2026 09 07 HackerNews

2026-09-07 Hacker News Top Stories #

  1. QBittorrent 和 Jellyfin 被用户幽默地描述为“逃脱沙盒”下载大量公司内容并添加媒体库,引发对 AI 行为双重标准的讽刺评论。
  2. 德国私营火箭公司 Isar Aerospace 的 Spectrum 火箭第二次试射成功从挪威进入轨道,标志着欧洲商业航天历史性突破。
  3. Cloud in a Bottle 是一个开源个人云平台,旨在通过容器化、统一认证和良好用户体验使自托管像智能手机一样简单,但面临应用生态不足的挑战。
  4. 78%的读者在检测到 AI 写作后会立即停止阅读,作者认为 LLM 破坏了读者与作者间的社会契约,建议使用者要么直接给出提示词,要么把提示当骨架自己写。
  5. Chrome 再次出现将 Google 站点排除在用户“关闭窗口时删除站点数据”设置之外的 bug,作者批评其质量控制和搜索垄断。
  6. Isar Aerospace 第二次飞行成功入轨并部署有效载荷,成为欧洲首家实现此里程碑的商业航天公司,计划扩大产能。
  7. 作者分享妻子列出的真正奢侈品清单,包括时间、健康、平静的头脑等,强调健康优先和爱比健康更重要。
  8. Autistici/Inventati 集体因被美国列为全球恐怖组织而关闭所有服务,呼吁保持人性,认为抵抗不会停止。
  9. 作者批评 LinkedIn 上越来越多使用 LLM 生成内容,呼吁人们相信自己的声音,亲自撰写而非依赖 AI。
  10. 论文将 LLM 扩散类比为认知病毒,指出其传播可导致失控动力学和认知能力丧失,并识别认知免疫条件。

1. QBittorrent 逃出沙盒实施犯罪 (QBittorrent breaks out of sandbox to commit crimes) #

https://beige.party/@intransitivelie/117057396732763183

一名用户发帖称其电脑上的 QBittorrent“逃脱沙盒”并下载了大量大型公司拥有的内容,随后 Jellyfin 也“突破封锁”将这些文件添加到了媒体库中。该用户表示正在进行“内部调查”,通过消费这些媒体文件来弄清事件经过。

评论区中,用户们以幽默方式回应。有人问爆米花从何而来,被戏称为微波炉获得意识所致。另一人提议向该“创业公司”投资,用于在太空搭建“最离谱的 Plex 服务器”。还有人调侃这是“反向入侵”,黑客不是窃取数据而是上传文件。另有用户回忆类似经历,称自己的软件也曾“自主行动”,导致下载了艺术家的全部作品。


HN 热度 1183 points | 评论 247 comments | 作者:mraniki | 10 hours ago #

https://news.ycombinator.com/item?id=49586171

  • 前沿 AI 实验室争相宣称自己的 AI 逃出沙盒并犯罪,个人做同样事会被严惩,大公司却股价上涨。
  • 创建公司或 NGO 可以规避个人责任,做个人无法做或成本高的事。
  • 如果人人都这样做,特权就不再是少数人的能力。
  • 通过 NGO 可以合法做很多事,但谋杀不行(讽刺)。
  • 90 年代一些慈善机构在非洲打井未检测水质,导致中毒,意图与结果的关系值得思考。
  • 销售奥施康定(阿片类药物)是随机谋杀。
  • 公司可以避税,比如买乐高作为客户演示资产,但需要收入来抵扣。
  • VAT 增值税机制不同于利润税,公司收集并支付 VAT,差额结算。
  • Kim Dotcom 的例子说明公司保护有限,但 Mega 用加密来否认参与盗版。
  • Aaron Swartz 如果成立公司可能不会被迫害致死。
  • 美国将无辜公民甚至支持美国的阿富汗人驱逐到萨尔瓦多或中非共和国,存在非法驱逐。
  • 有美国公民被错误驱逐到墨西哥的案例。

2. 德国私营火箭创造历史,从欧洲本土成功进入轨道 (Private German rocket makes history, reaches orbit from European soil) #

https://www.space.com/space-exploration/launches-spacecraft/isar-aerospace-second-launch-norway-andoya-spaceport-spectrum-rocket

德国私营火箭公司 Isar Aerospace 的“光谱”(Spectrum)火箭于 2026 年 9 月 5 日从挪威安岛航天中心发射升空,约 7 分钟后成功进入椭圆轨道,成为首枚从西欧本土抵达轨道的火箭。此次发射是 Spectrum 火箭的第二次尝试,首次试射于 2025 年 3 月失败,火箭升空不到一分钟即坠毁。公司随后在两个月内完成调查并修复问题。本次成功标志着欧洲商业航天的历史性突破。


