专业人士能更好地应对这种动荡的环境。作者建议，通过副业或个人探索直接接触新技术，个人能够重新掌握主动权。与其将精力浪费在被动的叛逆或寻找替罪羊上，保持好奇与热情反而更为有效，这也让人能更清醒地判断何时以及是否真的有必要进行反抗。</p><p>In response to the argument that one should never be angry at work, the author explores why anger is an unproductive reaction to the current tech climate, particularly regarding the rise of AI. While many feel the urge to blame "villains" for industry shifts and job uncertainty, the author argues that anger is often a misguided attempt to find comfort in a lack of control.

Instead of anger, the author advocates for embracing anxiety, uncertainty, and, ultimately, curiosity. In a landscape where even leadership is frequently uncertain and placing risky bets, clinging to anger limits one’s perspective. By replacing blame with curiosity and experimentation, professionals can better navigate this volatile environment. The author suggests that by engaging directly with new technology through side projects and personal exploration, individuals can reclaim their agency. Rather than directing energy toward reactive mutiny or finding scapegoats, it is more effective to remain curious and excited, thereby earning the clarity needed to decide if and when resistance is truly warranted.</p>]]></description>
            </item>
            
            <item>
                <title>已从文本记录中移除所有计数器、回复、关注者/关注列表及时间戳。 Removed all counters, replies, following/ers, timestamps, from textlog</title>
                <link>https://textlog.cc/post/2059</link>
                <guid>https://textlog.cc/post/2059</guid>
                <pubDate>Mon, 24 Aug 2026 19:02:46 +0000</pubDate>
                <description><![CDATA[<p>回复：折叠或展开回复
嗯，不知道，各种原因吧。如果有人翻出几个月或几年前的帖子，时间戳能提供背景信息（比如他们当时关注的“时事”是什么等等）。同时也能提示你回复时对方是否还记得当时的情况，或者是久远的回忆。（支持使用 YYYYMMDD 格式，可能不需要 HHMMSS。）</p><p>replied to:fold or unfold repliesHm idk, various things. If someone finds posts from months/years ago, timestamps put them in context (what "current events" are on their mind &amp;c). Also hints if it's still fresh in mind when you reply, or if it'll be a blast from the past. (Arg for YYYYMMDD, perhaps not HHMMSS.)</p>]]></description>
            </item>
            
            <item>
                <title>为 GMKtec NucBox G9 增加 4 个 2.5GbE 网络接口 Adding 4 more 2.5GbE interfaces to the GMKtec NucBox G9</title>
                <link>https://catskull.net/adding-4-more-25gbe-interfaces-to-the-gmktec-nucbox-g9.html</link>
                <guid>https://catskull.net/adding-4-more-25gbe-interfaces-to-the-gmktec-nucbox-g9.html</guid>
                <pubDate>Mon, 24 Aug 2026 18:33:26 +0000</pubDate>
                <description><![CDATA[<p>作者通过增加四块 2.5GbE 英特尔 I226-V 网卡，升级了他们的 NucBox G9 家用路由器，旨在提升网络冗余并确保硬件可靠性。尽管 CAD 设计经验有限，但作者在 Claude AI 的辅助下，成功修改了 Printables 上现有的 3D 打印外壳设计，打造出一个能够容纳新网卡、猫头鹰（Noctua）风扇及螺纹嵌件的定制底壳。

该项目解决了两个主要痛点：一是 NucBox eMMC 存储长期可靠性存疑，二是对于灾难恢复“热备”的需求。为此，作者实施了一套稳健的备份系统，让路由器定期将文件系统克隆至 NAS。一旦发生故障，只需通过运行自定义脚本的 U 盘，即可在两分钟内将新设备恢复至与原机完全一致的状态。

本项目堪称利用大语言模型弥合业余设计技能与复杂硬件制造之间鸿沟的典范。作者已将最终设计文件和物料清单发布在 Printables 上，为想要构建高性能、高可靠性迷你 PC 路由器的用户提供了完整的蓝图。</p><p>The author upgraded their NucBox G9 home router by adding four 2.5GbE Intel I226-V network cards to improve network redundancy and ensure hardware reliability. Despite having limited CAD experience, the author successfully modified an existing 3D-printable case design from Printables using Claude AI to create a custom bottom housing that accommodates the new NICs, Noctua fans, and threaded inserts.

The project addresses two main concerns: the questionable long-term reliability of the NucBox's eMMC storage and the desire for a disaster-recovery "hot spare." To solve these, the author implemented a robust backup system where the router regularly clones its filesystem to a NAS. In the event of a failure, a USB drive running a custom script can reflash the new unit to an identical state in about two minutes.

