Scraped at 09:34, September 17, 2026 (PDT)
(1) Canada welcomes EU proposal to become 'associate member'
Canada endorses a proposal to deepen ties with the EU by adopting an 'associate member' status. Such a status would streamline regulatory alignment, trade, and security cooperation, potentially reshaping tech policy and data flows between North America and the EU. The move signals Canada’s readiness to formalize a closer, more structured partnership beyond traditional trade pacts.
加拿大支持通过准成员身份深化与欧盟的关系,可能推动监管、贸易与数据流动方面的更紧密协作。此举有望重塑北美与欧盟之间的科技政策与数据治理格局,并显示加拿大愿意在传统贸易框架之外形成更结构化的伙伴关系。
(2) Neovim have a ~$800k Bitcoin donation sitting untouched since 2023
Neovim has about $800k in Bitcoin donated, untouched since 2023. The post underscores how crypto donations can fund open-source projects, but also raises questions about liquidity, access, and governance of donated crypto assets.
Neovim 持有约 80 万美元的比特币捐款,自 2023 年起未动。提醒人们加密捐赠能为开源项目提供资金,但也暴露出流动性、访问和治理等风险。
(3) Iran school bombing: grounds to believe US was behind atrocity, UN finds
A UN investigation says there are grounds to believe the US military carried out the Iran school bombing. The finding could exacerbate tensions in the region and prompt calls for accountability and independent verification.
联合国调查称存在证据表明美国军方参与对伊朗一所学校的爆炸袭击,可能加剧区域紧张局势并促成对问责与独立核查的呼声。
(4) One Year of Sponsored Servo Development
A year into a sponsored development program for Servo, the team highlights accelerated contributions, milestones, and evolving sponsor expectations. The post outlines what sponsorship unlocked, how governance shaped decision-making, and what’s on the horizon for the browser engine.
在 Servo 的赞助开发计划开展一年之际,团队回顾了贡献增长、重要里程碑以及对赞助方的期望演变。文中解释赞助带来的能力提升、治理方式如何影响路线选择,以及未来的开发方向。
(5) GLM Built Its Own Inference Infrastructure
GLM built its own inference infrastructure, signaling a move toward tighter integration between model development and serving. By owning the hardware and software stack, they aim to optimize latency, cost, and security, and reduce dependency on cloud providers.
GLM 自建推理基础设施,体现了在模型开发与服务之间实现更紧密耦合的趋势。掌控硬件与软件栈有助于降低延迟、成本与安全风险,同时减少对云厂商的依赖。
(6) CCC invites all model citizens to 40C3
Chaos Communication Congress invites 'model citizens' to 40C3, inviting participants to discuss openness, AI ethics, and hacker culture at the event.
Chaos Communication Congress 邀请“模型公民”参加 40C3,号召参与者讨论开放、人工智能伦理与黑客文化等议题。
(7) AI Safety Is Mostly a Sex Cult
The post argues that AI safety discourse is dominated by a tight-knit, gatekept circle that enforces norms through social dynamics. It calls for more open, diverse governance and less dogmatic adherence to a single worldview.
文章认为 AI 安全领域被一个紧密封闭的圈子主导,通过社会压力和门槛来维护规范。呼吁建立更开放、多元且透明的治理路径,减少教条化影响。
(8) Training a 4B model to produce 81% faster query plans than Postgres
A 4B-parameter model is trained to output query plans that run 81% faster than PostgreSQL's planner. This demonstrates the potential of learned query optimizers, but practical use requires thorough benchmarking across workloads and smooth integration with existing databases.
一个4B参数的模型被训练来输出查询计划,其规划阶段比PostgreSQL的生成器快81%。这展示了学习优化器在查询优化中的潜力,但在实际应用中需要对多种工作负载进行基准测试,并考虑与现有数据库的无缝集成。
(9) Xiaomi Mimo 2.6 live post-training dashboard
Xiaomi Mimo 2.6 introduces a live post-training dashboard that gives engineers real-time visibility into model performance after training runs. It enhances experiment tracking, metrics comparison, and configuration debugging across iterations.