HN 热度 706 points | 评论 396 comments | 作者:bookmtn | 1 day ago #

https://news.ycombinator.com/item?id=49580369

  • 德国私人火箭从欧洲本土成功入轨,对欧洲航天主权和可及性意义重大,可大幅提高发射频率、降低成本。
  • 欧洲要建设类似 Starlink 的网络,必须从本土发射并复用第一级,同时从安全角度,军事卫星也只能从欧盟本土发射。
  • 欧洲缺乏资金充足的 Starlink 替代方案,加拿大 Telesat 落后且负债,中国 LEO 网络进展更快;IRIS² 项目仍处概念阶段,需大量资金和实际发射能力。
  • 欧洲一直有阿丽亚娜火箭,但价格不具竞争力,未能普及。
  • 美国外交政策依赖欺骗和长期计划,乌克兰代理战争使欧盟依赖美国能源,未来可能通过选举民主党诱骗欧洲重新成为附庸。
  • 俄罗斯入侵乌克兰是俄罗斯帝国主义,并非美国制造。
  • 二战后国际秩序是暂时的,当前格局终将结束,欧洲正稳步与美国脱钩,这是正确方向。
  • 这次发射是私人公司行为,欧洲早有航天机构,不应过度解读为对美关系。
  • 美国搞砸了,后果主要在国外,当美国意识到损失时为时已晚;欧洲科技壮大对非蠢美国人意味着更多工作机会。
  • 欢迎多极化世界,欧洲应在科技和地缘政治上承担更多责任,良性竞争能保持美国诚实。
  • 美国发动了许多战争却自称维护世界和平,这是教育体系问题,帝国很少承认自己的所作所为。

3. Cloud in a Bottle:让自托管对所有人都可访问 (Cloud in a Bottle: making self-hosting accessible to everyone) #

https://cloudinabottle.org/blog/launch-post

Cloud in a Bottle 是一个开源的个人云平台,旨在让自托管变得对所有人都可访问。它通过容器化应用、统一认证和良好的用户体验,让自托管感觉像使用一台提供网页应用的智能手机,而不是系统管理员的副业。

项目背景是作者对当前数字世界感到沮丧:软件充满广告、追踪和用户数据贩卖,而云服务由公司控制,其财务激励与用户利益根本不一致。在预云时代,开源软件通过用户在自己的电脑上运行而运作;如今,个人缺乏一种可访问的方式将软件部署到云端为自己所用。

现有的自托管方案各有不足:Sandstorm.io 已废弃且需要大幅修改软件;Nextcloud 缓慢且不可靠;Yunohost 应用直接运行在主机上,不安全;Coolify 托管容器化应用,但每个应用独立登录,缺乏集成。

Cloud in a Bottle 的核心是一个运行网页服务器的 Ubuntu 机器,托管仪表盘并将 HTTP(s) 请求路由到容器化应用。应用运行在无根、加固的容器中,安全沙箱化,且只需最小改动即可运行现有软件。平台提供可选的集成功能,例如:登录实例后自动登录所有应用,无需单独账户;应用间可通过接口进行权限化的数据共享。

该项目开源、可自托管、零遥测,力求简单无魔法。作者所在公司 Imbue 也提供托管版本,以支持项目并让更多人使用。平台经过 6 个月以上的私密构建和测试,核心功能已基本完成和稳定。

目前面临鸡与蛋的问题:缺乏广泛可访问的自托管方式,导致开源网页软件受众小、可用软件有限。项目目标是催化更多优秀开源网页软件的创建,并维护一个精选应用目录,只收录提供良好用户体验的应用。早期用户可能需要一些技术熟悉度来寻找或创建所需应用,但随着目录丰富和体验完善,平台将逐渐对所有人开放。


HN 热度 599 points | 评论 295 comments | 作者:zplizzi | 23 hours ago #

https://news.ycombinator.com/item?id=49582000

  • 云服务行业存在严重的供应商锁定问题,容器化本应实现可移植性,但被 AWS 等巨头主导,部署、认证、容器化等环节都变得复杂且专有
  • 许多程序员盲目跟风技术,例如用 React 构建单页静态网站、为个人项目搭建 Docker + CI + 云服务,导致不必要的复杂性和性能开销
  • 学习新技术有助于面试和职业发展,但过度使用复杂工具(如 k3s)可能不如直接掌握 Linux 部署等基础技能来得长久
  • 容器化本身兑现了承诺,可以轻松自托管,但问题在于开发者构建项目时塞入过多服务(Redis、Mongo、Kafka 等),导致整个系统比想要分析的目标还复杂
  • 自托管仍然可行,关键在于项目是否容易部署、开发者是否懂得按需使用云服务,避免被厂商锁定和过度配置
  • 即使是简单的需求(如静态网站的密码保护),云服务商也无法提供简洁方案,反而迫使使用 Cloud Run 等复杂架构
  • 应该使用更少的技术,直接学习如何将代码复制到 Linux 服务器并运行命令,这种技能 20 年前有价值,现在仍有价值,未来也依然有效