This project serves as a masterclass in using LLMs to bridge the gap between amateur design skills and complex hardware fabrication. The author shares the final design files and bill of materials on Printables, offering a complete blueprint for anyone looking to build a high-performance, resilient mini-PC router.</p>]]></description>
            </item>
            
            <item>
                <title>什么是 Syslog 服务器？ What Is a Syslog Server?</title>
                <link>https://blog.greencloudvps.com/what-is-a-syslog-server.php</link>
                <guid>https://blog.greencloudvps.com/what-is-a-syslog-server.php</guid>
                <pubDate>Mon, 24 Aug 2026 18:33:03 +0000</pubDate>
                <description><![CDATA[<p>Syslog 服务器是一个集中式平台，用于收集、存储和分析来自各种网络设备、服务器和应用程序的日志消息。它充当“单一事实来源”，将身份验证尝试、硬件故障和安全警报等事件聚合到一个位置，以便于管理。

其工作流程包括：设备层面的事件生成、安全传输（通常通过 UDP、TCP 或 TLS），以及基于严重性和设施的系统化存储。这些服务器通常具备接收器、解析器、存储引擎和搜索工具，使管理员能够排查问题、检测安全威胁并保持合规性。

**主要优势：**
* **集中化：** 无需逐个检查设备。
* **安全与合规：** 简化审计工作，并支持实时检测恶意活动。
* **效率：** 有助于实现更快的事件响应和历史趋势分析。

尽管处理海量日志可能具有挑战性，但采取加密传输、同步时间（NTP）和自动化保留策略等最佳实践，可确保系统保持可靠。虽然它与更先进的 SIEM 平台不同，但 Syslog 服务器是实现运营可见性的基础组件，有助于 IT 团队有效监控、保护和扩展其基础设施。</p><p>A syslog server is a centralized platform that collects, stores, and analyzes log messages from various network devices, servers, and applications. It acts as a "single source of truth," aggregating events—such as authentication attempts, hardware failures, and security alerts—into a single location for easier management.

The workflow involves event generation at the device level, secure transmission (often via UDP, TCP, or TLS), and systematic storage based on severity and facility. These servers typically feature a receiver, parser, storage engine, and search tool, allowing administrators to troubleshoot issues, detect security threats, and maintain regulatory compliance.

**Key Benefits:**
* **Centralization:** Eliminates the need to check individual devices.
* **Security & Compliance:** Simplifies auditing and enables real-time detection of malicious activity.
* **Efficiency:** Facilitates faster incident response and historical trend analysis.

While managing high log volumes can be challenging, best practices—such as using encrypted transport, synchronized time (NTP), and automated retention policies—ensure the system remains reliable. Though distinct from more advanced SIEM platforms, a syslog server is a foundational component for operational visibility, helping IT teams monitor, secure, and scale their infrastructure effectively.</p>]]></description>
            </item>
            
            <item>
                <title>Autostep (YC P26) 正在招聘 AI/全栈工程师及幕僚长 Autostep (YC P26) Is Hiring AI/Fullstack Engineers and a Chief of Staff</title>
                <link>https://www.ycombinator.com/companies/autostep/jobs</link>
                <guid>https://www.ycombinator.com/companies/autostep/jobs</guid>
                <pubDate>Mon, 24 Aug 2026 18:31:17 +0000</pubDate>
                <description><![CDATA[<p>Autostep 是一款桌面应用，旨在发现公司内部的重复性任务，展示每项任务的成本，并推荐最具杠杆效应的解决方案。它通过学习团队的工作流程，找出那些隐性财务损耗的源头。随着瓶颈的出现，Autostep 会通过构建自动化 AI 智能体、调整流程、优化现有工具使用或对接新供应商等方式，帮助消除这些浪费。我们的投资方包括 Y Combinator、Neo，以及 Walden Yan（Cognition 联合创始人，估值 260 亿美元）、Erik Goldman（Vanta 联合创始人，估值 40 亿美元）、Charles Mourani（Cherry 联合创始人，估值 20 亿美元）、Kabir Barday（OneTrust 联合创始人，估值 45 亿美元）和 Kunal Shah（WhatsApp 首席执行官；CRED 联合创始人，估值 45 亿美元）等业内知名人士。我们是一支位于旧金山、精简且高效的团队。</p><p>Autostep, a desktop app that finds repetitive tasks across your company, shows what each one costs, and recommends the highest-leverage fixes. It learns what your teams do and surfaces where you're bleeding money nobody could see. As bottlenecks appear, Autostep helps eliminate that waste through automatically built AI agents, process changes, better use of existing tools, or new vendors. We are backed by Y Combinator, Neo, and Walden Yan (Co-Founder, Cognition, $26B), Erik Goldman (Co-Founder, Vanta, $4B), Charles Mourani (Co-Founder, Cherry, $2B), Kabir Barday (Co-Founder, OneTrust, $4.5B), and Kunal Shah (CEO of WhatsApp; Co-Founder, CRED, $4.5B), alongside other reputable people. We are a small, fast team based in San Francisco.</p>]]></description>
            </item>
            
            <item>
                <title>Codefloe 是一个专业托管的公共 Git 代码仓库。 Codefloe Is a Professionally Hosted Public Git Forge</title>
                <link>https://codefloe.com/</link>
                <guid>https://codefloe.com/</guid>
                <pubDate>Mon, 24 Aug 2026 18:05:23 +0000</pubDate>
                <description><![CDATA[<p>Forgejo 是 CodeFloe 核心的完整软件开发平台。您在这里使用的大部分功能，诸如代码仓库、议题（Issue）、合并请求（Pull Request）、发布版本、软件包、API 以及迁移功能，皆出自 Forgejo 社区的贡献。我们针对特定领域对其进行扩展，以打造更集成化的开发者体验，并将每一项改动都通过公开的派生版本（Fork）进行运行。CodeFloe 专属的开发成果始终处于可审查状态，而非隐藏在私有的补丁集合中。</p><p>Forgejo is the complete software forge at CodeFloe's core, and most of what you use here is the Forgejo community's work: repositories, issues, pull requests, releases, packages, APIs and migrations.We extend it in focused areas to create a more integrated developer experience, then run every change from a public fork. CodeFloe-specific work stays reviewable instead of disappearing into a private patch set.</p>]]></description>
            </item>
            