小米 Mimo 2.6 引入实时的后训练仪表板,为工程师提供训练完成后的模型性能实时可视化。它增强了实验跟踪、指标对比和跨迭代的配置调试能力。
(10) Keys Not Included: recovering the signing keys for US driver's license barcodes
This piece dives into the process of recovering signing keys used to sign US driver's license barcodes, highlighting key management gaps and potential security implications for ID integrity. It explains the challenges of reconstituting cryptographic keys without original materials and what it means for barcode validation and revocation workflows.
本文聚焦于用于签署美国驾照条码数据的密钥如何被找回,突出密钥管理缺口及其对身份认证完整性的潜在影响。文章描述在没有原始材料的情况下重建密钥的难点,以及这对条码校验与密钥撤销流程的意义。
(11) Introducing System One Models and Jev
Typesafe.ai unveils a new System One model family and a model named Jev, outlining their architecture, capabilities, and intended use cases. The launch signals an emphasis on safe, scalable AI tooling aimed at enterprise workloads and developer productivity.
Typesafe.ai 公布 System One 系列新模型及名为 Jev 的模型,介绍了其架构、能力与应用场景。此次发布凸显其在企业级 AI 工具链中的安全性、可扩展性与开发者友好性的定位。
(12) Nvidia announces native GPU programming in Rust
NVIDIA unveils native Rust support for writing GPU kernels, offering two tracks to run CUDA code from Rust. The move could boost safety and productivity by bringing Rust's guarantees to high-performance kernels and by easing integration with the CUDA ecosystem.
NVIDIA 推出用于编写 GPU 内核的原生 Rust 支持,提供两条 CUDA 开发路径。此举有望提升安全性与生产力,并促进 Rust 生态与 CUDA 的深度融合。
Tiny programming tricks can yield outsized gains in clarity and speed. A few well-chosen patterns—like leveraging language features, avoiding boilerplate, and embracing simple abstractions—can make code easier to maintain and faster to ship.
微小的编程技巧往往带来意想不到的提升,包括代码可读性、可维护性以及潜在的性能改进。通过善用语言特性、减少重复代码与采用简洁的抽象,这些技巧帮助开发者更高效地交付高质量软件。
(14) EU chief opens door for Canada to become 'associate member'
EU leaders signal openness to Canada becoming an associate member, signaling closer regulatory and security cooperation with the bloc. The move could reshape Canada-EU ties, accelerating alignment on trade, digital policy, and strategic issues. It stops short of full membership, but sets a framework for deeper collaboration.
欧盟领导人表示愿意让加拿大走上“准成员”之路,显示两者在监管与安全合作方面将更紧密。此举可能重塑加拿大与欧盟的关系,加速在贸易、数字政策和战略议题上的协同。虽然非正式成员身份,但为更深层次的协作设定了框架。
(15) Hackers Got Inside a Flock Camera
Hackers breached a Flock camera, and the retrieved data reveals how the system authenticates, communicates with the cloud, and handles footage. The leak provides a rare inside look at the telemetry and control signals powering modern surveillance hardware, highlighting potential weaknesses in device-to-cloud architectures. It underscores the need for stronger firmware integrity and better security practices in IoT surveillance.
黑客入侵了 Flock 摄像头,窃取的数据揭示了该系统如何进行认证、与云端通信以及如何处理影像。此举让人得以窥见现代监控硬件背后的遥测与控制信号,揭示设备与云端架构中的潜在弱点。它强调需要加强固件完整性和物联网监控的安全实践。
Backups Aren't Simple argues that robust backup strategies require verification, retention policies, testing, and ransomware resilience, not just copying files. The post emphasizes guarding against data loss and ensuring reliable restores.
《备份并非简单》认为健全的备份策略需要核验、保留策略、定期测试和勒索软件防护,而不仅仅是简单地拷贝文件,强调确保可恢复性与数据安全。
(17) Australia says it could follow Canada in forging deeper ties with EU
Australian officials say Australia could deepen ties with the EU, mirroring Canada's approach. A closer partnership would influence trade, regulatory coordination, and tech policy in Australia’s region, complementing its security partnerships.
澳大利亚官员表示可能效仿加拿大,与欧盟建立更紧密关系,推动贸易、监管对接和科技政策协同。此举将与其在印太地区的安全伙伴关系互为补充。
(18) Mistral X Mozilla: Private, Multilingual AI Browsing
Mistral AI teams up with Mozilla to offer a private, multilingual AI browsing experience. The setup emphasizes privacy-preserving on-device inference and strong language support, aiming to keep user data out of cloud telemetry. The move signals growing emphasis on user privacy in AI-enhanced browsing.