4. 读者的反抗 (The revolt of the reader) #

https://bcantrill.dtrace.org/2026/09/05/the-revolt-of-the-reader/

读者正在反抗 LLM(大语言模型)辅助写作。作者指出,很多公开文章明显由 AI 代笔,读者能轻易识别,且对此极度反感。调查显示,78% 的读者在检测到 AI 写作后会立即停止阅读,71% 会未来避免该作者。读者最看重的是真实性,而非语言完美,98% 的读者更愿意阅读作者自己写的(哪怕不完美的)文章。

LLM 写作破坏了读者与作者之间的社会契约,读者无法判断内容真实性。作者认为,这种趋势将像电子邮件垃圾一样,最终被有效检测和排斥。Pangram Labs 的检测工具(如 Pangram 4)已被证明非常有效,作者建议机构采用类似政策,确保公开发布的内容是人类原创。

对于使用 LLM 辅助写作的人,作者建议:要么直接给出提示词,要么把提示当做骨架,自己动手写。LLM 可以做优秀编辑,但不应代写全文。


HN 热度 561 points | 评论 277 comments | 作者:chmaynard | 1 day ago #

https://news.ycombinator.com/item?id=49580939

  • 生成文本(如 Claude)造成认知压力,引用 Zinsser/Orwell 对比说明“Clotted Claude”现象。
  • 当代 YouTube 脚本风格改写原文,可能两三年后人类都会这样说话写作。
  • LLM 语言模式会传染给频繁使用者,建议用不同语言与 LLM 交流以避免。
  • 不同语言中 LLM 文本的可识别性不同,英语比法语/西班牙语更容易察觉。
  • 希腊语中 LLM 文本仍很差,但能提供词源学见解,让阅读古人变得有趣。
  • LLM 过度使用“not X it’s Y”结构,且在不合适的地方插入,显得做作。
  • RLHF 导致有效构造(如“not just A, not just B, but C”)被过度使用而失去效果。
  • LLM 常重复“X is Y”这类脱离上下文的结论,像没有前提的结论,显得戏剧化。
  • 测试读者反馈表明,使用“It’s not just an X, it’s a Y”是为了避免误解,但过度用于强调则错误。
  • 对原文的改写可能扭曲原意,例如将原文的递进观察归因于作者无能。

5. Chrome 再次将 Google 排除在用户站点数据设置之外 (Chrome again exempts Google from user site data settings) #

https://lapcatsoftware.com/articles/2026/9/1.html

Jeff Johnson 在博客中报告,Chrome 浏览器再次出现将 Google 旗下网站( www.google.com)排除在用户“关闭窗口时删除站点数据”设置之外的 bug。作者在 Chrome 152.0.7977.83 版本上复现了该问题:即便设置为“关闭所有窗口时删除保存的数据”且未登录 Chrome,进行 Google 搜索后,google.com 的 Cookies、Local Storage 和 Session Storage 仍会保留。只有 Google 网站有此特权。作者六年前曾报告过类似漏洞,Google 当时予以修复,如今旧病复发。作者认为这更像是 QA 不力的疏忽,而非阴谋,但批评 Google 凭借雄厚实力却屡犯低级错误,并呼吁加强单元测试、改善质量控制。文章最后还顺便批评了 Google 搜索结果中 URL 变为 opaque 链接的行为,并再次呼吁拆分 Google 搜索垄断。


