欧盟要干掉烦人的Cookie弹窗,但谷歌不乐意;Anthropic发现Claude 5太聪明不用管太多;Ruff规则翻了7倍;8美元芯片就能跑AI模型,这些都很值得看。
欧盟委员会在2025年秋季提出的数字综合法案中,计划通过浏览器自动发送用户隐私偏好信号来消灭Cookie横幅,但以谷歌为首的追踪行业正在大力游说阻挠,多个成员国和欧洲议会已开始反对。Anthropic移除了Claude Code超80%的系统提示,因为Claude 5代模型(Opus 5和Fable 5)能力提升,不再需要过多约束,上下文工程转向使用模型判断力和渐进式信息加载。Ruff v0.16.0默认规则从59条增至413条,新增Markdown代码格式化等功能。在8美元的ESP32-S3微控制器上可本地运行28.9M参数的语言模型,生成速度约9.5 token/秒。
2026 07 27 HackerNews
2026-07-27 Hacker News Top Stories # 欧盟拟推浏览器隐私信号功能以消灭Cookie横幅,但遭遇谷歌等追踪行业游说阻挠。 “他们是否已读不回?”网站公开记录面试后被公司“冷处理”情况,康泰纳仕、苹果和微软位列冷处理榜前三。 Claude 5代模型不再依赖严苛指令,上下文工程转向发挥模型判断力与渐进式信息加载。 GrapheneOS为锁定设备提供多层数据提取防护,包括磁盘加密、速率限制及自动重启回退至首次解锁前状态。 Ruff v0.16.0默认规则从59条增至413条,新增Markdown代码格式化与灵活抑制注释等功能。 Htmx 4.0以Game Boy卡带形式发布,内含收集泡菜击败Boss解锁源代码的复古游戏。 谷歌披露持有SpaceX约941亿美元股票,占股6%,部分受短期和长期出售限制。 在8美元ESP32-S3微控制器上本地运行28.9M参数语言模型,生成速度约9.5 token/秒。 美国出现破坏Flock车牌监控摄像头的义警运动,抗议隐私侵犯,已蔓延至23个州。 伦敦盖特威克机场推出机器人代客停车服务,仅优化内部空间利用,未简化用户流程或降低费用。 1. 消灭 Cookie 横幅 (Kill The Cookie Banner) # https://killthecookiebanner.eu/ 欧盟委员会在 2025 年秋季提出了一项法律改革(数字综合法案),其中包含一个解决 Cookie 横幅问题的方案:让浏览器自动发送用户的隐私偏好信号,用户只需设置一次,即可拒绝或限制追踪,不再被烦人的 Cookie 横幅骚扰。然而,以谷歌为首的追踪行业担心此举会降低用户同意率,正在大力游说,多个成员国和欧洲议会已开始阻挠该提案。目前,成员国和欧洲议会尚未最终表态,倡议组织呼吁公众联系自己在欧洲议会或本国政府的代表,表达对现状的不满,推动消灭 Cookie 横幅。需要注意,该提案只是“数字综合法案”的一部分,倡议组织明确反对该法案中其他削弱用户权利的条款。多个欧洲民间组织联合发起了这一行动。 HN 热度 761 points | 评论 366 comments | 作者:rapnie | 12 hours ago # https://news.ycombinator.com/item?id=49057175 点击复选框或按钮不能构成知情同意,因为很少有人真正阅读,只是想快速关掉 很多人快速点击"接受"而不阅读,虽然"拒绝"也常能消失,但"接受全部"总是立即消失 “拒绝"往往需要更多操作,这是故意设计,属于恶意合规 “仅必要"按钮有时不存储用户偏好,导致每次刷新都显示横幅,也属于恶意合规 不存储拒绝记录而存储接受记录违反 GDPR,造成接受和拒绝所需努力不对称 某些 Cookie 横幅提供商建议在欧洲以外地区不显示"拒绝全部"按钮,因为被起诉风险低,加州则建议显示 点击拒绝按钮可能无效,因为第三方 JavaScript 已加载,横幅 UI 无法强制其他代码行为 浏览器应提供默认拒绝或"永远不允许"的设置才是合理方案 使用扩展程序如"I don’t care about cookies"可自动拒绝大多数 cookie 弹窗 2. 他们是否已读不回? (Did they ghost you?) # https://didtheyghostyou.com/ 这是一个名为“他们是否已读不回?”的网站,旨在公开记录面试后被公司“冷处理”(ghosting)的现象。页面显示已有 709 份经过审核的匿名举报。用户可举报面试后无回复的公司,也能为沟通清晰的雇主点赞。网站设有排行榜,列举报案最多的公司:康泰纳仕、苹果、微软位居前三(各报告约 50、50、40 次)。同时设有“优秀沟通者”榜,表彰清晰告知结果的雇主,如田纳西河谷管理局、Virio.ai 等。右侧还解释了运作方式:匿名提交、经审核后计入公共记录,并回答了关于冷处理定义、等待时间、隐私保护等常见问题。 HN 热度 458 points | 评论 201 comments | 作者:mooreds | 1 day ago # https://news.ycombinator.com/item?id=49051120 招聘中的“ghosting”常因联系人突然离职或公司裁员导致系统无人跟进。 有些公司(如 Roku)在一年后才发拒信,新员工清理积压申请是原因之一。 从投递到回复的时间跨度极大:最长可达 4 年(DocuSign),最短为几小时甚至负数时间(Cloudflare 在提交过程中就发拒信)。 快速的自动拒信往往基于关键词筛选,甚至申请人还没填完表格就被拒绝。 远程面试通过后可能因 recruiter 被裁或公司冻结招聘而突然中断流程。 邀请提供推荐信在面试流程中备受争议,有人认为面试本身就应足以评估能力,有人则视其为必要数据点。 公司政策常限制推荐人只能提供“姓名、职位、在职时间”,导致其参考价值有限。 多次文化不匹配可能造成长久被拒的恶性循环。 3. Claude 5 代模型上下文工程的新规则 (The new rules of context engineering for Claude 5 generation models) # https://claude.com/blog/the-new-rules-of-context-engineering-for-claude-5-generation-models Anthropic 最近移除了 Claude Code 超 80% 的系统提示,因为新一代 Claude 5 模型(如 Opus 5 和 Fable 5)能力大幅提升,不再需要过多约束。文章总结了上下文工程的新规则: 用判断力替代规则 :不再给 Claude 硬性指令(如“不要写注释”),而是让它根据上下文自行判断,比如“让代码匹配周围代码的注释密度和风格”。 用接口设计替代示例 :不再提供大量工具使用样例,而是优化工具本身的参数设计,让参数命名和枚举值自然暗示使用方式。 用渐进式披露替代一次性堆砌 :不再把所有信息塞进系统提示,而是让 Claude 按需加载技能、工具定义等上下文,避免浪费上下文窗口。 文章还建议使用 claude doctor 命令优化 CLAUDE.md 和技能文件,避免前后矛盾或过度约束。 HN 热度 438 points | 评论 352 comments | 作者:mellosouls | 1 day ago # https://news.ycombinator.com/item?id=49051361 底层技术原理不明确,操作像黑盒迷信和占星术,没人真懂怎么用。 模型不遵守指令,常写错文件、格式混乱、遗漏步骤,输出不可靠。 基准测试提升但实际输出质量下降,价格越来越贵,让人失望。 依赖专有云 AI 等于放弃自主权,应使用可本地运行的开源模型。 可用专有 AI 加速开发本地软件,但需保证质量标准和维护性,避免锁定。 AI 生成的代码导致代码量爆炸、复杂性剧增、审查困难,实际交付反而更慢。 开发者过度依赖 AI 产生“脑腐”,自身能力退化,团队协作变差。 对 LLM 的不满类似于早期对编译器的怀疑,但编译器确定性强且优于人类,LLM 则非确定且易出错。 系统提示是必需的,因为 LLM 本质是 token 预测器,需要初始上下文引导。 用独立 AI 审查代码可消除初始编码的偏见和懒惰,提升质量。 新模型(如 Claude 5.6/Opus Fable 5)质量确有显著提升,并非停滞。 