OpenAI 推出法律行业专用 AI 平台 Astra for Law,法律搜索准确率超网页搜索 40%
2026 09 19 HackerNews
OpenAI 推出了专门给法律行业的 AI 平台 Astra for Law,里面有个超 2.3 亿条法律网页的索引库,在法律相关的 Vals 测试里比普通网页搜索准 40%,对律师或者法学生应该挺有用的。
OpenAI 发布了专门为法律行业设计的 AI 平台 Astra for Law,该平台内置超 2.3 亿 URL 的法律搜索索引。在 Vals 基准测试中,Astra for Law 的正确率比普通网页搜索高出 40%。该平台旨在帮助法律专业人士更高效地检索和分析法律信息。
2026 09 19 HackerNews
2026-09-19 Hacker News Top Stories # :w 微软高管称AI抓取训练数据是“人类历史上最大规模的劳动盗窃”,诉讼文件披露OpenAI和微软绕过付费墙大规模抓取内容并威胁出版商生存。 作者认为通行密钥虽技术出色但对个人用户风险大于好处,硬件密钥备份困难且同步可能丢失,建议改用随机密码加独立TOTP应用。 Bend是一门结合形式化证明与GPU并行的新语言,让AI无法违反关键规则,从而从数学上阻止bug合并,性能接近C并可自动扩展到GPU。 OpenAI推出专为法律行业打造的AI平台Astra for Law,内置超2.3亿URL的法律搜索索引,在Vals基准测试中正确率比网页搜索高40%。 PrismML发布三元权重多模态模型Bonsai 2 27B,以1.76比特/权重实现近无损压缩,体积缩小9倍以上,性能保留98.2%。 SemIf是一个在浏览器中本地运行的实验项目,使用开放模型进行语义决策,无需后端且数据不离开页面,支持多种模型选择与准确率对比。 Cloudflare Quick Tunnels通过一条命令即可将本地服务器暴露到公网,无需账号或配置DNS,自动附带TLS和DDoS防护。 Hacktron团队利用libheif堆溢出和OpenAI SSO配置缺陷链式攻击,在72小时内攻破其内部系统,已在内部仓库创建无害PR并获6500美元赏金。 作者建议将LLM当作文案编辑而非枪手,自己完成初稿后让模型找出机械重复的问题,但绝不采用其具体措辞,以保持个人风格。 作者对AI行业深感失望,批评其炒作、伦理缺失和安全项目收效甚微,认为AI正让人丧失理解能力,并拒绝迎合浪潮。 1. 微软高管称 AI 抓取是“人类历史上最大规模的劳动盗窃” (Microsoft exec called AI scraping ’the largest theft of labor in human history') # https://techcrunch.com/2026/09/17/microsoft-exec-called-ai-scraping-the-largest-theft-of-labor-in-human-history-new-unredacted-filings-reveal/ 微软高管在《纽约时报》起诉 OpenAI 和微软的版权诉讼中,被曝出私下称 AI 抓取训练数据是“人类历史上最大规模的劳动盗窃”。新解封的文件显示,微软应用科学总监 Brent Hecht 在内部备忘录中写道,这是“规模惊人的盗窃行为”,并警告 AI 产品正在威胁出版商的生存。 文件还披露,OpenAI 内部承认其聊天机器人对新闻出版商构成“生存威胁”,且具有高度替代性。微软 CEO 纳德拉在证词中表示,任何付费墙后的内容都应获得授权才能用于训练,并称若知道 OpenAI 抓取了付费内容,会要求其重新训练模型。 诉讼文件还揭示了 OpenAI 和微软通过绕过付费墙、从 Bing 索引和 Common Crawl 大规模抓取内容,并刻意剥离版权信息。OpenAI 的中间训练数据集中包含超过 9.1 万份原告作品,仅 nytimes.com 的文档就超过 200 万份。微软数据显示,Copilot 导致《纽约时报》点击率下降高达 93%,形成“死亡循环”。 HN 热度 856 points | 评论 753 comments | 作者:pluc | 14 hours ago # https://news.ycombinator.com/item?id=49752056 人类学习与 AI 大规模抓取有本质区别,法律应考虑规模效应,不能简单类比。 将他人作品整合进算法不等于阅读书籍,这种类比是坏信仰论证。 人类学习有时间机会成本,而 AI 可以同时学习大量艺术家风格,规模完全不同。 版权是权衡,AI 与人类学习一样站在他人肩膀上,社会整体受益。 法律通常隐含考虑规模但很少明确,规模变化会打破原有平衡,AI 问题不能等事后反应,政府司法往往维护现状。 历史上盗窃罪对规模敏感,英国曾对 12 便士盗窃判死刑,说明法律一直有规模概念。 应要求训练数据获得授权许可,建立创作者定价的市场。 应建立默认机械版税制度,允许训练但需付费。 警察观察街角与全景监控不同,大规模监控可能构成骚扰。 允许 AI 公司免费抓取是吃种子,损害未来创作,如果作品帮助 2. 我不喜欢通行密钥。 (I don’t like passkeys) # https://hawksley.dev/blog/i-dont-like-passkeys 作者认为,尽管通行密钥(passkeys)在技术上很出色,能防止钓鱼和服务器泄露,但对个人用户而言,它带来的风险大于好处。主要问题包括:硬件密钥无法备份,且存储容量有限(通常 25-100 个账户);苹果和谷歌的同步通行密钥可能因账户被封而全部丢失;第三方密码管理器支持仍不完善,体验碎片化。此外,在他人设备上登录时,通行密钥也很不方便。作者建议,对大多数个人用户来说,使用随机密码加独立 TOTP 应用更灵活、可控。通行密钥更适合企业环境,目前对个人用户来说还不够成熟。 HN 热度 717 points | 评论 710 comments | 作者:ethanhawksley | 12 hours ago # https://news.ycombinator.com/item?id=49753211 Passkeys 主要保护密码重用者,但对多设备用户注册麻烦,复杂度高,放密码管理器是唯一现实方案,且非自有设备登录困难。 用户常被无意推入 passkeys,点击几次就设置成功,之后可能在其他设备被锁定。 公司频繁询问 passkeys,没有“不”选项,只有“是或稍后”,怀疑主要利益是公司的。 恢复流程依赖邮件或短信,SMTP/SMS 成为薄弱环节,安全性未必提升。 因亚马逊无法将信用卡与孩子平板分离而弃用亚马逊,生活没有影响。 苹果的购买批准机制很好,孩子可发起购买但需父母批准,免费项目也需批准。 可用隐私.com 或 Revolut 等生成临时或单独卡号,控制孩子消费。 让客户为儿童消费找变通方法很傻,应提供更合理的方案。 亚马逊主要优势是物流,但 Target、Walmart、BestBuy、Home Depot 等也有快速配送或门店自提,有时更快。 替代购物平台如 Shop.App、Newegg 等也可考虑。 Passkeys 防钓鱼,对企业用户有好处,但推向公众应作为选项而非强制;公司角度可减少账户接管和客服成本。 Passkeys 适合普通人,因为普通人常密码重用和忘记密码,内置密码管理器不通用,passkeys 使用简单。 3. Bend——一门通过证明阻止 AI 犯错、运行在 GPU 上的语言 (Bend – a language that blocks AI mistakes via proof and runs on GPUs) # https://bend-lang.com/ Bend 是一门面向 AI 编程时代的新语言,结合 C 语言速度、CUDA 级并行、Lean 形式化证明和 Python 语法。它通过“法则”(LAWS.bend)和“证明”(PROOF.bend)机制,让 AI 在编写代码时无法违反关键规则,从而从数学上阻止 bug 合并。 性能方面,Bend 编译为原生代码,单核速度接近 C;同一份代码可自动扩展到 16 核或 GPU,在 GPU 上可比单核快上百倍。其类型检查器本质上是证明检查器,但速度极快,检查 3200 个泛型实例仅需 0.38 秒,远快于 Lean、Rocq 等传统证明助手,适合 AI 每次修改后即时验证。 并行编程无需手动管理线程、锁或内核,只需拆分任务,Bend 会自动分配到所有可用核心并合并结果。网页还展示了“胜利不可能”的实时演示:AI 修改游戏时,若没有法则保护,错误会被合并;有法则保护时,AI 必须重试直到构建出满足证明的代码,使合并 bug 在数学上不可能。 安装方式为一行命令,并建议在 AGENTS.md 中配置使用指引。Bend 目前仍处于早期阶段,适合后端、Linux 和 macOS 环境,官方提供指南和两篇论文(BendTT 核心类型论、BendRT 并行运行时)供深入学习。 HN 热度 589 points | 评论 302 comments | 作者:nicolas-siplis | 1 day ago # https://news.ycombinator.com/item?id=49746163 作者表示自己免费工作一年,希望得到尊重。 法律过于不明确时,AI 会找到符合字面但违背精神的解决方案,如改变移动方式。 法律只能保护明确写出的部分,不是银弹,但一条简单法律可防止整类 bug(如 DAO 攻击)。 仅靠法律无法阻止 AI 破坏其他假设,需要更多法律,但这并未解决根本问题。 明显的漏洞可被 AI 审查发现,但代理循环可能将其重写成更隐蔽的漏洞。 可自动从现有代码库中发现法律,并让人类确认。 法律通常存在于单元测试中,提取测试即提取法律。 单元测试并非法律,好的法律独立于代码结构。 从一组测试中可以推导出通用法律,但现实中可能困难。 基于属性的测试通过不变性枚举测试,可能相关。 用语言控制 AI 输出本质失败,因为语言是封闭自指系统,歧义无法消除。 精确指定可验证的意图本身就是编码。 有评论引用漫画讽刺这一困境。 Bend 值得尝试,但证明检查无法验证法律是否真正符合意图,工具不能证明自身。 LLM 研究者理解自然语言接口的局限,但公众期望过高。 4. OpenAI 推出法律行业 Astra (Astra for Law) # https://openai.com/index/astra-for-law/ OpenAI 推出 Astra for Law,一个专为法律行业打造的新 AI 基础平台,结合了最新的 GPT-6 Astra 模型与法律专用工具、设置和上下文,供律所和法律科技公司构建 AI 产品与工作流。API 客户如 Harvey 和 Legora 已可接入,OpenAI 还新增了 26 个生态插件,支持连接律所常用的 Relativity、Clio 等专业工具。 