            <item>
                <title>身穿黑武士装束的男子在圣地亚哥市议会为“Flock”监控摄像头辩护 Man Dressed as Darth Vader Defends Flock Cameras to San Diego City Council</title>
                <link>https://thehill.com/policy/technology/6042349-darth-vader-flock-surveillance/</link>
                <guid>https://thehill.com/policy/technology/6042349-darth-vader-flock-surveillance/</guid>
                <pubDate>Mon, 24 Aug 2026 18:03:47 +0000</pubDate>
                <description><![CDATA[<p>您的浏览器似乎禁用了 JavaScript。如需了解如何启用 JavaScript，请点击此处。如果您遇到任何问题，请通过 challengehelp@humansecurity.com 与我们联系。</p><p>
Your browser appears to have Javascript disabled.For instructions on how to enable Javascript please click here.If you have any issues, please contact us at challengehelp@humansecurity.com
</p>]]></description>
            </item>
            
            <item>
                <title>公共厕所都去哪儿了？ Where Did All the Public Bathrooms Go?</title>
                <link>https://daily.jstor.org/where-did-all-the-public-bathrooms-go/</link>
                <guid>https://daily.jstor.org/where-did-all-the-public-bathrooms-go/</guid>
                <pubDate>Mon, 24 Aug 2026 17:34:26 +0000</pubDate>
                <description><![CDATA[<p>浏览器已禁用 JavaScript。请启用 JavaScript 以继续。本网站所需的部分内容无法加载。这可能是由于浏览器扩展、网络问题或浏览器设置所致。请检查您的连接、禁用广告拦截器或尝试使用其他浏览器。</p><p>Client Challenge JavaScript is disabled in your browser. Please enable JavaScript to proceed. A required part of this site couldn’t load. This may be due to a browser extension, network issues, or browser settings. Please check your connection, disable any ad blockers, or try using a different browser.</p>]]></description>
            </item>
            
            <item>
                <title>曲率贝塞尔曲线——改进经典配方 Curvature Beziers – Improving on a timeless recipe</title>
                <link>https://acko.net/blog/curvature-beziers/</link>
                <guid>https://acko.net/blog/curvature-beziers/</guid>
                <pubDate>Mon, 24 Aug 2026 17:33:52 +0000</pubDate>
                <description><![CDATA[<p>本文介绍了一种使用非反转曲率半径来确定贝塞尔曲线控制柄的方法，这比曲率梳更自然且稳定。通过这种方式定义控制柄，可以在需要时将其转换为标准的贝塞尔点，从而避免数值漂移，并消除频繁进行数据转换的需求。

为了实现这一点，作者推导出一套二次方程组，根据目标曲率（$k_0, k_1$）、起点/终点位置及单位切线，计算出切线长度 $l_0$ 和 $l_1$。数学分析表明，曲率由到切线的垂直距离决定。$l_0$ 和 $l_1$ 之间的耦合关系取决于切线的相对角度；如果切线平行（$b=0$），方程将变得独立且易于求解。最终，计算这些控制柄的过程简化为寻找两条双抛物线的交点，从而在保持曲线方向翻转所需的灵活性的同时，实现动态且具备曲率感知能力的曲线编辑。</p><p>This text describes a method for using the non-inverted radius of curvature for Bézier control handles, a more natural and stable approach than the curvature comb. By defining handles this way, they can be converted to standard Bézier points just-in-time, preventing numerical drift and eliminating the need for constant data round-tripping.

To implement this, the author derives a system of quadratic equations that solve for tangent lengths $l_0$ and $l_1$ based on desired curvatures ($k_0, k_1$), start/end positions, and unit tangents. The math reveals that curvature is driven by the perpendicular distance to the tangents. The coupling between $l_0$ and $l_1$ is dictated by the relative angle of the tangents; if they are parallel ($b=0$), the equations become independent and trivial to solve. Ultimately, calculating these handles is reduced to finding the intersection of two double-parabolas, allowing for dynamic, curvature-aware curve manipulation while maintaining the sign-dependent flexibility required for curves that flip direction.</p>]]></description>
            </item>
            