社区出现“提示词占星术”等非理性行为,取代了真正的软件工程实践。 企业打着“AI 原生”旗号实际效率降低,AI 成为管理层推广噱头。 4. GrapheneOS 针对锁定设备的数据提取防护 (GrapheneOS protections against data extraction from locked devices) # https://discuss.grapheneos.org/d/40700-grapheneos-protections-against-data-extraction-from-locked-devices GrapheneOS 针对锁定设备的数据提取提供了强大的防御措施,主要建立在 Android 17 的安全功能和最安全的硬件基础上。目前只有 Pixel 设备满足要求,2027 年起将因与摩托罗拉和高通的合作而扩展。 核心防护机制: 磁盘加密:攻击者难以直接破解,只能通过在首次解锁后(AFU)利用系统漏洞或暴力破解 PIN/密码。 安全元件速率限制:Android 16 QPR2 要求安全元件实现递增延迟(10 次后 4 小时,15 次后 41 天),最多 20 次尝试,并拒绝最近 5 次重复错误以节省尝试次数。GrapheneOS 仅支持最新一代安全元件的速率限制。 内部攻击抵抗:所有者用户必须成功认证后才能更新安全元件固件,防止政府胁迫创建绕过速率限制的固件更新。 GrapheneOS 的增强功能: 密码长度上限从 16 提升至 128 字符,支持高熵 diceware 密码短语。 可选二次因子指纹 PIN:将指纹尝试次数从 20 降至 5,失败计入二次因子 PIN 计数。可用 6-8 个随机 diceware 词作为主解锁方式(BFU),短 PIN 配合指纹(AFU)便捷使用。 强化利用防护:硬化的内存分配器、硬件内存标记(MTE)等。 锁定状态下默认阻止新 USB 连接,无活跃连接时禁用 USB 数据。 自动重启定时器(10 分钟至 72 小时,默认 18 小时)使设备回到首次解锁前(BFU)状态,并清除内存。 支持对二级用户和私人空间独立启用 BFU 状态(无需重启)。 胁迫 PIN/密码:输入后立即擦除整个设备(适用于所有用户和指纹二次因子,但不含 SIM PIN)。可作为防范数据提取的最后一层保障。 HN 热度 369 points | 评论 216 comments | 作者:Cider9986 | 18 hours ago # https://news.ycombinator.com/item?id=49055169 GrapheneOS 的 18 小时自动重启功能可将设备返回 BFU 模式,有效阻止密钥提取,保护数据安全。 媒体报道中将安全保护称为“默认犯罪”是误导性语言,不能因为防护强就污名化系统。 iPhone 拥有类似防护等级却不被视作“犯罪默认”,应推动更多人使用 GrapheneOS 以破除偏见。 GrapheneOS 在 Cellebrite 支持矩阵中有专属列,且至今未被破解(最后一版破解是 2022 年)。 iOS 并非完全安全,近期 Darksword 漏洞说明其风险;GrapheneOS 的 SELinux 强制模式是重要优势。 若 iPhone 真安全则不会出现可被利用的漏洞,可能缺少关键信息。 GrapheneOS 在 AFU(After First Unlock)状态下是 Cellebrite 最难攻破的系统;iPhone 保护优于除 Pixel 外的 Android 机型。 GrapheneOS 安全排序推荐:GrapheneOS > iOS > Pixel » 其他;谷歌的 MTE 在 PixelOS 上仍为非强制选项。 Cellebrite 尚不能破解较新版本的 GrapheneOS,而 iPhone 破解难度高于普通 Pixel,原因包括谷歌更早公开测试。 苹果和谷歌已从 GrapheneOS 复制功能(如重启定时器),GrapheneOS 的 USB 端口加固更彻底。 苹果可随时推送更新移除安全功能,且存在 PRISM 等后门风险,不可信。 最新 iPhone 难以破解,但旧款机型存在已知漏洞。 硬件(如 bootROM)漏洞无法修复,使用最新硬件可缩短攻击窗口。 建议 GrapheneOS 伪装成普通 Android 以避免被怀疑为犯罪工具,但谷歌不会放弃管理权限以利于数据收集,且伪装不切实际。 5. Ruff v0.16.0——重大更新——默认规则从 59 条增至 413 条 (Ruff v0.16.0 – Significant new updates – 413 default rules up from 59) # https://astral.sh/blog/ruff-v0.16.0 Ruff v0.16.0 发布。主要更新包括: 默认规则集大幅扩展 :从之前的 59 条规则增加到 413 条,涵盖更多严重问题(如语法错误、运行时错误)。可配置回旧规则集: [lint] select = ["E4", "E7", "E9", "F"] 。 Markdown 代码块格式化 :现在可以格式化 Markdown 文件中的 Python 代码块(支持 py 、 python 、 pyi 、 pycon 等标识),包括 Quarto 笔记本( .qmd )。可通过 fmt: off/on 或 HTML 注释禁用。 新的 ruff 抑制注释 :新增 ruff: ignore (抑制单行或下一逻辑行)和 ruff: file-ignore (抑制整个文件),支持添加原因说明。新增 --add-ignore CLI 自动添加。预览模式下支持使用规则名称替代代码。 输出显示差异 : check 和 format --check 默认输出中现在会显示修复的 diff 内容,不再需要单独 --diff 。支持多种输出格式(JSON、GitHub/GitLab 注释)。JSON 输出中部分字段可能为 null。 规则稳定化 :多项规则从预览转为稳定,包括 AIR303、CPY001、FURB164、FURB192、ISC004、LOG004、PLE0304、PLR0917、PLR1708、RUF036、RUF063、RUF068 等。 其他行为稳定化 :包括 BLE001 的异常日志抑制扩展、FA102 检查更多 PEP 585 API、INT 系规则支持更多 gettext 用法、S310 解析本地字符串绑定减少误报、S508/S509 支持新 PySNMP API、UP019 识别 typing_extensions.Text 等。 HN 热度 332 points | 评论 221 comments | 作者:vismit2000 | 15 hours ago # https://news.ycombinator.com/item?id=49056112 Ruff v0.16.0 新增大量默认规则,更新后能提升代码质量并发现之前遗漏的问题。 尽管 Astral 被 OpenAI 收购,ruff、ty 和 uv 仍被积极开发令人欣慰。 Ty 工具因误报多且缺乏基线支持,在大型代码库上不如基于 pyright 的方案;但 uv 和 ruff 很出色。 过度热衷“语法警察”工具令人费解,它们纠结于空格、引号等琐碎格式,却放过了超长列表推导这类真正复杂的代码问题,精力用错了地方。 自动化 lint 工具能消除 PR 中对代码风格的争论,让开发者专注更有价值的工作。 曾有过禁止在 PR 中讨论编码风格的公司,运行同样良好。 统一代码风格(如 Go)能保证所有代码外观一致,避免无谓讨论。 代码略微不同不是问题,只要可读易懂;强求格式统一会抹杀程序员的个性与人文气息,让人从工匠沦为代码猴子。 代码的可扩展性、可维护性和实际交付价值远比有趣的变量名更重要。 团队需要一致性,就像米其林餐厅的团队协作不能被单个厨师的任性破坏。 当核心人员离开,定制化与艺术化的代码会导致后续维护困难,软件不应过于“手工艺”。 程序员离开后代码仍在;争论本质是希望被当作艺术家还是齿轮。 在现实经济中,个人艺术追求应在业余时间实现;lint 规则可自动化,也能按需排除特定规则。 6. Htmx 4.0——首款仅在 Game Boy 上发布的 JavaScript 库 (Htmx 4.0, the first JavaScript library to release exclusively on the Game Boy) # https://swag.htmx.org/en-cad/products/htmx-4-the-game 这是一个商品页面,销售“htmx 4: the game”游戏卡带,售价 25 美元。