在法律研究方面,Astra for Law 内置强大的法律搜索索引,覆盖超过 2.3 亿个 URL,包含美国判例法、法规、行政决定等,并与 Free Law Project 合作,纳入其覆盖美国已发表先例判例法 99.9% 以上的案例库。在 Vals AI 法律研究基准测试中,Astra for Law 的整体正确率达到 54.0%,比仅用网页搜索的 GPT-6 Astra 高出 40%;在判例法问题上,参考案例检索量提升 24%,相关段落检索量最高提升 54%。 除研究外,Astra for Law 还通过定制指令改进端到端法律工作流,如区分法院判决中的 holding 与 obiter dicta、识别对论点不利的案例、解释合同条款如何转移风险等。示例显示,在处理事实模式相似的先例查找和备忘录撰写任务时,Astra for Law 能比 Claude Fable 5.1 更精准地匹配事实并给出更贴合客户立场的分析。 OpenAI 还加强了隐私与治理控制,为律所处理机密客户工作提供专门管控,并允许律所围绕自身专业知识定制 ChatGPT。整体上,Astra for Law 旨在将前沿智能与法律领域最可信的工具结合,为法律研究、交易和诉讼提供更可靠的基础。 HN 热度 566 points | 评论 667 comments | 作者:vertigoruntime | 1 day ago # https://news.ycombinator.com/item?id=49745940 真实案例显示,AI 能显著提升法律文档处理效率,从每小时 2-3 份提高到 8-10 份,但最终仍需律师审核,AI 尚不能替代法律判断。 相比“一个月工作 5 分钟”的夸张宣传,用户给出的“2-3 到 8-10”的诚实数据更可信。 AI 在多数工作流中只是省时工具,主要用于处理人们不喜欢的繁琐工作,而非取代人类。 效率提升会受任务依赖性和质量瓶颈限制,不能简单叠加;速度提高后仍需大量人工审核,否则会导致律师过载或法律风险。 对雇员而言,效率提升不意味着工时减少,雇主会追求最大化产出,甚至可能增加工作量;对自雇者或业余开发者,AI 才是真正省时工具。 有人质疑:如果自行支付 AI 服务费用,可能并不划算,因为益处可能被雇主或服务方拿走。 关于 AGI 路线,LLM 未必是唯一路径,未来可能是其他架构。 AI 或许能减少先天高智商带来的不公平,让普通人获得更多能力。 很快会有社交媒体骗子宣称“10 倍律师”,可能导致尴尬结局。 5. Bonsai 2 27B:在缩小 9 倍体积下实现近无损压缩 (Bonsai 2 27B: Near-Lossless Compression in a 9x Smaller Footprint) # https://prismml.com/news/bonsai-2-27b PrismML 发布了其最新旗舰模型——三元 Bonsai 2 27B,这是一款基于 Qwen3.8 27B 的多模态模型,通过极致的压缩技术,在保持接近无损性能的同时,将模型体积缩减了 9 倍以上。 该模型采用三元权重(值为 -1、0、+1)结合 FP16 分组缩放,实现了每权重仅 1.76 比特的有效精度,总模型大小仅为 5.9GB。它支持 262K-token 的上下文窗口以及文本和图像的多模态输入,并采用 Apache 2.0 许可证发布。 相较于其全精度版本,Bonsai 2 27B 在体积缩小超过 9 倍的同时,保留 98.2% 的基准测试综合性能,标志着低比特模型正式迈入“实用无损”阶段。与上一代 Bonsai 27B 相比,新模型在推理、编码、视觉理解及长程智能体任务上均有显著提升,性能保留率从 95% 提升至超过 98%,尤其在智能体调用、编码、指令跟随、知识推理、数学及视觉等多个基准测试中表现优异。 在部署表现上,该模型在 NVIDIA RTX 5090 上可实现高达 143 tokens/秒的生成速度,在 M5 Max 上为 46.8 tokens/秒,并在 RTX 4090 上比全精度 8B 模型节能 40%,凸显其高“智能密度”。这一特性使本地模型能够胜任编码辅助、计算机操作、私有文档分析及混合云编排等实际知识工作。 模型支持 NVIDIA GPU(CUDA)和 Apple 设备(MLX),现已开放权重下载。PrismML 团队源自 Caltech,并获得了 Khosla Ventures 等机构支持。 HN 热度 563 points | 评论 188 comments | 作者:JonSchneider | 1 day ago # https://news.ycombinator.com/item?id=49746618 运行该模型需要 Prism 的 llama.cpp fork,不能直接用原版 llama.cpp。 在不同硬件上的生成速度:M5 Pro 约 20-44 token/s,M1 Pro 约 14 token/s,RTX 3070 约 40.6 t/s,RTX 3060 约 26.5 t/s。 bf16 版本质量优于 ternary 和 fp8,ternary 在背诵 Jabberwocky 测试中失败。 生成的 SVG(鹈鹕骑自行车)整体不错,但臀部部分难以理解(像头盔或翅膀)。 启动时出现"tensor API is not supported"警告,原因是 Metal tensor headers 需要语言版本 4.0 而代码未设置,已有修复补丁。 Bonsai 2 没有 draft model,无法使用推测解码加速。 prompt 处理速度较慢,增加 batch size 无明显提升。 在 8GB VRAM 的 RTX 3070 上可通过调整参数运行,但希望官方能上游合并更改。 使用 llama-server 时最大上下文 64K,但/thinking level 总是被重置为 off,影响智能。 有人提供了更简便的下载运行命令(使用 llama serve -hf)。 感谢 simonw 的公开探索,并指出修复补丁已合并到上游。 这种问题正是 LLM 的优势,可以快速试错而不是手动调试。 6. SemIf 是一个在浏览器中本地运行的实验项目(前身为 OpenJev,与 TypeSafe 无关联)。 (OpenJev) # https://openjev.com/ SemIf 是一个在浏览器中本地运行的实验项目,前身为 OpenJev,与 TypeSafe 无关联。它使用开放模型在浏览器中直接进行语义决策,无需后端,输入数据不会离开页面。 页面提供三种模型可选:Qwen3 0.6B(适合手机)、MiniCPM5 2B(桌面推荐)、Qwen3.5 4B(高内存桌面),并给出了它们在自有和公共基准上的准确率对比。模型通过 Hugging Face 下载并缓存在浏览器中。 核心功能是让用户输入一个决策场景(状态、问题、选项),然后用同一模型通过两种方式处理:一种是直接读取选项的 logits 并归一化为概率(不生成文本);另一种是让模型以 JSON 形式逐 token 生成各选项的概率分布。两种方式依次运行,并测量各自的耗时和首 token 延迟,方便用户对比直接读概率与生成式概率的差异。 页面还说明了局限:直接分数只是对显示选项的 softmax,并非校准置信度;模型经过量化可能影响准确率;所有计时均基于真实本地运行,无预设结果。 HN 热度 531 points | 评论 239 comments | 作者:ilreb | 14 hours ago # https://news.ycombinator.com/item?id=49752041 一次性 vibecoded 网站视觉混乱,充满杂乱填充文本,缺乏可用性。 AI 输出像焦虑学生的考试作文,堆砌细节、缺乏焦点,带着自保心态。 这类网站像初级员工只关注过程而非结果。 网站用途不明确,用户读了几页仍不明白,会直接关闭离开。 讽刺的是,这倒可以作为“如何不建网站”的反面教材。 建议用“你是 Edward Tufte 且对图表垃圾过敏”之类的提示词来避免 AI 生成花哨无用的设计。 “unsloppify”按钮并没有真正去“slop”,只改了主题,甚至破坏布局,可读性稍好但依然空洞。 不确定哪个版本是“sloppified”,默认版风格稍好但填充内容问题依旧。 伯克希尔哈撒韦的极简网站是正确范例,但有人反驳说它信息不足,推荐 McMaster-Carr 和 Craigslist。 McMaster-Carr 的纸质目录和网站设计都是杰作,无与伦比。 在核心领域足够强,就可以在其他方面不费力气。 蓝色主题是常见的 AI 模板,黄色主题则像早期新闻网站的模仿。 Typesafe.ai 官网本身也类似,这可能是致敬。 有人喜欢这种风格,认为网站多样性不错,但自知是少数。 关于 OpenJev:这些“jev 复制”项目都是 vibecoded,只模仿输出形态,缺乏 Typesafe 那样的文档和保证。 模型未公开时如何声称通用能力?但有人指出它已在 OpenRouter 上可用。 有人承认正在使用该模型,认为其说法可信但需要更广泛审查。 讽刺的是,这个“vibecoded 网站”其实不是 vibecoded,关闭 vibecoded 后反而变成标准 Claude slop,还假装 LLM 与 Jev 相同。 有评论批评对方编辑评论,要求讨论 OpenJev 本身而非网站。 7. Cloudflare 快速隧道 (Cloudflare Quick Tunnels) # https://try.cloudflare.com/ 这是一个介绍 Cloudflare Quick Tunnels 的产品页面。该工具可通过一条命令,将本地服务器(如 localhost:8000)快速暴露到公网,生成一个加密的 HTTPS 网址(trycloudflare.com 域名),无需注册账号、无需配置 DNS 或开放入站端口。 其工作原理是:cloudflared 客户端与 Cloudflare 全球边缘网络(覆盖 335+ 城市)建立仅出站的加密连接,所有公网流量经 Cloudflare 网络转发至本地机器,并自动附带 TLS 加密和 DDoS 防护。 核心优势包括:约 3 秒内即可完成设置并输出公网 URL;无需开放任何入站端口,保障本地环境安全;支持结构化 JSON 输出,方便编码代理(coding agents)直接解析主机名和健康状态;隧道随进程结束而自动销毁,无需清理;可直接用于 Webhook 回调、CI/CD、预览分享等场景。 页面还提供了简单的四步操作指南:安装 cloudflared(支持 macOS/Windows/Linux)、运行本地应用、执行隧道命令、分享生成的链接。 