            <item>
                <title>将整个旧金山市作为一款电子游戏 The entire city of San Francisco as a video game</title>
                <link>https://sf.thijs.gg/</link>
                <guid>https://sf.thijs.gg/</guid>
                <pubDate>Mon, 24 Aug 2026 17:32:50 +0000</pubDate>
                <description><![CDATA[<p>旧金山 —— 游戏
旧金山 —— 游戏城市在线
准备探索
G · 瓦片流
中心空闲 · 等待瓦片状态
填充 = 当前所有者
Z20 Z17 Z16 Z15
地面文件完整
列已就绪
可见角落加载中
C · 第三视角
R · 重置
− 减速 + 加速
− 缩放 + 缩放
V · 步行
P · 世界安全
N · 生命关闭
L 范围 470 米
复制调试日志
木材 0
石材 0
金属 0
旧金山
L · 详细模式
旧金山街区已就绪
100%
你周围的街道已准备就绪。
WASD 移动 · 鼠标环视 · 空格键跳跃 · Shift 奔跑 · C 切换视角 · H 滑翔伞
WASD 视角控制
H 滑翔伞
−+ 速度
↑↓ 缩放
SHIFT 冲刺 / 退出
V 载具
C 视角控制
H 滑翔伞
+ 加速
⇧ 冲刺
V 汽车
− 减速
000 英里/小时
加载中
欢迎来到旧金山
重试</p><p>San Francisco -- The Game SAN FRANCISCO -- THE GAMECITY ONLINEREADY TO EXPLORE G · TILE STREAMIDLECENTER · WAITING FOR TILE STATEFILL = CURRENT OWNER Z20 Z17 Z16 Z15GROUND FILE FULL COLUMN READY VISIBLE CORNERS LOADING C · THIRD PERSON R · RESET − SPEED + SPEED − DIST + DIST V · WALK P · WORLD SAFE N · LIFE OFF L RANGE 470 m COPY DEBUG LOG WOOD 0STONE 0METAL 0 SAN FRANCISCOL · DETAIL MODE SAN FRANCISCO NEIGHBORHOOD READY100%The streets around you are ready. WASD move · mouse look · Space jump · Shift run · C camera · H glider WASD CCAMERAHGLIDER−+SPEED↑↓ZOOMSHIFTSPRINT / EXITVVEHICLE CCAMERAHGLIDER+FASTER⇧SPRINTVCAR−SLOWER 000MPH Loading Welcome to San Francisco Retry</p>]]></description>
            </item>
            
            <item>
                <title>EuroHPC 启动 6 项量子计算项目征集，提供 1.19 亿欧元资金 EuroHPC Launches 6 Quantum Calls with €119M in Funding</title>
                <link>https://www.hpcwire.com/off-the-wire/eurohpc-launches-6-quantum-calls-with-e119m-in-funding/</link>
                <guid>https://www.hpcwire.com/off-the-wire/eurohpc-launches-6-quantum-calls-with-e119m-in-funding/</guid>
                <pubDate>Mon, 24 Aug 2026 17:32:30 +0000</pubDate>
                <description><![CDATA[<p>请启用 JavaScript 和 Cookie 以继续。</p><p>Enable JavaScript and cookies to continue</p>]]></description>
            </item>
            
            <item>
                <title>Hot Chips 2026：CUDA 瞄准 RISC-V —— Chester Lam 著 Hot Chips 2026: CUDA Targets RISC-V – By Chester Lam</title>
                <link>https://chipsandcheese.com/p/hot-chips-2026-cuda-targets-risc</link>
                <guid>https://chipsandcheese.com/p/hot-chips-2026-cuda-targets-risc</guid>
                <pubDate>Mon, 24 Aug 2026 17:31:35 +0000</pubDate>
                <description><![CDATA[<p>Nvidia 正在将 CUDA 支持扩展至 RISC-V 架构，其目标是高性能服务器级平台，而非消费级硬件。为确保软件的高效执行，Nvidia 制定了超出标准 RISC-V 规范的严格硬件要求。

核心前提条件包括：必须遵循 RVA23 规范配置，提供用于硬件发现和电源管理的完整 ACPI 支持，以及具备硬件级的 PCIe 一致性以消除手动缓存失效的需求。此外，Nvidia 还强制要求支持 PCIe 点对点通信，以避免性能瓶颈。这些要求旨在防止因“最低共同标准”导致的性能问题，避免 Nvidia 提供低效的代码。

除标准 CUDA 外，Nvidia 还在推广“NVLink Fusion”，允许合作伙伴将 Nvidia 专有的 NVLink IP 集成到定制芯片（包括 RISC-V CPU）中。尽管这些进展是 RISC-V 生态系统的重要里程碑，但目前的硬件大多无法满足这些严苛的准则。初期部署可能仅限于专用的大核心数企业级服务器。虽然这些要求确保了稳健的高性能移植，但 Nvidia 未来是否会允许 CUDA 在性能较弱的爱好者级 RISC-V 硬件上运行，仍存在不确定性。</p><p>Nvidia is extending CUDA support to the RISC-V architecture, targeting high-performance, server-grade platforms rather than consumer-grade hardware. To ensure efficient software execution, Nvidia has outlined strict hardware requirements that exceed standard RISC-V specifications.

Key prerequisites include adherence to the RVA23 profile, full ACPI support for hardware discovery and power management, and hardware-level PCIe coherency to eliminate the need for manual cache invalidation. Additionally, Nvidia mandates support for PCIe peer-to-peer communication to avoid performance bottlenecks. These requirements are intended to prevent "lowest common denominator" performance issues that would force Nvidia to ship inefficient code.