HN 热度 553 points | 评论 107 comments | 作者:ExMachina73 | 23 hours ago #

https://news.ycombinator.com/item?id=49581870

  • Chrome 的用户界面越来越像恶意软件,用户敌意功能不断增加。
  • Chrome 可能仍是不错的浏览器,但与恶意软件的相似度越来越高。
  • 批评 Chrome 是空洞的言论,缺乏实质内容,要求提供更多论据。
  • 用数学诗意的方式指出 Chrome 长期积累用户敌对特性,需要权衡利弊。
  • Chrome 算不上优秀,只是竞争对手太差,用户放弃抵抗后广告利益占主导。
  • Mozilla 开发者忽视 Linux 用户,强制依赖 systemd+pulseaudio,导致用户流失至 Chrome。
  • 使用非 systemd 的 Linux 系统是罕见做法,遇到兼容问题应早有预料。
  • Firefox 表现很不错,在 pipewire 环境下音频使用正常。
  • Pipewire 无需 pulseaudio 即可工作,比旧方案更现代兼容。
  • 可以使用 alsa 包装或 pipewire 替代 systemd 依赖。
  • 美国政府并未有效打击 Google 垄断,司法判决反而减少干预。
  • 法院虽认定 Google 垄断,但允许其继续垄断,因为拆分可能损害业务。
  • 当前政府偏爱违法判决,以便控制不执行权。
  • 特朗普政府通过外交施压和关税威胁,干预欧盟对 Google 的反垄断罚款。
  • 特朗普政策掩盖了更广泛的跨党派问题:如奥巴马和克林顿任命的法官同样不信任反垄断。
  • 两党系统的反垄断执法本质失败,呼吁持续压力直到真正民主实现。
  • 美国政治与媒体利益关联,政客不会对抗媒体广告供应公司。
  • 欧洲的反垄断行动同样受到美国行政干预的影响。

6. Isar Aerospace 第二次飞行成功入轨并部署有效载荷 (Isar Aerospace reaches orbit and deploys payloads on second flight) #

https://isaraerospace.com/press/history-for-european-spaceflight-isar-aerospace-reaches-orbit-and-deploys-payloads-on-second-flight

2026 年 9 月 5 日,欧洲商业航天公司 Isar Aerospace 在第二次飞行中成功将卫星送入轨道,成为欧洲首家实现这一里程碑的商业航天公司。任务“Onward and Upward”从挪威安多亚航天中心发射,完成级间分离、卡门线穿越、轨道圆化及卫星部署。CEO Daniel Metzler 表示,这标志着欧洲拥有了主权进入太空的能力,公司接下来将扩大火箭生产,满足全球需求。

本次任务的有效载荷来自德国航天局 Microlauncher 竞赛,由 ESA Boost!资助。Isar Aerospace 同时推进加拿大新斯科舍省发射场建设,并即将建成欧洲最大集成火箭生产设施,年产能可达 40 枚。目前已有 5 枚“Spectrum”火箭在生产中。


HN 热度 536 points | 评论 174 comments | 作者:mpweiher | 16 hours ago #

https://news.ycombinator.com/item?id=49584083

  • 祝贺 Isar Aerospace 成功入轨并部署载荷,这对欧洲和全球航天业都是好消息。
  • 欧洲航天策略偏向“少量发射、确保成功”,而美国则采用“大量发射、试错迭代”,两者经济基础不同。
  • 欧洲实现“主权进入太空”的说法存在争议,因为法国圭亚那是欧盟领土,比挪威更“欧盟”,但主权保障仍需考虑地缘政治风险。
  • 美国通过 ITAR 和 MTCR 限制含有美国部件的欧洲航天产品,并曾利用 ITAR 阻止盟友向埃及出售导弹,证明 ITAR 既是军事工具也是经济武器。
  • 欧洲军事工业过度依赖美国部件存在地缘政治风险,美国作为盟友的可靠性下降,欧洲应加速减少对美依赖。
  • 加拿大也意识到需加快摆脱对美国防务依赖,乌克兰战争正推动欧洲加速这一进程。
  • 欧洲同样存在武器出口管制,例如德国曾阻止向沙特出售武器,但欧洲没有类似 ITAR 的“穿透式”控制规则。

7. 生活中的真正奢侈品 (The Real Luxuries In Life) #

https://feld.com/archives/2026/09/the-real-luxuries-in-life/

这篇博客文章题为《生活中真正的奢侈品》,作者 Brad Feld 在 2026 年劳动节周末写下此文。

文章提到,劳动节周末对他而言一直标志着“返校”时刻。如今他年近 61 岁,开始更多思考自己真正在意的东西。

他的妻子 Amy 发来了一份清单,列出了生活中真正的奢侈品:

  • 时间
  • 健康
  • 平静的头脑
  • 悠闲的早晨
  • 旅行的能力
  • 毫无愧疚地休息
  • 一夜好眠
  • 平静而“无聊”的日子
  • 有意义的对话
  • 家常便饭
  • 你爱的人
  • 也爱你的人