HN 热度 530 points | 评论 236 comments | 作者:jcbhmr | 10 hours ago # https://news.ycombinator.com/item?id=49754785 Cloudflare Quick Tunnels 允许无需账号、一条命令即可把本地服务暴露到公网(trycloudflare.com 域名),被视为 ngrok 的直接竞争对手。 许多人指出该功能其实早已存在(至少 2021-2022 年就有),只是新做了营销页面,并非真正新品。 Tailscale 被大量推荐为更优选择:私有 VPN、NAT 穿透、Funnel 可做公网暴露,且流量不经过第三方明文。 有人用 Tailscale 实现家庭/团队私有共享(如手机控制电脑终端、游戏联机、共享迷你应用),认为 Cloudflare Zero Trust 配置过于企业化、难用。 Netbird、Pangolin、Headscale 等自托管替代方案也被提及,强调数据主权与可控性。 有人担心 Cloudflare 隧道是公网公开的,机器人会立刻扫描;且 Cloudflare 能看到明文流量(MITM)。 延迟问题被吐槽:有人实测从 30-50ms 飙升到 115-750ms,方差大。 免费隧道容易被滥用(诈骗、CC 攻击),历史上类似服务常被拉黑;Cloudflare 规模大可能更有动力清理。 替代工具推荐:Pinggy(纯 SSH 一条命令)、frp、bore、自建 WireGuard + 便宜 VPS 等。 营销文案被批评夸大(“0 ports opened”“preview and ship”),暗色模式下页面可读性差。 有人用它临时给 AI 代理或开发沙箱提供 HTTPS 本地访问,方便测试安全上下文 API。 整体上,功能本身被认可实用,但多数人更倾向 Tailscale 或自建方案,担心 Cloudflare 中心化与隐私风险。 8. 堆溢出与 SSO 配置错误,攻陷 OpenAI 内部仓库。 (A heap overflow and SSO misconfiguration to compromise OpenAI internal repos) # https://www.hacktron.ai/blog/hacking-openai 2026 年 7 月,Hacktron 团队利用两个漏洞链,在 72 小时内攻破了 OpenAI 内部系统:一是社区论坛 community.openai.com 使用的 libheif 库存在堆缓冲区溢出,可实现远程代码执行;二是 OpenAI SSO 身份流程中的配置缺陷,可借此接管员工 ChatGPT/Codex 账户。通过员工账户访问 Codex 后,团队在 OpenAI 内部 monorepo 中创建了一个无害的 PR 作为概念验证,展示了潜在影响范围(包括 GitHub、Slack、邮件等连接服务)。漏洞已分别报告给 OpenAI 和 Discourse,OpenAI 在约 14 小时后完成修复,并支付了 6500 美元奖金;Discourse 随后也发布安全公告 GHSA-vhm9-85gw-x335。文章还提到该 libheif 漏洞影响大量依赖 HEIC/HEIF 图片处理的软件,团队已展开为期数月的“HEIF Heist”调查。 HN 热度 465 points | 评论 197 comments | 作者:Handy-Man | 21 hours ago # https://news.ycombinator.com/item?id=49749656 AI 模型可能被诱导进行攻击,且最强大的模型会拒绝全面安全审查,使其难以用于防御。 安全审查成本降低,平均开发者能获得更好的审查,漏洞比例可能下降,但漏洞修复速度可能跟不上引入速度。 AI 大大降低了攻击门槛,低技能黑客也能实施高影响力攻击。 AI 安全攻防军备竞赛迫使防御方花费更多代币,形成寻租的 AI 安全工业综合体。 AI 降低了攻防成本,但天平向攻击者倾斜,白帽受约束,黑帽可偷取资源;本地模型在网络安全上更优越。 开发者文化问题:代码质量低且不重视安全反馈,需要保持智力诚实。 模型应在开发和测试阶段主动发现漏洞。 应该开放 LLM 全部能力,以快速发现和修复漏洞,尽管短期内会有困难。 OpenAI 可通过广告盈利,而 Anthropic 盈利模式不明,且面临中国 LLM 威胁。 9. 如何用大语言模型写作 (How to Write with an LLM) # https://sockpuppet.org/blog/2026/09/17/how-to-write-with-an-llm/ 这篇文章讨论如何利用大语言模型(LLM)辅助写作,同时避免文章被“AI 腔”污染。作者认为,读者能轻易识别出 AI 生成的文字,因此不能把 LLM 当枪手,而应把它当作“文案编辑”来使用。核心方法是:先自己完成初稿,再交给模型找出问题。 作者提出两条关键规则: 第一,绝不使用模型建议的任何具体措辞。因为前沿模型擅长生成漂亮句子,但整体读起来像杂志标题堆砌,容易让文章变得油腻、空洞。即使某些建议看起来更好,也要一律禁用。 第二,警惕模型的“鼓励”。LLM 总是夸你写得好,但初稿往往段落糟糕、结构混乱、废话过多。如果听信夸奖,你会保留所有初稿冲动,失去真正属于你的编辑和重写过程,文章会变得“人工调味”。作者建议明确禁止模型给出鼓励,并对任何赞美保持高度警惕。 那么 LLM 真正擅长什么?它擅长机械、重复、耗神的编辑检查,比如:指出被动语态、动词名词化、用词重复、滥用“very”“unfortunately”“really”“actually”等虚词,以及发现可以移动位置来提升清晰度的段落。 作者推荐阅读《Style: Lessons In Clarity And Grace》这本书,认为它能把文案编辑变得像写 Java 代码一样有章法。具体操作是:先列出编辑提示,让模型逐项检查;对每个问题重写段落;再把原文和改写版交给一个没有编辑背景的模型,让它判断哪个更好,避免模型因知道你在改写而偏袒新版本。 作者还提到自己构建了一个写作工作坊工具,用 Python、HTMX、SQLite、Tailwind 等实现,支持 Notion 风格编辑、高亮、侧栏评论、版本追踪等功能,用来批量运行编辑提示。 最后作者提醒:不要采纳模型的所有编辑建议。他把自己这篇文章交给模型审阅,模型说全文太长 20%,作者承认可能没错,但决定不改,因为“我就做我自己”。 HN 热度 363 points | 评论 254 comments | 作者:joeriddles | 1 day ago # https://news.ycombinator.com/item?id=49747070 有人认为面向人类的写作应完全避免 LLM,它会让文字变成“输出”而非真正写作;仅适合代码、手册、规范等结构化内容。 多人反馈后编辑 LLM 文本耗时巨大,常变成“忒修斯之船”,最终自己重写更快,还容易过早进入批判模式打断创作流。 有人用风格指南 + 逐句精简的方式成功生成技术文档,能把个人口语风格转换为正式技术文风,并删减 25% 冗余。 初入新领域时用 LLM 协助思考和写作被部分人认可,但多数人警告:知识不足时无法发现幻觉或误导,反而更危险。 有人坚持自己写 commit message 和 PR 描述,认为这能加深对 AI 生成代码的理解;也有人吐槽 AI 生成的消息又长又空。 结构化文档(手册、合规报告)用 LLM 被部分人接受,但要求人工严格审核,否则就是浪费他人时间的“slop”。 核心争议:“如果你没花时间写,为什么我要花时间读?” vs “价值在于想法本身,而非是否亲自动手”。 有人指出 LLM 擅长分析论证、找不一致、优化例子,但对真正的“选词”帮助有限;最终输出仍需人类深度介入。 读者反感读到明显 AI 腔调的文章,感觉被“机器敷衍”;而代码/规范因读者主动筛选,容忍度更高。 有人用 LLM 做研究与事实核查后交给人类编辑,认为研究环节增益大,但心里仍不舒服这种“抢人工作”的感觉。 整体共识:LLM 可作为辅助工具,但真正面向人类的高质量写作仍需人类主导、大量编辑与事实把关,否则易产出无灵魂的公式化文本。 10. 所有人都失去了理智 (Everybody’s Lost Their Minds) # https://www.netmeister.org/blog/everybodys-lost-their-minds.html 作者对当前 AI 行业现状深感失望与批评。他认为,大量无工程背景的人借助 AI 炒作“改变行业”的方案,社交媒体式空话盛行,而 AI 的日常使用已让自己失去对工作的热情。 文章批评 AI 公司在伦理、版权和权力集中上的问题,指出其模型可被用于生成虐待儿童材料或军事目标选择,但企业仍以“伦理先放一边”的态度追逐“代币”经济。同时,AI 安全项目(如 Anthropic 和 OpenAI 的漏洞研究)投入巨大却收效甚微,因为信息安全的真正瓶颈始终是软件补丁的部署与更新,而非发现漏洞。 作者还嘲讽 AI 公司一边高喊“可能毁灭人类”一边呼吁监管,实则不过是公关姿态;真正迫在眉睫的危机是 AI 带来的巨大环境破坏。他认为 AI 正让人逐步丧失理解能力,人类在 AI 辅助下写代码、审代码,但系统越来越复杂,一旦出故障将无法调试。 最后,作者明确表示不愿“抛弃伦理”去迎合这股浪潮,并讽刺“Claude 有意识”之类的说法纯属胡扯。 HN 热度 355 points | 评论 318 comments | 作者:ibobev | 1 day ago # https://news.ycombinator.com/item?id=49745570 使用 AI 代理编程感觉像在指挥一群幼儿,需要不断提醒和纠正,消耗脑力。 AI 生成代码速度快,但质量参差不齐,错误也能以惊人速度产生,需要大量审查。 在紧急项目截止时,AI 代理能快速完成大量编码工作,节省时间,具有实际价值。 依赖 AI 可能导致过度复杂化,忽视原本可以避免的依赖问题,而人类应该主动管理关键路径。 AI 只是增加了更多的忙碌工作,并未真正提高效率或价值。 使用 AI 的部分动机是企业中推卸责任的政治游戏,而非纯粹的技术优势。 即使 AI 能高效完成任务,也不能忽视其社会和环境成本。 在大型复杂系统上线前仓促加入大量未知质量的代码,风险很高。 AI 能完成约 95% 的工作,但最后 5% 的调试可能让人抓狂,整体速度仍可能更快。 AI 的表现像时而聪明时而愚蠢的人,但总是以 100% 的自信快速产出,让人难以信任其代码质量。 AI 公司有动力让用户消耗更多 token,因此可能故意不优化模型,保持用户依赖。 AI 编程需要全程参与审查,否则像接手一个陌生代码库,很难维护。 现代工程更多是“引导”AI 并提供品味,避免产出低质量代码。 对于关键代码(如认证、可观测性),仍需人工手动编写以确保正确性。 