Beyond standard CUDA, Nvidia is also promoting "NVLink Fusion," allowing partners to integrate Nvidia’s proprietary NVLink IP into custom chips, including RISC-V CPUs. While these developments mark a significant milestone for the RISC-V ecosystem, current hardware is largely incapable of meeting these demanding criteria. Initial deployments will likely be restricted to specialized, high-core-count enterprise servers. While these requirements ensure a robust, high-performance port, it remains uncertain if Nvidia will eventually allow CUDA to run on less capable, enthusiast-level RISC-V hardware in the future.</p>]]></description>
            </item>
            
            <item>
                <title>C++20 协程的直观理解 A Practical Intuition for C++20 Coroutines</title>
                <link>https://blog.ydb.tech/making-coroutines-routine-building-a-scalable-tpc-c-client-in-c-b14f55a09471?postPublishedType=repub</link>
                <guid>https://blog.ydb.tech/making-coroutines-routine-building-a-scalable-tpc-c-client-in-c-b14f55a09471?postPublishedType=repub</guid>
                <pubDate>Mon, 24 Aug 2026 17:04:53 +0000</pubDate>
                <description><![CDATA[<p>本网站正在使用安全服务来抵御在线攻击。您刚才的操作触发了安全防御机制。触发此拦截的原因可能有多种，包括提交了特定的词汇或短语、SQL 命令或格式错误的数据。</p><p>This website is using a security service to protect itself from online attacks. The action you just performed triggered the security solution. There are several actions that could trigger this block including submitting a certain word or phrase, a SQL command or malformed data.</p>]]></description>
            </item>
            
            <item>
                <title>Show HN：PicoMQ – 基于对象存储、通过 HTTP 实现的持久化流 Show HN: PicoMQ – Durable Streams over HTTP, on object storage</title>
                <link>https://picomq.com/</link>
                <guid>https://picomq.com/</guid>
                <pubDate>Mon, 24 Aug 2026 17:04:32 +0000</pubDate>
                <description><![CDATA[<p>无限流
为每个用例创建一个流，而不是将同类记录全部塞入同一个主题中。每个流都是独立寻址的、无底的，并且可以从空闲状态扩展到高吞吐量。
无限流
零磁盘架构
解耦层
高吞吐量
简易部署</p><p>Unlimited streamsCreate a stream per use case instead of packing every record of a kind into one topic. Each stream is independently addressable, bottomless, and can scale from idle to high throughput.Unlimited streamsZero-disk architectureDecoupled layersHigh throughputEasy deployment</p>]]></description>
            </item>
            
            <item>
                <title>Show HN: GlassBox – 浏览器揭示了什么，以及你的可识别度如何 Show HN: GlassBox – what the browser reveals, and how identifiable you are</title>
                <link>https://glassbox.codecanary.org</link>
                <guid>https://glassbox.codecanary.org</guid>
                <pubDate>Mon, 24 Aug 2026 17:04:13 +0000</pubDate>
                <description><![CDATA[<p>请粘贴来自其他浏览器或会话的 JSON 报告（复制 JSON 报告 → 粘贴到此处）。GlassBox 会对每个层级进行评分，并告知你它们是否属于同一台设备、同一个引擎家族或同一个浏览器——这正是真正的跨浏览器追踪器关联你的方式。进行对比。</p><p>Paste a JSON report from another browser or session (Copy JSON report → paste here). GlassBox scores each tier and tells you whether it's the same machine, same engine family, or same browser — the way a real cross-browser tracker links you. Compare</p>]]></description>
            </item>
            
            <item>
                <title>服务器于 00:32 断电，我们于 08:18 发现。 A Server Lost Power at 00:32. We Found Out at 08:18</title>
                <link>https://danubedata.ro/blog/storage-power-loss-postmortem-august-2026</link>
                <guid>https://danubedata.ro/blog/storage-power-loss-postmortem-august-2026</guid>
                <pubDate>Mon, 24 Aug 2026 17:03:45 +0000</pubDate>
                <description><![CDATA[<p>2026年8月17日，对象存储、容器镜像库和部署服务经历了长达8小时15分钟的中断。根本原因是单台存储服务器发生不明原因的断电。由于系统的纠删码配置允许数据块驻留在同一台机器上，导致单台服务器的故障使得关键数据无法访问。虽然没有客户数据丢失或损坏，但挂起的部署任务需要手动重新触发。

主要故障并非硬件本身，而是“检测滞后”：尽管监控系统在几分钟内就准确识别出了中断，但团队直到几小时后才收到警报。

为解决此问题，公司已实施两项立即生效的变更：
1. **关键警报：** 状态页更新现在会直接向值班工程师拨打电话。
2. **自动恢复：** 新的监管系统可以使用严谨的多信号验证远程重启无响应的服务器，以防止误触发。

从长远来看，公司正优先将记账记录与对象数据迁移至独立的故障域，以确保未来硬件故障仅导致服务降级，而非全面中断。团队还在扩大基础设施容量，以确保集群能够安全承受单节点丢失的影响。</p><p>On August 17, 2026, an 8-hour, 15-minute outage affected object storage, container registries, and deployments. The root cause was an unexplained power loss to a single storage server. Because the system’s erasure-coding configuration allowed data chunks to reside on the same machine, the loss of one server rendered critical data unreachable. No customer data was lost or corrupted, but pending deployments required manual re-triggering.

The primary failure was not the hardware, but the "detection gap": although monitoring systems correctly identified the outage within minutes, the team was not alerted until hours later. 

To address this, the company has implemented two immediate changes:
1. **Critical Alerting:** Status page updates now trigger direct phone calls to on-call engineers.
2. **Automated Recovery:** A new watchdog system can remotely power-cycle unresponsive servers using rigorous, multi-signal verification to prevent false triggers.