Mistral AI 与 Mozilla 合作,推出私密且支持多语言的 AI 浏览体验,强调在设备端进行隐私保护推断并提供强大的语言支持,尽量将用户数据与云端遥测分离。这一举动体现了在 AI 辅助浏览中对隐私日益重视。
(19) Breaking the 1.58-bit Barrier for Ternary LLMs
Researchers break the 1.58-bit barrier for ternary LLMs, suggesting that highly quantized, three-value models can still achieve competitive performance. The work highlights new techniques for maintaining accuracy at ultra-low bitwidth, enabling cheaper, more scalable inference.
研究团队打破三值语言模型的1.58比特瓶颈,表明极低位宽的三值权重也能达到可观的性能。该工作展示了在极低位宽下保持准确度的新办法,使推理成本更低、扩展性更强。
(20) HarnessTax: How Much Does the Harness Matter for Coding Agents?
HarnessTax investigates how much the coding agent harness influences performance, reliability, and behavior in autonomous tooling. The write-up discusses empirical findings, tradeoffs of harness complexity, and guidance for choosing or building an effective agent framework.
HarnessTax 探讨在编码代理中,Harness 对性能、可靠性和行为的影响有多大。文中给出经验发现、对复杂性取舍的分析,以及在选择或构建高效代理框架时的建议。
(21) OpenSpec – A lightweight and configurable AI spec framework
OpenSpec introduces a lightweight, configurable AI spec framework that lets teams describe model requirements, data contracts, and evaluation criteria in a portable format. It aims to improve interoperability and clarity across AI systems.
OpenSpec 提出一个轻量、可配置的 AI 规格框架,允许团队用可移植的格式描述模型需求、数据契约与评估标准,提升 AI 系统之间的互操作性和清晰度。
(22) PS5 Linux lead quits: "a bunch of noobs using LLMs" that "they don't understand"
The PS5 Linux lead has quit amid a clash over governance and culture in open-source development, branding critics as 'a bunch of noobs using LLMs they don't understand.' The resignation spotlights tension between seasoned maintainers and AI-powered tooling, raising questions about project direction, sustainability, and community governance. It also signals how AI tools are reshaping collaboration in high-profile OSS projects.
PS5 Linux 项目负责人离职,指责社区成员在使用大型语言模型时缺乏理解。事件暴露开放源代码项目在治理、AI 工具依赖与社区贡献方式上的冲突。它也揭示了 AI 工具正在重塑高知名度开源项目的协作方式。
(23) The Google Play app review process now regularly takes longer than a week
Google Play’s app review times have increasingly exceeded a week, delaying app updates and new launches. The growing backlog hurts developers' release cadence and can slow time-to-market for important features and security fixes. The trend highlights ongoing frictions in major app marketplaces as they scale and enforce security controls.
Google Play 的应用审核时间现在经常超过一周,延缓了应用更新和新应用上线。这给开发者的发行节奏带来影响,更新推送成本上升,也可能促使他们寻求替代市场或其他分发方式。此趋势反映出大型应用商店在规模化与安全之间的持续摩擦。
(24) Apple Reference Image: A New Approach for Verified Photography
Apple unveils the Reference Image approach to verify photography provenance on devices, enabling cryptographic-style checks and image-forensics workflows. The goal is to harden trust in photos, making spoofed or manipulated imagery easier to detect at capture or processing time. This strategy could reshape how apps and services verify media authenticity in practice.
苹果推出参考图像,用以验证摄影的来源与真实性。通过对比参考信息,系统可更早检测伪造或篡改的照片,提升数字影像的可信度。此方法可能改变媒体真实性的验证标准与流程。
(25) Claude Cowork and chat are now one Claude
Claude is merging its Cowork and Chat offerings into a single Claude experience. The consolidation aims to streamline team workflows and boost AI-assisted collaboration across coding and communication tasks.
Claude 将 Cowork 与 Chat 功能合并为一个统一的 Claude 体验,简化团队协作与 AI 助力的工作流,提升跨编程和沟通任务的协作效率。
(26) An update on Wayback Machine access
Internet Archive provides an update on access to the Wayback Machine, clarifying current accessibility options, rate limits, and API usage for researchers and developers.