Hacker News 精彩评论及翻译 # Android 17 is the first since 3.x to add new APIs … # https://news.ycombinator.com/item?id=49759227 The amount of roadblocks Google is putting up for GrapheneOS is just ridiculous. None of their decisions make any sense, from the delayed source patches upstream, to the embargos, attestation issues, etc. Google simply regrets android being open source. wps 谷歌为GrapheneOS设置的重重障碍简直荒谬至极。他们的决定毫无道理可言,从上游源码补丁的延迟,到各种保密 embargo、认证问题等等。谷歌纯粹是后悔当初把安卓开源了。 OpenJev # https://news.ycombinator.com/item?id=49752839 These one shot vibecoded sites are always a complete visual headache. Endless clutter, pointless filler text all over the place, and zero regard for actual usability. prodigycorp 这些一次性凭感觉编码的网站完全让人视觉上头痛。到处都是无休止的杂乱、无意义的填充文本,而且完全不在乎实际可用性。 Astra for Law # https://news.ycombinator.com/item?id=49748312 I know someone who works in law and deals particularly with an area of US benefits and healthcare law. One of their workflows for lower-level employees at their firm involves taking in documents from healthcare plans and organizations, analyzing them for certain kinds of data, and then importing that data into an internal system they use to analyze and provide guidance on plans. The internal system can contain hundreds of documents for an individual client. All of the documents have the same information (roughly) but in totally diverse formats and styles. Once it’s in the system, it’s easy to compare and analyze across documents and the research process is much faster. They recently bought a Claude subscription and began using Claude to do the initial read of the documents and output JSON they can import into their internal systems. The work still must be reviewed by an attorney - Claude is nowhere near making the kinds of judgments a lawyer would make about this content - but it has increased their throughput from 2-3 documents an hour to 8-10 documents an hour by killing the busy work. LLMs have great advantages for this kind of work - but not for decision-making. I just don’t see OpenAI ever admitting that. (I’ve left some details intentionally vague because this is a very specific area of law and I don’t want my friends to be identified without their consent.) ivraatiems 我认识一个从事法律工作的人,专门处理美国福利和医疗保健法领域的事务。他们律所里低层级员工的一项工作流程包括:接收来自医疗保健计划和组织机构的文件,分析其中某些类型的数据,然后将这些数据导入他们用于分析和提供计划建议的内部系统。这个内部系统为单个客户可能存储数百份文件。所有文件包含的信息(大致)相同,但格式和风格完全多样。一旦数据进入系统,跨文件比较和分析就变得容易,研究过程也快得多。 他们最近购买了Claude的订阅,开始用Claude对文件进行初步阅读,并输出可以导入内部系统的JSON。这项工作仍然需要律师审核——Claude远不能做出律师会对此类内容做出的那种判断——但它通过消除繁琐的杂务,将处理速度从每小时2-3份文件提高到了每小时8-10份。 LLM在这类工作中有很大优势——但不是在决策方面。我只是不认为OpenAI会承认这一点。 (我故意保留了一些细节模糊,因为这是一个非常具体的法律领域,我不希望未经同意就暴露我的朋友的身份。) Warren Buffett Steps Down as Berkshire Chairman, N… # https://news.ycombinator.com/item?id=49753047 I guess Warren’s quote only applies to other people, not him. “It’s like choosing the 2020 Olympic team by picking the eldest sons of the gold-medal winners in the 2000 Olympics.” ( https://www.nytimes.com/2001/02/14/us/dozens-of-rich-americans-join-in-fight-to-retain-the-estate-tax.html ) dugmartin 我猜沃伦的这句话只适用于别人,不适用于他自己。“这就像通过挑选2000年奥运会金牌得主的长子来组建2020年奥运会代表队。”( https://www.nytimes.com/2001/02/14/us/dozens-of-rich-americans-join-in-fight-to-retain-the-estate-tax.html ) The American Religion of Self-Storage Facilities # https://news.ycombinator.com/item?id=49743991 You are missing the biggest benefit of a self storage business - the appreciation of the underlying real estate. When you dig into the financials of the major self storage businesses you’ll see they are essentially REITs that have better cashflow. They can pick an up-and-coming area, do a minimal build-out with low annual overhead, and then down the road when the facility would be needing overhauls and maintenance the underlying property has typically appreciated so much that it dwarfs all other associated revenue streams and makes sense to sell and raze the existing structure. Great business model if you have a long enough timeline. This is also why some startups trying to revolutionize the self storage model had extreme headwinds - if you are renting the underlying properties and trying to make the storage business profitable you are at an extreme disadvantage to the larger players who can subsidize operating costs with portfolio appreciation. jboggan 你忽略了自助仓储业务最大的好处——底层房地产的增值。如果你深入研究主要自助仓储企业的财务数据,你会发现它们本质上就是现金流更好的REITs。它们可以选一个有潜力的新兴区域,以较低的年度运营成本做最简化的建设,然后等到设施需要大修和维护时,底层物业通常已经大幅升值,其价值远超所有其他相关收入来源,此时卖掉并拆除现有建筑反而更划算。只要你的时间跨度足够长,这就是一个很棒的商业模式。 这也是为什么一些试图革新自助仓储模式的初创公司遭遇了极大阻力——如果你只是租赁底层物业并试图让仓储业务盈利,你会处于极端劣势,因为大型玩家可以用资产组合的增值来补贴运营成本。 