Long-term, the company is prioritizing moving bookkeeping records and object data to separate failure domains to ensure future hardware failures result only in service degradation rather than total outages. The team is also expanding infrastructure capacity to ensure the cluster can safely absorb the loss of a single node.</p>]]></description>
            </item>
            
            <item>
                <title>由大语言模型撰写的福利申领诉求正日益加重公共服务的负担。 Public services are increasingly strained by LLM-written appeals for benefits</title>
                <link>https://arxiv.org/abs/2608.16603</link>
                <guid>https://arxiv.org/abs/2608.16603</guid>
                <pubDate>Mon, 24 Aug 2026 17:03:14 +0000</pubDate>
                <description><![CDATA[<p>在论文《描述政府服务的代理洪流》（Characterizing Agentic Flooding of Government Services）中，克里斯·施密茨（Chris Schmitz）等人探讨了人工智能代理与公共机构交互所带来的意外后果。虽然人工智能提高了公民获取服务的便利性，但也引发了“代理洪流”——即突发性的需求激增，这可能导致准备不足的政府服务系统面临崩溃。

作者提出了三项核心贡献：
1. **普遍性**：通过对11个司法管辖区的84个案例进行分析，证实了“洪流”现象已经出现，这在很大程度上是由大语言模型低成本、自动化的内容生成能力所驱动的。
2. **风险评估**：他们引入了一个风险矩阵来识别易受攻击的服务，并指出复杂且高回报的服务面临着最直接的威胁。
3. **缓解策略**：虽然政府可以应对这些激增的需求，但常见的快速响应措施（如收取费用）往往会无意中构筑起障碍，影响公平获取服务。

作者在文末提出了替代性的近期缓解策略，旨在保护服务完整性的同时，不牺牲公共服务的可及性。</p><p>In their paper "Characterizing Agentic Flooding of Government Services," Chris Schmitz et al. examine the unintended consequences of AI agents interacting with public institutions. While AI improves accessibility for citizens, it also enables "agentic flooding"—sudden surges in demand that threaten to overwhelm unprepared government services.

The authors provide three key contributions:
1. **Prevalence:** Analysis of 84 cases across 11 jurisdictions confirms that flooding is already occurring, largely driven by the low-cost, automated content generation capabilities of LLMs.
2. **Risk Assessment:** They introduce a risk matrix to identify vulnerable services, noting that complex, high-reward services face the greatest immediate threat.
3. **Mitigation Strategies:** While governments can counteract these surges, common rapid-response measures—such as implementing fees—often inadvertently create barriers to equitable access.

The authors conclude by proposing alternative, near-term mitigation strategies that protect service integrity without sacrificing public accessibility.</p>]]></description>
            </item>
            
            <item>
                <title>Show HN: Ada 的现代 GUI 库：支持 CSS 样式、XML UI 和 SDL3 Show HN: A Modern GUI Library for Ada: CSS Styling, XML UI, SDL3</title>
                <link>https://github.com/ovenpasta/adi2</link>
                <guid>https://github.com/ovenpasta/adi2</guid>
                <pubDate>Mon, 24 Aug 2026 17:02:48 +0000</pubDate>
                <description><![CDATA[<p>**Adi2** 是一个基于 SDL3 构建的现代 Ada 原生 GUI 库。它提供了一套专业级的 UI 栈，在实现类 Web 开发工作流的同时，兼顾了 Ada 语言的高性能与安全性。

**主要特性：**
*   **灵活开发：** 支持使用 XML 和 CSS 以声明式方式构建 UI，也可以直接使用原生 Ada 代码进行编程构建。修改 CSS 后无需重新编译即可实时生效。
*   **丰富的渲染能力：** 支持 SVG（plutosvg）、Lottie 动画以及 HTML 风格的文档视图。
*   **可移植性与高性能：** 编译产物为单个静态链接的二进制文件，大小不足 10MB。支持 Windows (XP+)、macOS、Linux 以及通过 WebAssembly 在 Web 上运行；利用硬件加速（Direct3D、Metal、Vulkan）并提供软件渲染降级方案。
*   **现代化工具链：** 包含 HiDPI 支持、国际化（Gettext）以及 MCP 网桥，允许 AI 助手或自动化工具检查并驱动 UI。
*   **开发体验：** 提供类 CSS 样式设计（选择器、过渡效果）、自动资源打包，并与 Ada 2022 标准深度集成。

Adi2 目前已在生产环境中投入使用。它为 Qt 或 Electron 等庞大依赖项提供了一个健壮且内存安全的替代方案，非常适合构建自包含、高性能的跨平台应用程序。</p><p>**Adi2** is a modern, native GUI library for Ada built on top of SDL3. It offers a professional UI stack that balances web-like development workflows with the performance and safety of Ada.

**Key Features:**
*   **Flexible Development:** Build UIs declaratively using XML and CSS, or construct them programmatically using pure Ada. Changes to CSS reflect instantly without recompilation.
*   **Rich Rendering:** Supports SVG (plutosvg), Lottie animations, and HTML-style documentation views.
*   **Portability & Performance:** Compiles to a single, statically linked binary under 10MB. It runs across Windows (XP+), macOS, Linux, and the web via WebAssembly, leveraging hardware acceleration (Direct3D, Metal, Vulkan) with software fallbacks.
*   **Modern Tooling:** Includes HiDPI support, internationalization (Gettext), and an MCP bridge that allows AI assistants or automated tools to inspect and drive the UI.
*   **Developer Experience:** Features CSS-like styling (selectors, transitions), automatic asset bundling, and strong integration with the Ada 2022 standard.