互联网档案馆就 Wayback Machine 的访问情况给出更新,澄清当前的访问方式、速率限制与研究/开发者 API 的使用条件。该进展暴露出开放存档与平台控制之间的张力,以及对可复现性和历史研究的影响。
(27) Fed hikes rates as inflation worries push up bond yields
The Fed raised rates amid stubborn inflation, pushing bond yields higher. The move signals persistent price concerns and could raise borrowing costs for consumers and businesses, influencing tech funding and market activity.
美联储在通胀担忧持续存在的背景下再次加息,推动国债收益率走高。这一举措表明价格稳定的压力仍在,可能提高个人与企业的借贷成本,影响科技领域的融资环境与市场运作。
(28) Original Sony PlayStation 2 security chip 'broken wide open' after 26 years
A long-running reverse-engineering effort finally cracked the PS2's security chip, shedding light on how the system prevents tampering. The breakthrough exposes security flaws that persisted for decades and has implications for hardware preservation, emulation, and security nostalgia. It demonstrates how even enduring hardware protections can eventually yield to deep analysis.
经过长期逆向工程的努力,PS2 的安全芯片终于被破解,揭示了系统防篡改的原理。此次突破暴露了数十年来持续存在的安全漏洞,并对硬件保存、仿真与安全研究产生影响。也显示出即便是长期的硬件保护,最终也会被深入分析所突破。
(29) A warning about 'model welfare'
Mustafa Suleyman cautions that as AI models scale, we risk treating them as moral actors with welfare concerns. He argues for governance that addresses welfare-related concerns without anthropomorphizing models, and for safeguards against misaligned incentives.
Mustafa Suleyman 警示,随着模型能力提升,我们可能对其福利产生拟人化的伦理担忧。他主张在不将模型拟人化的前提下,制定覆盖福利相关风险的治理框架,并防范错位激励。
(30) Vectorized and performance-portable Quicksort (2022)
Google Open Source describes a vectorized Quicksort that stays fast across architectures thanks to portable SIMD. The approach reduces maintenance costs for library developers and speeds up data-heavy workloads on diverse hardware.
Google 开源团队介绍了一种向量化、跨体系结构可移植的快速排序实现,利用通用 SIMD 提升跨平台的执行效率。此做法降低了库开发的维护成本,并提升了在多样硬件上的大规模数据处理速度。
(31) AWS says it can't restore some data from mideast facilities struck by Iran
AWS says some data cannot be restored after Iran-struck Middle East facilities, underscoring limits of disaster recovery and the value of cross-region backups.
AWS 表示在被伊朗袭击的中东设施中,部分数据无法恢复,凸显灾备的局限性,以及跨区域备份的重要性。
Salesforce suffered a global outage that disrupted access to core CRM and cloud services across regions. Incident responders are investigating the root cause and restoring services, with status updates guiding customers through recovery. The outage underscores the risk of SaaS dependencies for business operations and the importance of incident readiness.
Salesforce 遭遇全球性宕机,影响了多区域的核心 CRM 与云服务。故障原因正在调查,服务逐步恢复,状态更新帮助客户度过修复阶段。此次事件凸显 SaaS 依赖对业务运营的风险,以及完善应急准备的重要性。
(33) Dream-RSI: Recursive Self-Improvement through Evolving Worlds
A study on Dream-RSI outlines recursive self-improvement by training agents in evolving environments. The approach explores how iterative self-improvement loops could scale AI capabilities, while underscoring safety and alignment challenges.
Dream-RSI 的研究探讨在不断演化的环境中训练代理以实现递归自我提升。该思路揭示自我改进循环如何潜在放大AI能力,同时也强调安全性与对齐问题的挑战。
(34) Learning Programming in an Age of LLMs
Large language models are changing how people learn to code, but fundamentals still matter. The piece argues for focusing on problem solving, design thinking, and reading code, with LLMs serving as debugging partners and code generators rather than crutches. Practical tips include deliberate practice, peer review, and building small projects to reinforce learning.