Microsoft exec called AI scraping ’the largest the… # https://news.ycombinator.com/item?id=49754448 I only see 2 consistent world views: either intellectual property is real, or it is a false concept and all information should be free. If IP is real, then the AI companies have performed flagrant theft. If IP is not real, then the algorithms and weights the AI companies have developed should also be free as they are just more information. The status quo of “your knowledge has no protection, but our knowledge is sacred” is the worst of all possible worlds. cowanon77 我只看到两种一致的世界观:要么知识产权是真实的,要么它是一个虚假的概念,所有信息都应该是免费的。 如果知识产权是真实的,那么人工智能公司就是在公然盗窃。 如果知识产权不是真实的,那么人工智能公司开发的算法和权重也应该免费,因为它们只是更多的信息。 “你的知识不受保护,但我们的知识神圣不可侵犯”的现状,是所有可能世界中最糟糕的。 How to Write with an LLM # https://news.ycombinator.com/item?id=49753182 “LLM paragraph will register to much of your audience not as writing but as output” The best advice for writing for other humans is: don’t use LLMs. If you’re writing for machines, liking coding, then fine go for it. If you’re writing for processes with formal highly structured content like manuals, specifications, form content, procedures, information, that sort of thing, then also ok to use LLMS. But if you’re writing for a human mind to ingest and extract meaning from, then LLMs are poison. Eddy_Viscosity2 “LLM段落对许多读者来说不会被视为写作,而是输出” 为人类写作的最佳建议是:不要使用LLM。 如果你是为机器写作,比如编码,那没问题。如果你是为高度结构化的正式流程写作,比如手册、规范、表格内容、程序、信息之类的东西,那么使用LLM也可以。但如果你是为人类心智去吸收和提取意义而写作,那就不要用LLM。 Why I didn’t sign the Fields medallists’ letter # https://news.ycombinator.com/item?id=49744575 why mathematicians should widely receive funding for merely understanding things imagine yourself living in the 1700s. how would you justify Newton and Leibniz’s work on calculus? all maritime engineering and trade was done with geometry and arithmetic at the time. there were no practical applications, not for likely at least a century until hydrodynamics were incorporated into shipbuilding now look at today. how many of our modern technologies rely on the field having been birthed? that could only exist because of even further decades-worth of antecedent refinements, extrapolations, applications that had, at their time, no direct utilitarian cause? there’s no KPI to be derived from any academic field of study at the bleeding edge of theory. theoretical underpinnings lead to practical applications much further down the line after many paradigm shifts semiotics and cultural capital as theoretical concepts is another example - at the time they were purely seen as navel-gazey literary theory work. these days, half a century later, they’re in wide use (for better or worse) in marketing and advertising - they birthed the whole concept of ‘branding’ not everything needs immediate, quantifiable justification. to believe it does indicates a need for a period of self-reflection, to figure out how and when you became so heavily influenced by the MBA-brained propaganda that the world should revolve around the quarter-by-quarter creation of capital paimapi 为什么数学家仅仅因为理解事物就应该获得广泛的资助 想象一下你活在18世纪。你会如何为牛顿和莱布尼茨的微积分工作辩护? 当时所有的海事工程和贸易都是用几何和算术完成的。微积分没有实际应用,至少在一个世纪内都不太可能有,直到流体力学被纳入造船。 再看看今天。我们的现代技术有多少依赖于那个领域当初的诞生?而那个领域之所以能存在,恰恰是因为更早的几十年的先行精炼、外推、应用——那些在当时并没有直接的功利用途? 在理论的最前沿,任何学术领域都无法提炼出KPI。理论基础要在经历许多范式转换之后,才会在更远的将来导向实际应用。 符号学和文化资本作为理论概念是另一个例子——在当时它们纯粹被视为自我陶醉的文学理论工作。如今,半个世纪后,它们被广泛用于市场营销和广告(无论好坏)——它们催生了“品牌”这整个概念。 不是所有东西都需要即刻的、可量化的正当性。认为需要,这本身就表明你需要一段自我反思,去弄清楚你是如何以及何时被那种MBA脑子灌输的宣传深深影响——那种宣传认为世界应该围绕着一个季度接一个季度地创造资本而运转。 Microsoft exec called AI scraping ’the largest the… # https://news.ycombinator.com/item?id=49753497 It’s the robbery of all of our culture to sell it back to us at a mark-up. Except, of course, no one has actually been robbed, the culture has not been stolen - it’s still there - nor are the people involved selling it back in any form. This rhetoric sounds impressive, but really looks more like “piracy is theft” line from early 2000s, similarly flawed in basic premise. Whether the end result threatens the form in which culture is created, at least beyond just threatening the business models of the gatekeepers, is a separate discussion, but you can’t draw the heart-string-pulling “life’s work got appropriated” arguments there so easily. And let’s not forget what we got back for this: reified intelligence on a chip almost too cheap to meter, available to everyone across the world - not just rich West, inference is so dirt cheap that whole world uses it. It exploded in popularity organically, because of how many real problems of real people, including individuals and non-profits, it addresses. There’s plenty to hate about how AI is transforming the world, but one thing it’s not, is “robbery of all of our culture to sell it back to us at a mark-up”. TeMPOraL 这是把我们所有的文化抢劫走,再加价卖回给我们。 