该游戏号称是首款在 Game Boy 平台上发布的 JavaScript 库,包含四个关卡,玩家需收集泡菜、击败最终 BOSS Warren 以解锁 htmx 4.0 源代码。页面提供数量选择、加入购物车功能,并附带质量保证与退换政策说明。底部还展示了其他推荐商品,如贴纸、海报、马克杯等。 HN 热度 329 points | 评论 102 comments | 作者:rcy | 12 hours ago # https://news.ycombinator.com/item?id=49057241 HTMX 让我在三年间解锁了新的 Web 开发方式,尤其搭配服务端模板语言,极大简化了前后端交互 用 HTMX 和服务端模板替换了三分之二的 JS 代码,开发效率显著提升 HTMX 给人的感觉很好,技术简洁,适用广泛,且不严肃,团队对细节和乐趣非常用心 HTMX 本质上是旧概念(如.NET Update Panels)的新实现,但更强大、更完善 开发 React/Angular/Vue 十年后,回归服务端渲染(Ruby/Elixir/PHP)反而觉得更正确、更高效 HTMX 类似于过去 LAMP 栈的网站开发方式,但生活质量更高,更现代 之前反感 HTMX,但尝试后觉得不错,对 React 感到厌倦,HTMX 提供了更直接的开发体验 HTMX 商店对用户反馈响应迅速,例如按照抱怨很快上架了大尺寸咖啡杯,体现对社区的重视 商店的商品可能是按需印刷/代发,部分用户对质量表示担忧 使用 HTMX 时面临如何构建类型安全服务端模板的问题,目前仍在寻找解决方案 Quasar UI 框架很好,但 Material 组件不够理想,希望样式可以解耦,提供默认样式但允许自由定制 7. 谷歌披露持有 SpaceX 价值 941 亿美元的股票,占比 6% (Google Discloses $94.1B in SpaceX Stock, Marking 6% Stake) # https://www.wsj.com/tech/google-discloses-94-1-billion-in-spacex-stock-marking-6-stake-91655d7c 谷歌在最新季度文件中披露,持有 SpaceX 约 941 亿美元的股票,相当于该公司约 6% 的股份。这些可交易权益证券中,800 亿美元受短期出售限制,141 亿美元受长期限制(至 2027 年第三季度)。谷歌正扩大其轨道数据中心项目,以加速人工智能发展。 HN 热度 304 points | 评论 271 comments | 作者:1vuio0pswjnm7 | 11 hours ago # https://news.ycombinator.com/item?id=49057574 Google 曾向 SpaceX 投资约 9 亿美元,占约 7-7.5% 股权,公司当时估值约 100-120 亿美元。 SpaceX 如今重心偏向 AI 和 Twitter,不再是纯粹的太空公司,长期投资者可能想锁定期结束后退出。 SpaceX 在 IPO 前改为双重股权结构,马斯克等内部人持有 10 倍投票权的 B 类股,其他投资者只有 1 倍投票权的 A 类股。 创始人通过特殊投票权控制公司可能引发治理问题,但也有观点认为正是这种结构才让公司成功(如 Facebook)。 许多股东(如通过 ETF、养老金投资)并不知情或无法真正行使股东权利,但也有观点认为投资者应主动了解自身投资。 被动指数基金投资者通常不会关心投票权,但可通过选择其他基金或直接持股来获得投票权。 8. 在 8 美元微控制器上运行 28.9M 参数的大语言模型 (Running a 28.9M parameter LLM on an $8 microcontroller) # https://github.com/slvDev/esp32-ai 这是一个在 ESP32-S3 微控制器(约 8 美元)上运行的 28.9M 参数语言模型项目。它每秒可生成约 9.5 个 token,所有计算在设备本地完成,无需联网。 核心突破:利用 Google Gemma 模型中的“逐层嵌入”(Per-Layer Embeddings)思想,将 25M 参数的查找表存储在慢速闪存中,每次只读取需要的约 450 字节,而推理核心保留在快速 SRAM 中。这使得模型大小比此前同类芯片上的模型(260K 参数)大了约一百倍。 模型训练于 TinyStories 数据集,能生成简短连贯的故事,但无法回答问题、写代码或常识推理——限制来自推理核心的小尺寸,而非存储技巧。 项目包含完整的固件(含接线和刷写指南)、训练/量化/消融代码,以及详细的实验结果文档(RESULTS.md)。作者保留了历史提交记录,包括早期参数计算的错误与修正,供读者参考。 HN 热度 269 points | 评论 68 comments | 作者:boveyking | 1 day ago # https://news.ycombinator.com/item?id=49050512 现在的 5 美元微控制器功能强大,例如 Milk-V Duo 系列具备 256MB 内存、1TOPS TPU、运行 Linux,还有 128 位矢量 ISA 支持 1024 位单指令处理。 这类 SoC 是异构计算设备,包含 arm64 核和两个 RISC-V 核(1GHz 跑 Linux、700MHz 跑 RTOS)。 有人认为在受限环境运行模型无用,但实验和迭代能突破限制,例如计算机视觉已成功落地 MCU。 从零挑战极限是学习的过程,即使看似无用也能获得技能;具体应用如用水表读取、AI on the edge。 存在更便宜的微控制器(如 0.03 美元的 Padauk),但多为 OTP,高产量时才有意义。 微控制器不应局限于汇编或 C,可运行更高层次系统(如 Xerox PARC OS)。 9. 日益壮大的义警运动旨在破坏 Flock 监控摄像头 (The growing vigilante movement to knock out Flock surveillance cameras) # https://www.theguardian.com/us-news/ng-interactive/2026/jul/25/flock-surveillance-cameras 《卫报》报道:美国兴起一股地下隐私活动人士运动,他们通过破坏或遮挡 Flock 公司的自动车牌识别摄像头(ALPR)来表达对大规模监控的抗议。Flock 摄像头遍布全美约 6000 个社区,每月扫描数十亿次车牌,被批评者称为“监控工具”,但公司声称其并非用于追踪个人。 化名“NoMark”的明尼苏达州活动人士已破坏十余个摄像头,并发布视频吸引数十万粉丝。类似行动在全美 23 个州至少发生 33 起,手法包括喷涂、遮挡镜头、剪断电线等。部分参与者已被警方指控破坏财产罪,但他们坚称摄像头违宪,破坏行为是“传递信号”。Flock 公司则回应称已制定摄像头受损应对方案,并强调摄像头对公共安全至关重要。 HN 热度 268 points | 评论 166 comments | 作者:bookofjoe | 1 day ago # https://news.ycombinator.com/item?id=49050538 Flock 监控系统被宣传为终结犯罪,但实际上是控制工具,被犯罪分子利用 监控应该反向:普通公民匿名,政府成员应被 24/7 监控,权力越大监控越严 民主社会中政客是雇员,应服务于公众利益,而非享有特权 这是部落主义的堕落:财富流向首领,他们可恣意妄为,社会暴力、报复性强 任何人都可以建立自己的监控网络来追踪政客,这是合法的 常见犯罪与腐败相关,但 Flock 缺少防止警察滥用(如跟踪前妻)的保障 Flock 摄像头确实用于检测被盗车辆等犯罪,但警察只处理大规模案件,对零散盗窃不关心 所有数据被保留,无论有无嫌疑,这是最令人担忧的问题 增加监控并未减少犯罪或追回被盗财产,因为警察不跟进 警察更热衷于殴打黑人、镇压抗议,而非解决实际犯罪 即使通过 Find My 精确定位被盗手机,警察也不会帮忙找回 10. 