大语言模型正在改变编程学习方式,但基础仍然关键。文章主张专注于问题解决、设计思维和阅读代码,让 LLM 作为调试伙伴和代码生成工具,而非依赖的拐杖。实用建议包括有意识的练习、同行评审,以及通过小型项目巩固所学。
(35) Gemini 3.8 Live and 3.8 Live Extended Thinking
Google releases Gemini 3.8 Live and its Extended Thinking variant, boosting reasoning, multi-step problem solving, and tool usage in real time. The update underscores advances in AI reasoning capabilities and how Google is balancing speed, safety, and utility in consumer-facing models.
Google 推出 Gemini 3.8 Live 与 3.8 Live Extended Thinking,显著提升模型的推理、分步问题解决和工具调用能力。更新体现了在提升推理水平的同时,如何在速度、安全性与实用性之间取得平衡。
(36) Why I'm still bearish on LLMs after Navier-Stokes
The author remains bearish on LLMs despite progress exemplified by fluid dynamics analogies like Navier–Stokes. They argue that scaling models alone won’t overcome fundamental limits around reliability, reasoning, and alignment, urging caution and exploration of alternative AI approaches.
尽管以 Navier–Stokes 之类的比喻描述进展,作者仍对大语言模型持悲观态度。其认为仅靠扩展规模无法解决可靠性、推理与对齐等根本问题,呼吁谨慎并探索替代的 AI 方法。
DeepMind's Institute outlines its mission, research domains, and collaboration model as a central hub for AI science. The page emphasizes interdisciplinary work and long-term safety and alignment goals.
DeepMind 研究院阐述了其使命、研究领域与协作模式,定位为AI科学的核心枢纽。页面强调跨学科合作以及对长期安全与对齐目标的关注。
(38) Building a Linux GPU Driver for the M4 Mac Mini in One Month
A software engineer documents building a Linux GPU driver for Apple Silicon's M4 Mac Mini within a month. The chronicle sheds light on the sheer difficulty of porting or writing GPU drivers for non-x86 hardware, the state of Linux on Apple Silicon, and strategies for delivering credible open-source drivers quickly.
一名工程师记录在一个月内为 Apple Silicon 的 M4 Mac Mini 构建 Linux GPU 驱动的过程。此经历揭示了在非 x86 硬件上移植或编写 GPU 驱动的巨大挑战,以及 Linux 在 Apple Silicon 上的现状和快速交付开源驱动的策略。
(39) DeepSeek v4.1 Flash Is Now Our Best Hacking Model
DeepSeek v4.1 Flash is presented as the top-performing security-focused model for hacking tasks. The update emphasizes faster inference and stronger capabilities for automated vulnerability discovery and offensive security workflows.
DeepSeek v4.1 Flash 被宣布为在渗透测试任务中表现最强的模型,强调提升推理速度与自动化漏洞发现及红队工作流程的能力。
(40) We got admin access to Baseten's production GitHub
A security demonstration shows admin access to Baseten's production GitHub within 25 minutes, highlighting misconfigurations around secrets management and third-party access. The post emphasizes the need for better secret hygiene, stronger access controls, and rapid incident response.
安全演示显示在仅用 25 分钟内就拿下 Baseten 生产环境的 GitHub 管理权限,揭示了密钥管理与第三方访问中的配置漏洞。文章强调需要改进密钥安全、加强访问控制并提升事件响应速度。
(41) German Rheinmetall open-sources its Battlesuite connected weapon system protcol
Rheinmetall has released the protocol for its Battlesuite connected weapons stack as open source. The move highlights a rare instance of transparency in military tech and could spur cross-vendor interoperability and defense software ecosystems, while raising safety and dual-use concerns.
莱茵金属将其 Battlesuite 连接武器系统协议开源,此举在军事科技领域并不常见。该动作可能推动跨厂商互操作性与防务软件生态,但也引发安全和双用途应用的担忧。
(42) The engineering behind the US Strategic Petroleum Reserve
Engineering behind the US Strategic Petroleum Reserve explains how salt caverns, large-scale piping, and robust safety systems were engineered to store millions of barrels safely and respond to aging infrastructure and security needs.
美国战略石油储备的工程设计揭示了通过盐穴地下储存、规模化管线和强健的安全系统来安全存储数百万桶原油,并应对基础设施老化和安全需求。
(43) America's Driver's License Breach Is a National Security Disaster
A driver’s license data breach is framed as a national-security disaster due to identity theft risks and impacts on government services. The piece argues for urgent reforms to data protection and credentialing infrastructure.