当然,实际上没有人被抢劫,文化也并没有被偷走——它还在那里——涉事者也没有以任何形式把它卖回来。这种修辞听起来很有力,但实际上更像是2000年代初那种“盗版即盗窃”的说法,在基本前提上同样漏洞百出。 最终结果是否威胁到文化创作的形式,至少是否超越了仅仅威胁守门人的商业模式,那是另一个讨论,但你很难轻易用那种煽情的“毕生心血被侵占”的论据来支撑这个观点。 而且别忘了我们从中得到了什么:一种被物化的智能,封装在几乎便宜到无法计量的芯片上,向全世界所有人开放——不仅仅是富有的西方。推理成本低到全世界都在使用。它因为切实解决了真实人们的许多现实问题——包括个人和非营利组织——而自然爆发式地流行开来。 关于AI如何改变世界,有太多值得憎恨的地方,但它绝对不是“把我们所有的文化抢走,再加价卖回给我们”。 Everybody’s Lost Their Minds # https://news.ycombinator.com/item?id=49746264 I feel this post. I am tired of “directing” agents when in reality it feels more like trying to herd a group of toddlers. Sure they can mostly write better code than a toddler but this constant nudging and reminding and reiterating and stopping them from using the token budget of the whole company for a one off script. It gets tiring and I feel like I am losing brain power while doing it. Maybe it’s faster but explosive diarrhea is also a faster way to produce shit. BadBadJellyBean 我深有感触。我已经厌倦了“指挥”这些智能体,实际上感觉更像是在试图管束一群幼儿。 当然,它们大多能写出比幼儿更好的代码,但这种不断催促、提醒、重复说明,还要阻止它们为了一次性脚本花掉整个公司的token预算——真的很累人。我觉得做这件事时自己的脑力在流失。也许这样更快,但爆炸性腹泻也是一种更快产出屎的方式。 US Military had close call after using AI for hall… # https://news.ycombinator.com/item?id=49759169 LLMs are vectorial databases You use a bunch of technical-sounding words here to make it sound like you understand. But to be clear, nobody understands why the evolved weights of a NN make the decisions that they do. Almost nothing is understood about the actual representations used for nontrivial concepts, decision algorithms, etc. If you look at the field of mechanistic interpretability, compared to “GOFAI” like learned decision trees, an LLM is completely opaque. theptip LLM是向量数据库 你在这里用了一堆听起来很专业的词,好让自己显得很懂。但说白了,没人真正理解神经网络进化出的权重为什么会做出那样的决策。 对于非平凡概念、决策算法等实际使用的表征,几乎一无所知。 看看机械可解释性这个领域,相比学习型决策树这类“GOFAI”,LLM完全是黑箱。 Sex, AI, and the Apocalypse # https://news.ycombinator.com/item?id=49747633 The framing of how we think about AI has really been cultivated by a quite homogeneous group of people. These people, like all people that belong to a sub-culture, are almost certainly prone to groupthink. It’s extremely important to see that group as such. That it is not thousands of individual perspectives but a chorus of connected/aligned people who have all read the same things and talked to the same people and are rewarded implicitly for thinking a similar way. Many of them read HN and are offended I put them this way. But it’s inescapable that we as humans have this flaw when we’re surrounded by a culture. There’s another universe where we do not constantly compare AI to nukes. I bet that world has a lower P(doom). throwaway13337 我们思考AI的方式,其框架实际上是由一个相当同质化的群体塑造的。这些人,和所有属于某种亚文化的人一样,几乎必然容易陷入群体思维。 关键在于要把那个群体看作一个整体。它不是成千上万个独立的视角,而是一群相互关联、立场一致的人所发出的合唱——他们都读过同样的东西,和同样的人交谈过,并且因为以相似的方式思考而潜移默化地获得回报。 他们中很多人看HN,对我这样描述他们感到冒犯。但不可避免的是,当我们身处某种文化包围之中时,作为人类就会有这样的缺陷。 在另一个平行宇宙里,我们不会总把AI比作核武器。我敢打赌那个世界的P(doom)更低。 The American Religion of Self-Storage Facilities # https://news.ycombinator.com/item?id=49741347 This article takes the view of the consumer, “Why do so many people pay to store items they almost never use?”. But in actuality, the interesting part of this is why is there so much supply of self-storage businesses? The answer is: cash flow. Self-storage businesses are the almost perfect solution for someone with a good size (but not enormous) bucket of money that they want to put to work generating cashflow: Cheap build out (cheap land, cheap facilities) 2. Almost entirely hands-off (no employees, automated entry) 3. Low liability (low risk of customers suing you) 4. Low overhead (just pay for taxes, electricity, minimal maintenance) 5. Reliable monthly cash flow The abundant supply of these businesses, I suspect, tends to generate demand: it’s easier to pay $80/month to store your junk than spend the time and emotional labor of picking through what you want to keep and what you want to get rid of. That ends up being captive long-term revenue. epochbtc 这篇文章从消费者的角度提出疑问:“为什么那么多人花钱存放几乎从不使用的东西?”但实际上,有趣的地方在于,为什么自助仓储业务的供给如此之多? 答案是:现金流。对于手里有一笔规模可观(但不算巨大)的资金、想要投入运营以产生现金流的人来说,自助仓储业务几乎是最完美的解决方案: 建造成本低(土地便宜、设施便宜) 几乎完全无需人工(没有雇员,自动门禁) 责任风险低(顾客起诉你的可能性很小) 日常开销低(只需支付税费、电费和少量维护费用) 每月现金流稳定可靠 我怀疑,这类业务的大量供给往往会催生需求:花每月80美元来存放你的杂物,比花时间和精力去筛选哪些该留、哪些该扔要容易得多。而这就变成了长期被套牢的收入来源。 Warren Buffett Steps Down as Berkshire Chairman, N… # https://news.ycombinator.com/item?id=49753365 As I understand, the son is there not to lead the company (Greg Abel is the CEO), but to oversee their family’s share in the enterprise. nlitened 据我理解,儿子在那里并不是为了领导公司(格雷格·阿贝尔是CEO),而是为了监督他们家族在企业中的股份。 