伦敦盖特威克机场推出机器人机场停车服务 (London Gatwick has launched a robotic airport parking service) # https://aerospaceglobalnews.com/news/gatwick-airport-robotic-parking-stanley-robotics/ 该页面是一个网站的 Cookie 同意管理界面,列出了不同类别的 Cookie 及其用途。页面包含以下分类: 必要型 Cookie(25 个) :用于网站基本功能,如页面导航和安全区域访问。包括 Cloudflare、Cookiebot、Google、LinkedIn、Soundcloud 等提供商的 Cookie。 偏好型 Cookie(6 个) :用于记住用户的语言、区域设置、弹窗显示状态等。来自 LinkedIn、Telegram 等。 统计型 Cookie(12 个) :用于匿名收集访问者行为数据,帮助网站优化。包括 Hotjar、Microsoft、Soundcloud、Telegram、Vimeo 等。 营销型 Cookie(42 个) :用于跨站追踪用户,展示相关广告。 页面底部提供了“必要”“偏好”“统计”“营销”四个选项供用户选择同意或拒绝。 HN 热度 264 points | 评论 222 comments | 作者:agotterer | 9 hours ago # https://news.ycombinator.com/item?id=49058669 该机器人停车服务仍需先停车再坐巴士,并未真正解决用户便利性问题,只是机械移动车辆。 机场停车费过高,用户希望自动化能降低价格,但可能不会实际降价。 用户更信任自己停车而不愿把钥匙交给代客泊车公司,担心车辆被滥用或保险失效。 骑自行车去机场在荷兰可行,因为有完善自行车道和适应雨天的衣物,但带行李和恶劣天气仍是障碍。 电动货运自行车可缓解行李运输问题,但并非人人适用。 汽车被视为私人庇护所,可避免与他人接触,但车祸死亡率高于街头暴力。 不同地区气候差异(如北美强雷暴 vs 荷兰细雨)影响对自行车出行可行性的判断。 Hacker News 精彩评论及翻译 # The new rules of context engineering for Claude 5 … # https://news.ycombinator.com/item?id=49052510 Now I have the full picture. You’re right to push back, and that’s on me. The load-bearing seams of language are the smoking gun I should have been aware of. hmokiguess 现在我看清全貌了。你反驳得对,这是我的错。语言中的承重接缝就是我一直该注意到的确凿证据。 Did they ghost you? # https://news.ycombinator.com/item?id=49052057 Anecdotal, I know, but I was ghosted by Google back in 2004-2005 or thereabouts. Back and forth with a recruiter, who promised me that she would book phone screens. Then heard nothing. Pinged her repeatedly. Nothing. A few years later got another Google recruiter after me. Ended up getting hired in 2008. Looked up the previous recruiter. Her last day at the company was the day she promised she would book phone screens, or the day after (can’t remember exactly, this is quite a few years ago). I can only assume she was suddenly let go. Ever since, I keep wondering how many ghostings happen because the person holding the strings disappears for some reason, and there’s a lack of system to follow up on that. arcade79 我知道这只是个例,但早在2004-2005年左右,我就被谷歌放了一次鸽子。当时和一位招聘人员反复沟通,她承诺会帮我安排电话面试,然后就杳无音信了。我反复联系她,毫无回音。 几年后另一位谷歌招聘人员联系了我,最终我在2008年被录用了。 我查了一下前一位招聘人员的情况,她在这家公司的最后一天,正好是她承诺安排电话面试的那天,或者第二天(记不太清了,毕竟很多年前的事了)。我只能假设她突然被解雇了。 从那以后,我一直在想,有多少次被放鸽子的情况,是因为掌握主动权的人因故消失,而缺乏后续跟进机制造成的。 DeepSeek pause fundraise after comments on compute… # https://news.ycombinator.com/item?id=49053254 I think the way to parse the current title “DeepSeek pause fundraise after comments on compute gap to US leaked (transcript) [pdf]” is that there was a leak that DeepSeek will pause fundraising because they perceive there is a compute gap with the US. I am also guessing that the majority of the people who read this title will think that DeepSeek is pausing this fundraising because some comments they made about the compute gap were leaked. That is not the case. credit_guy 我认为当前标题“DeepSeek在关于与美国算力差距的评论泄露后暂停融资(文字记录)[PDF]”的正确解读是:有一则泄露消息称DeepSeek将暂停融资,因为他们认为与美国存在算力差距。 我也猜测,大部分读到这个标题的人会认为DeepSeek暂停融资是因为他们关于算力差距的某些评论被泄露了。但事实并非如此。 Google Discloses $94.1B in SpaceX Stock, Marking 6… # https://news.ycombinator.com/item?id=49058426 This investment has never been secret. Google (now under parent company Alphabet) invested roughly $900 million as the majority of a ~$1 billion funding round alongside Fidelity Investments. This gave Google an initial equity stake of about 7–7.5% in SpaceX at a valuation of roughly $10–12 billion. miohtama 这项投资从来都不是秘密。 谷歌(现隶属于母公司Alphabet)与富达投资共同参与了SpaceX约10亿美元的融资轮,其中谷歌投资约9亿美元,占大部分份额。这使得谷歌最初获得了SpaceX约7-7.5%的股权,当时公司估值约为100-120亿美元。 