驾照信息泄露被视为国家安全灾难,原因是身份盗用风险及对政府服务的影响。文中呼吁对数据保护与凭证基础设施进行紧急改革。
(44) My temporary PHP fix from 2014 has nearly 20M installs. Today I'm deprecating it
The author is deprecating a tiny PHP fix they shipped in 2014 that somehow gained 20 million installs. The post reflects on legacy tech debt, the fragility of tiny abstractions in the wild, and the need for explicit maintenance or sunset plans.
作者宣布弃用一项2014年发布的简易 PHP 修复,这个小工具竟然积累了近两千万次安装。文章反思遗留技术债务、野外稳定性对生态的影响,以及进行显式维护和逐步下线的必要性。
(45) Fujitsu launches made-in-Japan next-generation CPU FUJITSU-MONAKA
Fujitsu unveils FUJITSU-MONAKA, a next-generation CPU built in Japan to bolster domestic chip capability. The launch signals a renewed push for local semiconductor supply chains and AI-ready performance for enterprise workloads.
富士通宣布推出日本制造的下一代处理器 FUJITSU-MONAKA,旨在提升国内芯片产能。此次发布凸显日本加强本土供应链和面向企业工作负载、AI 计算的性能诉求。
(46) Chopping up books when they're physically too big
The post advocates slicing oversized physical books into manageable chunks to facilitate reading, scanning, or note-taking. It discusses practical methods, trade-offs for preserving context, and how to maintain readability when working with large volumes.
文中提出将过大实体书拆分成可管理的小块,以便阅读、扫描或记笔记。介绍了实用的拆分方法,并权衡了在保留语境与提升可读性之间的取舍。
(47) Recreating Voodoo Graphics and a Late-1990s Gaming PC on an FPGA
A project recreates the Voodoo Graphics pipeline and a late-1990s PC on an FPGA, illustrating retro hardware emulation and the trade-offs between accuracy and engineering practicality.
在 FPGA 上重现 Voodoo 图形管线和九十年代末一台游戏 PC,展示了对复古硬件的仿真与保留。讨论实现中的时序挑战、精度取舍,以及对数字保存的启示。
(48) There's a 100% Chance AI Agents Are Ruining the Internet
A provocative article argues there is a 100% chance AI agents are already ruining the internet, by automating content creation, gaming systems, and eroding trust. It discusses how autonomous agents influence search results, moderation, and information quality, potentially magnifying misinformation and manipulation. The piece serves as a warning about designing AI-powered systems with safeguards to preserve the integrity of online ecosystems.
一篇挑衅性的观点文章声称,AI代理人已经在毁坏互联网,原因包括自动化内容创作、系统操控和信任下降。文章讨论自治代理如何影响搜索、内容审核和信息质量,可能放大错误信息与操纵的风险。作者警告在设计 AI 系统时需要加入防护措施,以维护在线生态的完整性。
(49) Dystopian Surveillance Is Becoming a Reality
Pervasive surveillance tech—from cameras to data analytics—has moved from fiction to routine reality. The piece explains how collectors and regulators deploy profiling, location tracking, and behavioral analytics to shape society. It warns that without strong safeguards, civil liberties could shrink under the weight of omnipresent monitoring.
普及的监控技术从虚构走向日常现实,包括摄像头和数据分析在内的手段正在塑造社会。文章阐述了监控者与监管机构如何利用画像、位置跟踪和行为分析来影响社会秩序。若缺乏强有力的防护措施,公民自由可能在无处不在的监控压力下受损。
(50) WangNet – 1.8 MB, zero-dependency Numberwang adjudication in 11 languages
WangNet is a compact, 1.8 MB, zero-dependency model for Numberwang adjudication available in 11 languages. The project demonstrates how tiny, self-contained ML tooling can perform lightweight linguistic tasks offline, without external dependencies.
WangNet 是一个 1.8MB、零依赖的 Numberwang 判定模型,支持 11 种语言。该项目展示了体积极小、可离线运行的机器学习工具在语言任务上的可用性,以及对依赖的剥离所带来的便携性好处。