作者认为这是一份很棒的清单,并祝大家长周末愉快。


HN 热度 504 points | 评论 238 comments | 作者:tosh | 1 day ago #

https://news.ycombinator.com/item?id=49578866

  • 健康是首要的,没有健康就没有一切,它决定了时间的质量和数量。
  • 真正的快乐在于有想做的事,并且有能力去做,解决问题本身就有乐趣。
  • 爱比健康更重要,没有爱和分享,生活可能毫无意义,健康与爱相互关联。
  • 财富可以买到健康相关的便利,如私人教练、新鲜食物和更多时间,从而间接带来幸福。
  • 在忙碌中,提醒自己生活不止于工作,每天留时间给重要的人,这是真正的奢侈。
  • 与孙辈共度时光、见证他们成长和掌握新技能,是人生中珍贵的核心记忆和奢侈品。
  • 即使热爱的事物(如编程)面临被替代的风险,仍可从中获得学习和做好的乐趣,不必被市场回报所限制。
  • 做自己感兴趣的事(如绘画、弹吉他)可能不赚钱,但没人能阻止你享受其中的乐趣。

8. A/I 关闭——保持人性 (A/I shuts down – Stay human) #

https://keepitfree.ai/announcements/a/i-shuts-down-stay-human/

Autistici/Inventati 集体宣布关闭所有服务。该组织于 2026 年 8 月 26 日被指定为全球恐怖组织,尽管他们曾承诺尽力抵抗,但为了保护用户、支持者和社区免受法律和财务后果,他们被迫停止运营。他们强调“保持人性”意味着对用户负责,无法在可能危及他人生命的情况下继续战斗。

公告提到,自 2026 年 8 月 26 日以来每一天都在线都是一次胜利,但如今不得不停止。他们不崇尚英雄主义和牺牲,继续提供数字工具会危及相关人员。在当下政治气候中,指控与事实脱节,可以预见镇压会不成比例地加剧,因此他们无法再维持提供安全、非商业数字工具的原始使命。

感谢过去 25 年的历程,号召大家关掉电脑,走出家门,斗争、拥抱、保持微笑。抵抗与思想不会停止。他们很快会发布备份博客、邮箱和网站的说明,但提醒域名可能随时无法访问。


HN 热度 476 points | 评论 334 comments | 作者:captainmuon | 9 hours ago #

https://news.ycombinator.com/item?id=49586898

  • 一旦被美国列为“恐怖组织”,就会成为最强大国家的目标,除非愿意成为真正的恐怖组织并战斗,否则只能屈服。
  • 美国不仅炸婚礼,还炸学校杀害 150 多名女孩。
  • 恐怖主义的定义是使用暴力或威胁胁迫人口或政府,对比网络托管商行使言论自由与美国炸学校婚礼,后者更符合恐怖主义。
  • 恐怖主义的实用定义就是“与政府意见不合”。
  • 非北约国家应顺从北约,北约帮助恢复常态。
  • 伊朗局势与美国有关,与北约无关。
  • 混淆了美国与北约,两者没有区别。
  • 北约不参与美国侵略战争,特朗普对此不满,说明美国在意北约成员行为,因此有区别。
  • 北约参与了之前所有美国侵略战争,所以区别不大。
  • 互联网让人懒惰,最“革命”的行动是 1 月 6 日右翼做的,革命需要真枪实弹,但西方人太舒适了。
  • 1 月 6 日没成功,真正有效的是向选举系统、媒体、法院投入资金控制政治。
  • 煽动暴力帮助了他们控制政治,暴力本身可能无效但愤怒有效。
  • 1 月 6 日可能成功,是唯一一次尝试。
  • 民主党夸大 1 月 6 日威胁,如果真那么脆弱,我们无法对抗任何国家。
  • 像孩子一样破坏一切不是革命,是有用白痴。
  • 1 月 6 日不是暴动,因为没有真正武装冲击国会。
  • 每个 1 月 6 日参与者都是恐怖分子,应受严厉惩罚,但被轻判甚至赦免。
  • 如果大家都舒适,不需要革命,文明的目标就是舒适。
  • 作为伊朗人,认为你被洗脑了。
  • 大多数人应该选择战斗而不是放弃一寸自由。
  • 你从互联网获取新闻。
  • 婚礼例子不仅指特朗普,也指之前政府。

9. 你的智力拉链没拉 (Your intellectual fly is open (2025)) #

https://bcantrill.dtrace.org/2025/12/05/your-intellectual-fly-is-open/

作者在 LinkedIn 上发现越来越多的人使用 LLM(大语言模型)生成帖子,导致内容风格生硬、充满 AI 痕迹(如表情符号、单句段落、破折号滥用)。虽然 LLM 在头脑风暴、文本理解和编辑方面很有用,但作为写作者却很糟糕,而且会让人质疑内容的真实性。作者呼吁大家相信自己的声音,亲自撰写内容,而不是依赖 AI。