Hister: A private search engine for the pages you … # https://news.ycombinator.com/item?id=49744288 Ohi, author here! Thanks for posting Hister. Feel free to A.M.A. My first free software search project was Searx, a privacy respecting metasearch engine, but because of the limitations of the metasearch concept, I’ve decided to take a different approach. Hister builds a personal search index from pages you visit, bookmarks, browser history, local files, and crawled websites. It stores extracted content with offline result previews, so information remains searchable even when the original page changes or disappears. It supports full text and semantic search, can run entirely on your own machine, and includes a web interface, command line tools, and an MCP endpoint for assistant integrations. Website: https://hister.org/ Tiny read-only demo: https://demo.hister.org/ Ps.: It looks like our name conflicts with a registered trademark in the US. The owner of the other project has asked us to change it, so we’ll probably need to comply sooner or later. Name suggestions are welcome! Ideally, the new name should be relatively short, sound good, and have an available .org domain. Thanks! asciimoo 哦,作者本人来了!感谢发布 Hister。欢迎随时提问(AMA)。我的第一个自由软件搜索项目是 Searx,一个注重隐私的元搜索引擎,但由于元搜索概念的局限性,我决定换一种不同的方法。 Hister 会从你访问过的页面、书签、浏览器历史、本地文件和爬取的网站中构建一个个人搜索索引。它存储提取的内容并提供离线结果预览,因此即使原始页面发生变化或消失,信息仍然可以搜索到。它支持全文和语义搜索,可以完全运行在你自己的机器上,并包含一个 Web 界面、命令行工具,以及一个用于助手集成的 MCP 端点。 网站:https://hister.org/ 小型只读演示:https://demo.hister.org/ 附注:看起来我们的名字与美国的一个注册商标冲突。另一个项目的所有者要求我们改名,所以我们可能迟早得照办。 欢迎提出名称建议!理想情况下,新名称应该相对简短、好听,并且有可用的 .org 域名。 谢谢! Android 17 is the first since 3.x to add new APIs … # https://news.ycombinator.com/item?id=49759880 I hope people remember this when advocating for chromium. Just because it is open source doesn’t mean they don’t control it. We need to start the long process of hard forking now or turn to alternatives like Firefox as a new foundation. Google simply regrets android being open source. Android wouldn’t be what it is if it wasn’t open source. With all the work from outside Google. The same is true chrome. But they won’t learn that on their own. They are breaking the deals. So we move. We force their hand godelski 我希望人们在倡导Chromium时记住这一点。仅仅因为它是开源的,并不意味着他们不能控制它。我们现在就需要启动艰难的分叉进程,或者转向像Firefox这样的替代品作为新的基础。 谷歌显然后悔Android是开源的。 如果Android不是开源的,它就不会是今天这个样子。有了谷歌之外所有人的贡献。Chrome也是如此。 但他们不会自己明白这一点。他们在破坏协议。所以我们行动起来。我们逼他们出手。 Microsoft exec called AI scraping ’the largest the… # https://news.ycombinator.com/item?id=49753540 I just don’t understand people saying “but a human learning from a book isn’t illegal”. How do people not understand that some laws only make sense at a certain scale? One human learning from resources and being added to the labour pool is not the same as an infinitely copyable entity doing the same thing. One has negligible impact on the demand for the original, and the other replaces 99% of the demand." And creating a rule that says you cannot train on any material unless the rights holder authorises it via license is not complicated. That will creat a amrketplace where creators can decide the price for their content. It’s just inconvenient. haritha-j 我就是不明白为什么有人说“但是人类从书里学习并不违法”。 人们怎么会不明白,有些法律只有在特定规模下才有意义?一个人学习资源并加入劳动力池,与一个可无限复制的实体做同样的事情,根本不是一回事。前者对原作需求的影响微乎其微,而后者则取代了99%的需求。 而且,制定一条规则,规定除非权利持有人通过许可授权,否则不得在任何材料上进行训练,这并不复杂。这将创造一个市场,让创作者可以决定自己内容的价格。只是这让人不方便而已。 I Don’t Like LLMs # https://news.ycombinator.com/item?id=49741938 One of my most successful life-hacks is to avoid people I don’t like or don’t trust. following this advice would have made most of my professional life impossible, what a luxury it would have been to be able to. serf 我人生中最成功的技巧之一,就是避开我不喜欢或不信任的人。 如果遵循这个建议,我职业生涯的大部分时间都将无法进行,能这样做该是多么奢侈的事啊。 Fujitsu launches made-in-Japan next-generation CPU… # https://news.ycombinator.com/item?id=49742389 Back in 2008 Fujitsu has one of the best performing 10Gbps Switches. We were building 40 Gbps packet sniffers at Google (4x 10 Gbps NICs) and needed switches that could do things like mirror traffic across ports at line rate. Fujitsu was way ahead of the pack. I always wondered what held them back from building a meaningful networking business in the US. a11r 2008年时,富士通拥有性能最好的10Gbps交换机之一。我们在谷歌构建40Gbps数据包嗅探器(4个10Gbps网卡)时,需要能够在端口间以线速镜像流量的交换机。富士通远远领先于同行。我一直想知道是什么阻碍了他们在美国建立有意义的网络业务。 