Ruff v0.16.0 – Significant new updates – 413 defau… # https://news.ycombinator.com/item?id=49056823 The point of the “grammar nazi” bots is to focus on the actual problems: if a bot is deciding about linting, you don’t have to waste brain power to discuss it in PRs. It is what it is, everyone gets the same, shut up and work on what matters. I’m surprised you consider it a lot of energy spent, I tend not to spend any on this, it just runs automatically on my code and I drop out of pretty much every discussions about linting as it’s good enough with automated tools. I also used to work in places where there was no such tools, and there I had to actually spend time discussing and thinking about linting. Majestic121 “语法警察”机器人的意义在于聚焦实际问题:如果由机器人来决定代码规范,你就不必浪费脑力在PR中讨论这些事。 事实就是如此,每个人都一视同仁,闭嘴去做真正要紧的事。 我很惊讶你觉得这很耗精力——我通常不会在这上面花任何时间,它只是自动运行在我的代码上,而我也几乎退出所有关于代码规范的讨论,因为自动化工具已经足够好了。 我以前也在没有这类工具的地方工作过,那时我确实得花时间讨论和思考代码规范问题。 The growing vigilante movement to knock out Flock … # https://news.ycombinator.com/item?id=49051660 Flock was pitched as the triumph of technology over criminality. It’s surveillance network was supposed to end crime. However, when people witness extreme criminality thriving unpunished at the top levels of U.S. politics, the lie becomes evident. Flock isn’t about ending crime. It’s a tool of control to be used by criminals. Who watches the watchers? Everyone. beloch Flock被宣传为技术对犯罪的胜利,其监控网络本应终结犯罪。然而,当人们看到美国政治高层中极端犯罪行为猖獗却逍遥法外时,谎言便昭然若揭。Flock并非旨在终结犯罪,而是犯罪者用来实施控制的工具。谁来监视监视者?所有人。 Kill The Cookie Banner # https://news.ycombinator.com/item?id=49059240 Tired of misleading cookie banners? The EU Commission has finally proposed a solution: set your privacy preferences in the browser once, and never see another banner. So lawmakers do know how to make legally binding preferences based on device settings? What a crazy innovation.. now if only parents were given these options to indicate their child is using a device.. we could do away with all this Online Safety Act nonsense… Phemist 厌倦了那些误导性的Cookie横幅?欧盟委员会终于提出了一个解决方案:在浏览器中一次性设置好你的隐私偏好,再也不会看到那些横幅了。 原来立法者们确实知道如何基于设备设置做出具有法律约束力的偏好?真是了不起的创新啊……要是家长也能有这样的选项来表明孩子正在使用设备,我们就能摆脱这些《在线安全法》的胡闹了…… Cloudflare’s new AI traffic options for customers # https://news.ycombinator.com/item?id=49053435 The big news here is that Googlebot will be blocked from September 15th onwards by one the “block training” policies, because Google use the same crawler infrastructure for their search index AND for training Gemini: Another change that will apply on September 15 is that multi-purpose crawlers (specifically those that combine Search with Training) will be allowed/blocked according to all of their behaviors, in line with our call for transparency for website owners. Since the defaults will be enforced by the most restrictive applicable rules, multi-purpose crawlers such as Googlebot, Applebot, and BingBot will be blocked by customers who have selected to block Training (either through the new options to manage AI traffic, or through the legacy Block AI bots service). simonw 重大消息:自9月15日起,Googlebot将被“阻止训练”政策屏蔽,因为Google对其搜索索引和Gemini训练使用的是同一套爬虫基础设施: 另一项将于9月15日生效的变更是,多用途爬虫(特指那些将搜索与训练结合使用的爬虫)将根据其所有行为被允许或阻止,这符合我们要求对网站所有者保持透明的呼吁。由于默认规则将按照最严格的适用条款执行,因此选择了阻止训练(无论是通过管理AI流量的新选项,还是通过原有的“阻止AI机器人”服务)的用户将屏蔽Googlebot、Applebot和BingBot等多用途爬虫。 London Gatwick has launched a robotic airport park… # https://news.ycombinator.com/item?id=49059244 So I’ll have to park my car in a garage first, then take a bus to the terminal just so that a robot can move my car from the place where I parked it to a different place? I was hoping it’d be something where I’d pull up to the curb, grab my bags and head in while the robot parked the car for me but apparently I’ll still have to take a bus to the terminal? pontus 所以我得先把车停到车库里,然后坐公交到航站楼,就为了让机器人把我的车从停的地方挪到另一个地方?