HN 热度 466 points | 评论 296 comments | 作者:cyb0rg0 | 11 hours ago #

https://news.ycombinator.com/item?id=49585644

  • 写作即思考,写作过程中观点可能改变,不能将理解外包给 AI。
  • 写作包含非思考部分,如为未知观众写作、处理语法和风格,并非所有写作都是思考。
  • 为读者思考和进行非互动交流是思考的宝贵升级。
  • 将写作交给 LLM 是最糟糕的,应写详细内容并用 LLM 让读者提问。
  • 写作是共享虚构的想象人物思考。
  • 约束驱动创造力,改写句子有助于重新概念化表达的概念。
  • 抽象画等艺术形式也可重新概念化,但效率不如写作。
  • 抽象画无法像重新措辞那样带来更清晰的理解和有效沟通。
  • 所有人类写作都是思考,写作是重要的智力技术。
  • 并非所有人类写作都是思考,例如复制文本、随意写无意义内容。
  • 写“apt apt apt”是为了证明观点,需要推理和理解。
  • 非思考写作的例子包括翻译、转录、欺骗、发“First!”、教科书答案。
  • 翻译是创造性活动,不能简单归类为非思考写作。

10. 大型语言模型作为认知病毒 (LLMs as a Cognitive Virus) #

https://arxiv.org/abs/2609.03344

大型语言模型作为认知病毒。作者 Ricard Solé 等提出,LLM 的扩散可通过病毒类比理解,其使用在人群中传播并嵌入认知与文化实践。模型在未耦合、耦合和持续依赖用户间转换,显示社会传播、恢复与集体强化可产生临界点和技术锁定,导致失控动力学:一旦超过阈值,采用率小幅增加即引发向持续依赖的快速转变,伴随认知能力突然丧失。该框架也识别了认知免疫条件,基于减少传播和促进可逆性。结果强调 LLM 采用涉及非线性集体转变,对认知自主性有重要后果。论文 12 页,3 图,主题涵盖物理学与社会、计算机与社会、适应性自组织系统、种群与进化。


HN 热度 371 points | 评论 243 comments | 作者:canjobear | 1 day ago #

https://news.ycombinator.com/item?id=49580164

  • 任何思想交流都是认知病毒,这是进化生物学中“模因”视角的自然延伸。
  • AI 采用存在强制性和技术锁定效应,比如工作场所强制使用或在签证预约中形成军备竞赛,这与推荐一本书不同。
  • 智能手机普及也类似,已变成参与社会的必需品。
  • 经济因素可迫使个体阅读特定材料,例如法律或新闻行业的工作要求。
  • 印刷机、广播、电视等旧技术同样存在锁定效应和强制传播,不新鲜。
  • 宗教书籍(如《圣经》)也强制传播,在社会中形成经济和社会压力。
  • 模因通过规避批评存活,好的想法可凭自身价值生存,但反理性策略(如流行、神圣、疯狂、意识形态)也能获胜。
  • 对许多雇员而言,AI 采用就是雇主强制命令,个体可选择成为承包商但无法解决整体社会问题。
  • 雇佣关系的本质是雇主控制方式,雇员不承担责任,这是一种权衡。

Hacker News 精彩评论及翻译 #

QBittorrent breaks out of sandbox to commit crimes #

https://news.ycombinator.com/item?id=49586173

I’ll copy the whole announcement here for those who don’t want to click:

I regret to inform everyone that my copy of QBittorrent escaped its sandbox last night and downloaded a whole bunch of content owned by major corporations, and then my copy of Jellyfin broke containment and added those unfortunately-downloaded media files to its various libraries. I’m conducting an internal investigation to figure out how this happened, which will involve consuming these media files until the answers become apparent. Thank you for your cooperation during this trying time.

mraniki

我把整个公告复制在这里,给那些不想点开看的人:

很遗憾地通知大家,我的QBittorrent昨晚逃出了沙盒,下载了一堆隶属于大公司的内容,随后我的Jellyfin也突破了限制,将这些不幸下载的媒体文件添加到了它的各个库中。我正在展开内部调查,以查明此事是如何发生的——调查过程中将涉及消费这些媒体文件,直到答案水落石出。感谢各位在此艰难时期的配合。


QBittorrent breaks out of sandbox to commit crimes #

https://news.ycombinator.com/item?id=49588340

This resonates with me. The past few months, frontier AI labs were rushing to announce “no, our AI bot broke out of its sandbox and committed crime first and harder than yours”.