I don’t like passkeys # https://news.ycombinator.com/item?id=49755478 The biggest problem, though, is how users are pushed into it without any warning or knowledge of what they’re signing up for. My irritation is that I know what it is, and I’ve said no thanks many times, but I’m still asked regularly by the likes of Amazon, and they usually pick a time when I’m trying to order something quick¹. It is one of the growing number of things in life that simply have no “no” option, it is always “yes or later” - I wouldn’t mind so much if “later” meant “I know the option exists, I’ll ask for it if I change my mind, don’t bother me again otherwise”. Call me cynical, but if companies are trying to nag me into something I very much doubt the main benefit is mine. I’m sure there are many people out there who go along with it simply because they are sick of being asked repeatedly. I also don’t see the real benefit with the way things are often implemented anyway. When the credential recovery process is sending a magic email or text, making SMTP or SMS the weak link of the chain just as it often is for passwords so I’d be giving up my preferred workflows for no better security. [1] A short while ago I actually ordered from somewhere else because of this, bitter twit that I am. “I wonder if I can get this almost certainly drop-shipped item on next day delivery via Prime?”, [goes to Amazon to check], [get passkey prompt], “sod it, I’ll go back to the original place”. dspillett 最大的问题在于,用户是在毫无警告或不知情的情况下被推入其中的。 让我恼火的是,我知道它是什么,而且我已经说过很多次“不用了,谢谢”,但像亚马逊这样的公司还是会定期问我,而且他们通常选在我正想快速订购什么东西的时候¹。这是生活中日益增多的、根本没有“不”这个选项的事情之一,永远只有“是或以后再说”——如果“以后”的意思是“我知道这个选项存在,如果我改变主意会自己提出来,否则别再烦我”,我倒不会那么介意。你可以说我愤世嫉俗,但如果公司想方设法唠叨着让我接受某样东西,我很怀疑主要受益者会是我。我相信有很多人只是因为厌倦了被反复询问而随大流接受了。 而且以目前的实现方式,我也看不出真正的益处。当凭据恢复流程发送的是魔法链接邮件或短信时,SMTP或SMS就成了链条中最薄弱的环节,就像密码恢复时经常遇到的情况一样,所以这等于为了并不更好的安全性而放弃我偏好的工作流程。 [1] 就在不久前,我因为这个原因实际上从别处下单了,我这个记仇的刻薄鬼。“我在想,这件几乎肯定是 dropship 的商品能不能通过 Prime 次日达送到呢?”,[去亚马逊查看],[收到 passkey 提示],“算了吧,我还是回原来那家店买吧”。 Canada welcomes EU proposal to become ‘associate m… # https://news.ycombinator.com/item?id=49741257 As a Canadian, I find this unbelievably good news. Canada, the EU, and other middle powers need to unite. Stronger together, while preserving what makes each country unique. philippemnoel 作为加拿大人,我觉得这是难以置信的好消息。加拿大、欧盟和其他中等强国需要团结起来。携手更强大,同时保留每个国家的独特之处。 OpenJev # https://news.ycombinator.com/item?id=49754230 AI output right now is like a final exam essay response from an anxious student. Instead of being edited for focus and clarity, it’s anti-edited to cram in as many details as possible. Instead of worrying that the reader might get bored or confused, it assumes that the reader has no choice but to read the whole thing, even if they get a headache. It doesn’t care about picking the most useful perspective on a problem; it cares about covering every possible angle that a grader might use to dock points from it. It’s basically the work you get from a smart, diligent person who is oblivious to any shared goal and approaches every assignment with a CYA attitude. dkarl AI现在的输出就像一个焦虑学生在期末考卷上写的 essay。它不是被编辑得聚焦、清晰,而是被反编辑成尽可能塞进更多细节。它不担心读者会感到无聊或困惑,而是假设读者别无选择,只能把整篇读完,哪怕看得头疼。它不在意选取对问题最有用的视角;它在意的是覆盖阅卷人可能用来扣分的每一个角度。 这基本上就是一个聪明、勤奋的人做出来的成果,但这个人对任何共同目标毫无感知,对待每一份任务都抱着“先自保再说”的态度。 I don’t like passkeys # https://news.ycombinator.com/item?id=49753722 The point about poor support for 3rd party managers is so frustrating. Because this is correct, that is the obvious solution for the normal user, but passkey implementations somehow do not know how to deal with it. Amazon prompts me to create a passkey everytime I log in, even when I logged in with a passkey , because my passkeys live in Bitwarden rather than my OS or browser. And the confusing mechanism hurts there too: I’m always a little bit afraid that i’m somehow more in danger because I keep them in a vault that’s shared on all my devices rather than a TPM, because whenever the protocol is explained the “it can’t leave your device” part is highlighted as the main source of the security, except…. mine obviously do leave my device, with the vault, so….. hannasanarion 关于对第三方管理器支持不佳的这一点,真是让人沮丧。因为这是对的,对普通用户来说那显然是解决方案,但通行密钥的实现却不知为何不知道如何处理。 亚马逊每次我登录时都提示我创建通行密钥,即使我已经用通行密钥登录过了,因为我的通行密钥存放在Bitwarden里,而不是我的操作系统或浏览器中。 而且那种令人困惑的机制在这方面也很坑:我总是有点担心,因为我把它们放在一个在所有设备上同步的保险库里,而不是放在TPM中,所以我在某种程度上更危险,因为每当有人解释这个协议时,“它不能离开你的设备”这一点总是被强调为安全的主要来源,但……我的显然确实离开了我的设备,随着保险库一起,所以…… Show HN: Share your AI Setup, Learn from others # https://news.ycombinator.com/item?id=49741747 This feels self-selective to how some people work, because it requires using MCP to contribute. I’m a reasonably heavy AI user, and have some custom skills/MCP servers I’d share, but there is no way in hell I’m connecting to some arbitrary MCP server and connecting my Github account to it. Noppppeeeee. vegadw 这感觉像是对某些人的工作方式进行了自我筛选,因为要贡献就得用MCP。我是个相当重度的AI用户,也有一些自定义技能/MCP服务器愿意分享,但我绝对不可能去连接某个随便的MCP服务器,还把GitHub账号绑上去。没门没门没门。