我原本希望的是开到路边,拿上行李直接进去,机器人帮我把车停好,但显然我还是得坐公交去航站楼? Opus 5 is currently #1 on Artificial Analysis Inte… # https://news.ycombinator.com/item?id=49042676 #1 in a very close race is way less useful when you have to walk on eggshells to avoid triggering censorship (“safeguards”) that either refuse or knock it down to another model. I’ve almost completely stopped using Claude (except some legacy workflows) for this reason, reliability matters more than scoring 61 instead of 57. To me Claude is the most compromised and unreliable model (between the censorship and the id checking - which I have not experienced personally), it’s not worth whatever slight benchmaxxing they did for the latest release. andy99 在激烈竞争中排名第一远没那么有用,当你不得不小心翼翼避免触发审查(“保护机制”),这些机制要么拒绝响应,要么将回答降级到另一个模型。因为这个原因,我几乎完全停止使用Claude(除了一些旧的工作流程),可靠性比得分从57提升到61更重要。对我来说,Claude是最妥协且最不可靠的模型(在审查和身份验证之间——虽然我个人没遇到过身份验证问题),无论他们最新版本在基准测试上做了多少微小的优化,都不值得。 What is happening to jobs? Separating AI hype from… # https://news.ycombinator.com/item?id=49053025 A challenge with this kind of study is that coding agents (Claude Code, OpenAI Codex) only started working really well in late November, which for most people meant early January due to the December break. General agents (OpenClaw, Anthropic Copilot, ChatGPT “Work”) started working even later than that. This category of software may have a much more meaningful impact on work than the mostly-chat systems we were using from 2022-2025. Studies that mainly focus on 2022 to end of 2025 might be missing out on a material uptick in capabilities. simonw 这类研究面临的一个挑战是,编码代理(如Claude Code、OpenAI Codex)直到去年11月下旬才开始真正表现出色——对大多数人而言,由于12月假期,实际感受到这一变化已是在1月初。 通用代理(如OpenClaw、Anthropic Copilot、ChatGPT的"工作"模式)甚至比这更晚才起步。 这类软件对工作的影响可能远大于我们在2022年至2025年间使用的那类以聊天为主的系统。 那些主要聚焦于2022年至2025年底的研究,可能会错过其能力上的实质性跃升。 Android may soon restrict on-device ADB # https://news.ycombinator.com/item?id=49046353 Limiting ADB is the obvious next step. Even if this one specific feature request does not come to pass, Google has cornered everyone into relying on a developer interface for any normal personal computing tasks, whether running on-device or through USB/wireless. It’s quite clear at some point in the future you will either be required to surrender your identity to them and pay a yearly fee or be severely limited to continue using it in any meaningful capacity, because Google does not want you to develop applications on Android outside their controlled channels – and it’s a developer bridge, the battle was already lost when they did not back down from the changes forbidding normal, legitimate ̶s̶i̶d̶e̶l̶o̶a̶d̶i̶n̶g̶ installation. Don’t even get me started on OEMs that force an audio warning such as “This call is being recorded,” when it’s in places where it’s not legally required. This is also Google’s fault. Their dialer–that OEMs increasingly pick over their own, despite their always being much better, see old MIUI one for example–just blanket applies the rule almost everywhere. Especially annoying on all MediaTek SoCs that do not support the feature on an hardware level at all through proper, reliable third-party applications. As if you didn’t need any more proof you don’t own “your” devices. But maybe in a couple years Gemini will be able to listen to the calls and summarize them for you, just need to go through the approved surveillance channel. 