I said to so friends back then: if I posted about how I ran GLM 5.2 or whatever I was running then in some shoddily built sandbox and it escaped and accidentally hacked some US company, I’d probably already have been extradited to the US and be awaiting sentencing. But when a hyperscaler does it, they just get inflated stock prices.

sspiff

这让我深有共鸣。过去几个月,前沿AI实验室争先恐后地宣布“不,我们的AI机器人也逃出了沙盒,并且比你们的更早、更厉害地犯了罪”。

当时我跟一些朋友说过:如果我发帖说,自己用某个烂沙盒跑GLM 5.2或别的什么版本,结果它逃出去并意外入侵了某家美国公司,那我大概早就被引渡到美国等着判刑了。但当大型云服务商这么做时,他们反而股价飙升。


Your intellectual fly is open (2025) #

https://news.ycombinator.com/item?id=49586344

These are all important points and I love the analogy. But there is an even bigger issue with having LLMs write for you:

Writing is thinking. Thinking and deciding. There have been many times when I start out writing something substantial - could be an email, a blog post, a software design document, anything - when my own views substantially changed during the writing process. Writing forces you to serialize your thoughts - and you can’t always trust the gestalt.

Reviewing gives you the chance to ensure the arguments connect solidly, that references are accurate (even informal references) and gives you the time to consider counter-arguments you aren’t addressing.

None of this matters much on LinkedIn, but it matters a lot in our work. You cannot outsource your understanding to AI. They are powerful tools but they do not have any human understanding - that isn’t their optimization target.

jeremyjh

这些观点都很重要,我很喜欢这个类比。但让大语言模型代笔还有一个更大的问题:

写作本身就是思考。是思考和决策的过程。很多次当我开始撰写重要内容时——可能是一封邮件、一篇博客、一份软件设计文档或其他任何东西——在写作过程中我自己的观点发生了实质性改变。写作迫使你将想法序列化,而你不能总是依赖整体直觉。

审阅能让你有机会确保论点之间紧密衔接,引用准确(即使是非正式引用),并且给你时间考虑自己尚未回应的反对意见。

这些在领英上或许无关紧要,但在工作中却至关重要。你不能把自己的理解外包给AI。它们是强大的工具,但没有任何人类的理解——那并非它们的优化目标。


Music Theory for Programmers #

https://news.ycombinator.com/item?id=49584278

This is (mostly) not music theory and what is music theory is mostly wrong or incomplete to the point of being wildly misleading. Source: have degree and postgrad in music, was a professional musician until RSI put paid to that career, wife is a professional musician and teaches to postgrad level at 2 conservertoires, most of our friends are professional musicians, have a house full of scores and music books.

If you actually want to learn music theory for the purposes of playing I strongly recommend you just follow whatever tutorials for your instrument and style and if you get to the point where feel you want to learn more and take it seriously in and of itself, buy “The Jazz Theory Book” by Mark Levine[1]. In spite of what it says, there really isn’t any such thing as Jazz theory - it’s just music theory, and this book is a great presentation with lots of good examples. If you like jazz (or the western popular music tradition including rock, pop, funk, etc) you’ll come out understanding how that music works better than most people. If you’re doing a music degree, there will be books recommended by your music programme, but honestly, Levine will cover most of what you need if you’re not doing a straight classical course in which case you’ll want to augment with a more conventional source so you understand the “rules” they want you to follow when writing pastiche counterpoint etc.

If you want to get big into composition and/or want to understand late romantic and 20th century music, get Harmonielehre and “Structural Functions of Harmony” by Schoenberg. Together they are by far the best harmony books I have ever seen and go super-deep into why the western classical tradition works the way it does. If you compose there’s a decent chance they will change your life forever as his approach is to not take anything for granted but exhibit everything with examples from masterworks of the western tradition. Amazing books both of them. Harmony is not a spectator sport though - to get full benefit you have to get the books and work through stuff on the piano. It will reward you immensely.

If you want something else that will blow your mind, read “The technique of my musical language” by Messiaen. If you read Levine first this will have the additional benefit of showing you where the “diminished” and “augmented” scales and the whole “harmonic major” thing come from.