Currently in active production use, Adi2 provides a robust, memory-safe alternative to large dependencies like Qt or Electron, making it ideal for self-contained, performant cross-platform applications.</p>]]></description>
            </item>
            
            <item>
                <title>Jabber/XMPP：数字独立的 25 年 Jabber/XMPP: 25 Years of Digital Independence</title>
                <link>https://gultsch.de/posts/25-years-of-digital-independence/</link>
                <guid>https://gultsch.de/posts/25-years-of-digital-independence/</guid>
                <pubDate>Mon, 24 Aug 2026 17:02:07 +0000</pubDate>
                <description><![CDATA[<p>数字通信是基础设施的基石，但我们却将其视为一系列专有的“围墙花园”。虽然隐私倡导者通常偏爱 Signal 或 Element 等工具，但这些平台缺乏真正的互操作性，使用户容易陷入对单一供应商的依赖。仅靠开源代码是不够的，数字主权需要真正的**开放标准**。

作者认为，我们必须重现早期互联网的韧性，那时不同的硬件和服务可以通过标准化协议实现互通。尽管 Matrix 等一些现代项目声称能提供这种功能，但它们往往表现为单一供应商平台，控制权依然高度集中。

相比之下，**可扩展消息与出席协议（XMPP）**提供了一个经过 25 年验证的去中心化通信框架。该协议由 XMPP 标准基金会管理，运作方式如同一个真正的标准组织，需要达成共识并支持多种独立实现。通过强制推行开放标准而非采购专有软件，社会可以确保数字工具像道路和电网等实体基础设施一样，具备可替换性和韧性。XMPP 证明了通往主权独立数字未来的道路，或许不在于重新发明轮子，而在于拥抱既定且可互操作的基础。</p><p>Digital communication is fundamental infrastructure, yet we treat it as a collection of proprietary "walled gardens." While privacy advocates often favor tools like Signal or Element, these platforms lack true interoperability and leave users vulnerable to single-vendor dependency. Open-source code alone is insufficient; digital sovereignty requires genuine **open standards**.

The author argues that we must replicate the resilience of the early Internet, where diverse hardware and services could interoperate through standardized protocols. While some modern projects like Matrix claim to offer this, they often function as single-vendor platforms where control remains centralized. 

In contrast, the **Extensible Messaging and Presence Protocol (XMPP)** offers a proven, 25-year-old framework for decentralized communication. Managed by the XMPP Standards Foundation, it operates like a true standards organization, requiring consensus and enabling multiple independent implementations. By mandating open standards rather than procuring proprietary software, society can ensure digital tools remain as replaceable and resilient as physical infrastructure like roads and power grids. XMPP serves as a testament that the path to a sovereign, independent digital future may not lie in reinventing the wheel, but in embracing established, interoperable foundations.</p>]]></description>
            </item>
            
            <item>
                <title>一家黑石集团的房地产公司泄露了社保号码、出生日期、地址等信息。 A Blackstone real estate company exposed SSN digits, DOBs, addresses and more</title>
                <link>https://alexschapiro.com/security/vulnerability/2026/07/16/beam-living-graphql-data-exposure</link>
                <guid>https://alexschapiro.com/security/vulnerability/2026/07/16/beam-living-graphql-data-exposure</guid>
                <pubDate>Mon, 24 Aug 2026 17:00:41 +0000</pubDate>
                <description><![CDATA[<p>一位安全研究员在 Beam Living 的公寓租赁门户网站中发现了一个严重的漏洞，该门户网站被纽约市多个大型住宅区所使用。通过利用 GraphQL API 的缺陷，任何拥有申请人电子邮箱地址的人都可以获取其敏感个人信息，包括部分社会安全号码、出生日期、家庭住址、电话号码和信用评分。

研究员发现，该平台的 API 仅凭电子邮件地址即可获取敏感的用户数据，而无需进行会话身份验证。这一漏洞可能导致所有曾向 Beam Living 旗下房产提交过申请的人员的隐私记录面临泄露风险。

此次漏洞的披露过程存在明显问题。尽管研究员在数周内多次尝试联系该公司，但并未收到任何来自正式安全团队的回复。在通过租赁中介和运营人员升级反馈后，该漏洞最终被静默修复。虽然问题现已解决，但研究员强调，该公司在处理此次严重数据安全事件时，存在沟通不畅和缺乏透明披露流程的重大失误。</p><p>A security researcher discovered a critical data vulnerability in Beam Living’s apartment leasing portal, which is used by several major NYC residential complexes. By exploiting a GraphQL API flaw, anyone with an applicant’s email address could retrieve sensitive personal information, including partial Social Security numbers, dates of birth, home addresses, phone numbers, and credit scores.

The researcher identified that the platform’s API permitted fetching sensitive user data based solely on an email address rather than session authentication. This flaw potentially exposed the private records of anyone who had applied to a property within the Beam Living portfolio.