0x_rs 限制ADB显然是下一步。即便这个特定功能请求未能实现,谷歌也已经迫使所有人依赖开发者接口来完成任何正常的个人计算任务——无论是在设备上运行,还是通过USB/无线连接。很明显,在未来的某个时间点,你要么必须向谷歌交出身份并支付年费,要么在继续以任何有意义的方式使用它时受到严重限制,因为谷歌不希望你在其控制渠道之外开发安卓应用——而这是一个开发者桥梁,当谷歌坚持推行禁止正常、合法的侧载安装的改动而不退缩时,这场战斗就已经输了。 更别提那些在无需法律要求的地区强制播放“此通话正在录音”音频警告的OEM了。 这也是谷歌的错。他们的拨号器——尽管OEM自家的拨号器一直更好(比如旧版MIUI的拨号器),却越来越多地选择谷歌的——几乎在所有地方一刀切地应用这条规则。尤其令人恼火的是,在所有联发科SoC上,它们根本无法通过可靠的三方应用在硬件层面支持该功能。仿佛你还需要更多证据证明你并不真正拥有“你的”设备。但或许几年后,Gemini就能帮你监听通话并总结内容,只需要通过那条被批准的监控通道即可。 Android may soon restrict on-device ADB # https://news.ycombinator.com/item?id=49046291 It seems to require the user to: Enable Developer Mode by going to an obscure settings page and tapping the build number seven times Enable USB ADB debugging in the Developer Options Establish an actual USB ADB session Enable TCP/IP ADB debugging in the Developer Options Unknowingly download a malware app from the official Play Store Blindly click “Yes” on the permission prompt. In other words: this is all but impossible to impact regular users, and it requires a particularly careless developer to be hit by it. And it only works if the Play Store is useless at preventing malware in the first place - but I thought their excellent app scanning was the entire reasoning behind all-but-banning 3rd-party app stores and sideloading??? It is “for safety” in the same sense that governments banning all encryption is to “protect the children” or to “prevent terrorism”: flawed justification invented to distract from the real reason they want it. crote 似乎要求用户: 进入一个晦涩难懂的设置页面,连续点击版本号七次来启用开发者模式 在开发者选项中启用USB ADB调试 建立实际的USB ADB连接会话 在开发者选项中启用TCP/IP ADB调试 毫不知情地从官方Play商店下载恶意应用 盲目点击权限提示框上的“是” 换句话说:这几乎不可能影响到普通用户,只有极其粗心的开发者才可能中招。而且,这只有在Play商店本身无法有效阻止恶意软件时才成立——但我不一直以为,他们之所以几乎全面禁止第三方应用商店和侧载,恰恰是因为其出色的应用扫描机制吗??? 这所谓的“为了安全”,和政府禁止所有加密是为了“保护儿童”或“防止恐怖主义”如出一辙:都是为了掩盖真实意图而编造的站不住脚的理由。 Android may soon restrict on-device ADB # https://news.ycombinator.com/item?id=49045435 Of course this was bound to happen, next you’re telling me people will be surprised that the 24 hour limit for side loading will turn into some indefinite time period. satvikpendem 当然这是必然发生的,接下来你又要告诉我,人们会惊讶于侧载的24小时限制会变成某个无限期的时间段。 Android may soon restrict on-device ADB # https://news.ycombinator.com/item?id=49045506 Spamming the thread will only cause Google developers to lock the issue, ignore valuable community feedback, or stop sharing public updates about this change entirely. So nothing would change (they can also lock away your “valuable community feedback” because what bothers them is the criticism itself), thus feel free to express your approval eviks 在帖子中刷屏只会导致Google开发者锁定该问题,忽视有价值的社区反馈,或者完全停止公开分享关于这一变更的进展。 所以什么都不会改变(他们也可以把你的“有价值的社区反馈”锁掉,因为他们反感的是批评本身),因此请随意表达你的赞同。 Claude Opus 5 # https://news.ycombinator.com/item?id=49046643 Why should I be amazed at something that promises to destroy my life? I genuinely don’t understand why people who have to work for their living are amazed at this. It will have a vast negative impact on your life unless you already live off of your wealth. muldvarp 为什么我要对一件承诺会毁掉我生活的东西感到惊叹?我真的不明白为什么那些必须靠工作谋生的人会对这个感到惊叹。除非你已经靠财富生活,否则它将对你的生活产生巨大的负面影响。 Hannah Fry Wins the Leelavati Prize in 2026 for Ma… # https://news.ycombinator.com/item?id=49045031 Well deserved. Her most memorable program for me was her 2018 program “Contagion” which modelled a virus outbreak among volunteers in the town of Haslemere, UK, using an app measuring Bluetooth proximity. Guess which town contained the UK’s Covid patient zero a year later! Edit: found it here https://youtu.be/yISdMLbO0Wc?is=T-Tq9LwzLgbusuoe kitd 实至名归。 她最令我难忘的节目是2018年的《传染》,该节目使用一款测量蓝牙距离的应用程序,模拟了英国黑斯尔米尔镇志愿者中的病毒爆发。 猜猜一年后英国新冠零号病人出现在哪个镇? 编辑:视频链接在此 https://youtu.be/yISdMLbO0Wc?is=T-Tq9LwzLgbusuoe DeepSeek pause fundraise after comments on compute… # https://news.ycombinator.com/item?id=49053421 Maybe: “Leaked Deepseek transcripts reveal plan to pause fundraising due to compute gap” I don’t know what “compute gap” means in this context though and it’s not clear that that’s why they plan to pause fundraising or if the title is conflating. culi 也许:“泄露的Deepseek记录显示因算力差距暂停融资计划” 不过我不知道这里的“算力差距”是什么意思,也不清楚这是他们暂停融资的原因,还是标题在混淆概念。 Zero roadkill as Amazon canopy bridges secure 15,0… # https://news.ycombinator.com/item?id=49049162 Just wanna say, Monga Bay is an incredible publication that doesn’t get enough attention. As someone who follows a lot of environmental news, they routinely cover important topics and do original journalism on stories I hear nowhere else. Their YouTube channel is full of extremely high quality videos that often get less than 2k views. I would highly recommend checking them out https://www.youtube.com/@MongabayTV/videos Here’s a few of my favorites: https://www.youtube.com/watch?v=j2rfy9HkzSs https://www.youtube.com/watch?v=3ZEkt4Ph41M https://www.youtube.com/watch?v=ynXNzOUI7Xw https://www.youtube.com/watch?v=RMeui4P6urY culi 就想说一句,Mongabay是一份非常出色的刊物,却未得到应有的关注。作为一个追踪大量环境新闻的人,他们经常报道重要议题,并且做一些我从未在其他地方听过的原创报道。他们的YouTube频道充满了极其高质量的视频,但观看量往往不到两千。我强烈推荐大家去看看。 https://www.youtube.com/@MongabayTV/videos 以下是我最喜欢的几个视频: https://www.youtube.com/watch?v=j2rfy9HkzSs https://www.youtube.com/watch?v=3ZEkt4Ph41M https://www.youtube.com/watch?v=ynXNzOUI7Xw https://www.youtube.com/watch?v=RMeui4P6urY Show HN: I simulated closing the Strait of Hormuz … # https://news.ycombinator.com/item?id=49043425 An interesting fact to consider is that the US stockpile (the Strategic Petroleum Reserve) is reported as the total of sour (high sulfur) and sweet (low sulfur) crude oil. The sweet stock makes up about 1/3 of the reserve and hardly varies at all. This is because US refineries are virtually all configured for sour crude: due to a mistaken belief in the 1990s that sweet crude was running out, the industry bet the farm on sour crude refining, and if sour crude runs low, it’s extremely economical to switch. As a result, almost all the draw from the SPR is of sour crude (currently ~5 million barrels/week). However, you can’t just use up all the reserve because as levels get lower brine must be pumped into the storage chambers to retain pumping pressure, and the more brine that is pumped, the more the output quality declines. The weekly reports indicate a total in the SPR of about 300mbb, of which ~100 are sweet and 200 sour. But for the reasons above, output becomes unusable one the sour levels fall to ~140-150mbb, at which point there is almost certainly a severe diesel supply shock. At current drawdown rates, that would be sometime around October/November, right in the middle of harvest season when demand for diesel is highest. There’s more complexity to this than I want to type out in a HN comment, but not that much more. Draw your own conclusions. anigbrowl 一个值得思考的事实是:美国战略石油储备(SPR)的总量被报告为含硫原油(高硫)与低硫原油(低硫)的总和。其中低硫原油约占储备的三分之一,且几乎从未变动。这是因为美国炼油厂几乎全部配置为加工含硫原油:由于1990年代错误地认为低硫原油即将枯竭,整个行业孤注一掷地转向了含硫原油炼化,而一旦含硫原油供应紧张,切换加工原料在经济上极为划算。 因此,SPR的释放几乎全部来自含硫原油(目前约为每周500万桶)。但储备不能完全用尽,因为随着储量降低,必须向储存腔中注入盐水以维持泵送压力,而注入的盐水越多,产出油的质量就越差。 每周报告显示SPR总量约为3亿桶,其中约1亿桶为低硫原油,2亿桶为含硫原油。但基于上述原因,一旦含硫原油储量降至约1.4-1.5亿桶,产出油将无法使用,届时几乎必然会爆发严重的柴油供应危机。按当前释放速度,这大约发生在10月或11月,正值收割季节中期,柴油需求达到峰值。 这其中涉及的复杂性远非我在HN评论中能详述,但也差不太多。各位自行判断吧。