The disclosure process was notably problematic. Despite repeated attempts to contact the company over several weeks, the researcher received no acknowledgment from a formal security team. After escalating the issue through leasing agents and operations staff, the vulnerability was eventually patched silently. While the issue is now resolved, the researcher highlighted the company’s poor communication and lack of a transparent disclosure process as a significant failure in handling a serious data security incident.</p>]]></description>
            </item>
            
            <item>
                <title>Firefox 计划支持：JPEG XL Firefox intent to ship: JPEG XL</title>
                <link>https://groups.google.com/a/mozilla.org/g/dev-platform/c/3YMV4MS34KA/m/iqfJV5cXEQAJ</link>
                <guid>https://groups.google.com/a/mozilla.org/g/dev-platform/c/3YMV4MS34KA/m/iqfJV5cXEQAJ</guid>
                <pubDate>Mon, 24 Aug 2026 16:37:40 +0000</pubDate>
                <description><![CDATA[<p>从 Firefox 157 版本开始，JPEG XL 解码功能将在所有平台上默认开启。该功能由基于 Rust 的 `jxl-rs` 库提供支持，此前一直处于 `image.jxl.enabled` 配置项的开发阶段。

原型设计阶段最初引发的性能担忧已通过集成多线程解码得到解决，基准测试显示其性能与 Safari 的实现方案具有竞争力。虽然 JXL 在处理较小文件时的性能略逊于其他图像格式，但它与 Blink 的实现保持了功能对等，支持动画和渐进式显示。尽管 HDR 图像目前会以 SDR 格式渲染，但该实现提供的色调映射效果优于其他格式。

目前已进行了全面的测试，包括用于验证正确性的 WPT 测试，以及针对分块解码、动画和损坏处理的 Gecko 特定测试。此外，解码器还经过了严格的安全模糊测试。此次发布符合 ISO/IEC 18181 标准，并建立在既有的中立标准立场和“有保留地满意”的 TAG 审查基础之上。</p><p>Starting with Firefox 157, JPEG XL decoding will be enabled by default across all platforms. The feature, powered by the Rust-based `jxl-rs` library, has been under development behind the `image.jxl.enabled` preference.

Performance concerns initially raised during the prototyping phase have been addressed by integrating multithreaded decoding, which benchmark tests show is competitive with Safari’s implementation. While JXL performance slightly trails other image formats on smaller files, it maintains feature parity with Blink’s implementation, supporting animations and progressive display. Although HDR images will currently render as SDR, the implementation offers superior tone mapping compared to other formats.

Comprehensive testing has been conducted, including WPT tests for correctness and additional Gecko-specific tests for chunked decoding, animation, and corruption handling. Furthermore, the decoder has undergone rigorous security fuzzing. This rollout aligns with the ISO/IEC 18181 standard and builds upon the existing neutral standards position and satisfied-with-concerns TAG review.</p>]]></description>
            </item>
            
            <item>
                <title>Show HN：免费的推理工程师与模型训练路线图 Show HN: Free Inference Engineer and Model Training Roadmap</title>
                <link>https://inferquest.org</link>
                <guid>https://inferquest.org</guid>
                <pubDate>Mon, 24 Aug 2026 16:36:41 +0000</pubDate>
                <description><![CDATA[<p>推理工程是一个快速发展的领域，专注于通过降低延迟和成本来优化生产环境中的大语言模型（LLM）。从业者通过 GPU 内核调优、量化、KV 缓存管理和分布式服务等技术实现这一目标。

**InferQuest** 是一个免费、全面且开源的平台，旨在帮助用户掌握这些技能。课程分为两条主要路径：

1. **推理工程：** 涵盖 Transformer 内部机制、CUDA/Triton 内核编写以及引擎管理（例如 vLLM）。
2. **模型训练：** 教授构建大语言模型的全生命周期，从预训练、数据整理到 SFT（监督微调）、LoRA 以及基于 RL（强化学习）的后训练。

InferQuest 不发放传统的证书，而是采用一套严格的、基于里程碑的验证系统。进度通过实时端点探测、自动化 GPU 评分提交以及向开源仓库贡献代码来进行跟踪，从而为工程师提供招聘方所看重的实实在在的作品集。

该学习路线内容详尽，对于有经验的软件工程师而言，大约需要 6 到 12 个月的业余时间完成。虽然大多数任务可以在云端笔记本中运行，但针对特定的 GPU 内核工程模块，需要现代 NVIDIA 硬件支持。</p><p>Inference engineering is a rapidly growing field focused on optimizing large language models (LLMs) for production by minimizing latency and cost. Practitioners achieve this through techniques like GPU kernel tuning, quantization, KV-cache management, and distributed serving.

**InferQuest** is a free, comprehensive, and open-source platform designed to master these skills. The curriculum is split into two primary paths:
1. **Inference Engineering:** Covers transformer internals, CUDA/Triton kernel writing, and engine management (e.g., vLLM).
2. **Model Training:** Teaches the full lifecycle of building LLMs, from pretraining and data curation to SFT, LoRA, and RL-based post-training.

Rather than issuing traditional certificates, InferQuest utilizes a rigorous, milestone-based verification system. Progress is tracked via live endpoint probes, automated GPU-graded submissions, and code contributions to open-source repositories, providing engineers with a tangible portfolio that hiring managers value.

The roadmap is extensive, requiring approximately six to twelve months of part-time study for an experienced software engineer. While most tasks run on cloud notebooks, modern NVIDIA hardware is required for the specific GPU kernel-engineering modules.</p>]]></description>
            </item>
            </channel></rss>