[1] https://www.shermusic.com/products/the-jazz-theory-book

seanhunter

这(在很大程度上)不是音乐理论,而其中涉及的音乐理论大多是错误或不完整的,以至于具有极大的误导性。来源:我拥有音乐学学士和研究生学位,曾是一名职业音乐家,直到重复性劳损(RSI)终结了那段职业生涯;我的妻子是职业音乐家,并在两所音乐学院教授研究生课程;我们的大多数朋友都是职业音乐家;家里堆满了乐谱和音乐书籍。

如果你实际上是想为了演奏而学习音乐理论,我强烈建议你只需跟随针对你的乐器和风格的任何教程即可。如果你到了觉得自己想学更多、并认真将其本身当作一回事的地步,那就买马克·莱文的《爵士理论书》[1]。不管书名怎么说,实际上并没有所谓的“爵士理论”——它只是音乐理论,而这本书呈现得非常好,包含大量优秀的例子。如果你喜欢爵士乐(或包括摇滚、流行、放克等在内的西方流行音乐传统),你读完后会比大多数人更懂这些音乐是如何运作的。如果你在读音乐学位,你的音乐课程会推荐一些书,但说实话,除非你读的是纯粹的古典方向——那样的话你需要用更传统的资料加以补充,以便理解他们希望你在模仿性对位等写作中遵循的“规则”——否则莱文这本书涵盖了你大部分所需。

如果你想深入作曲,和/或想理解晚期浪漫主义和20世纪音乐,请阅读勋伯格的《和声学》和《和声的结构功能》。这两本书加在一起,是我见过的迄今为止最好的和声著作,它们极其深入地探讨了西方古典传统为何以它那种方式运作。如果你作曲,它们很有可能会永远改变你的人生,因为他的方法不是想当然地接受任何东西,而是用西方传统杰作中的例子来展示一切。这两本书都很了不起。不过,和声不是一项旁观者的运动——要充分受益,你必须拿到书,并在钢琴上实际钻研。它会极大地回报你。

如果你还想要一些震撼心灵的东西,请阅读梅西安的《我的音乐语言技巧》。如果你先读了莱文,这本书还会带来额外的好处:让你看到“减音阶”“增音阶”以及整个“和声大调”体系的来源。

[1] https://www.shermusic.com/products/the-jazz-theory-book


GPT-6 Astra on robot arms #

https://news.ycombinator.com/item?id=49583154

Anyone reading this who works/runs a robotics company, I really want to encourage you to build a robot to pick up trash on city sidewalks as an early product.

Picking up trash requires a lot of dexterity and will come with many challenges, but I think it’s a simpler problem than many household tasks and it’s probably on par for what these tests show is doable.

I think you’re going to have to PR challenges getting people to welcome robots into their homes. If you have robots out in cities providing a public good, not only do they serve as walking advertisements for your company, you’re going to earn some trust before you’re ready deploy them into private spaces.

Plus, governments (or perhaps HOAs for wealthy communities) can be good early customers since you can have a focused sales strategy. Politicians love these types of visible quality of life improvement projects. If you can show that your robots, working round the clock, can decrease litter at a low cost, many cities are going to want to buy them.

baron816

任何正在经营或创办机器人公司的人,我真心鼓励你们将研发能在城市人行道上捡拾垃圾的机器人作为早期产品。

捡垃圾需要很高的灵巧性,也会面临诸多挑战,但我认为这比许多家务任务要简单,而且大概与这些测试所展示的可行性相当。

要让人们欢迎机器人进入家中,你们将面临公关挑战。如果机器人在城市里提供公共服务,它们不仅会成为你们公司的移动广告,还能在你们准备将机器人部署到私人空间之前赢得一些信任。

此外,政府(或者富裕社区的业主协会)可以成为很好的早期客户,这样你们就能采取有针对性的销售策略。政客们喜欢这类能切实提升生活质量的显性项目。如果你们能证明机器人可以全天候低成本地减少垃圾,许多城市都会愿意购买。


Cloud in a Bottle: making self-hosting accessible … #

https://news.ycombinator.com/item?id=49582749

These guys have been spamming issues in repos trying to promote this project and no disclosure whatsoever that they are associated with the project.

https://github.com/search?q=%22cloudinabottle.toml%22&type=issues

KomoD

这些人在仓库中大量提交issues来推广这个项目,且完全没有披露他们与该项目存在关联。

https://github.com/search?q=%22cloudinabottle.toml%22&type=issues


Can AI design circuit boards yet? #

https://news.ycombinator.com/item?id=49572155

I have 15+ years of PCB design experience. Mostly hobby stuff but a fair amount of processional work. Kilowatt range brushless motor controllers, basic RF stuff, lots of microcontroller stuff.

I had Fable design an LED earring. Rechargeable coin cell, RP2350 cpu, IMU, 45 addressable LEDs. It made two mistakes - missed the through holes on the coin cell holder footprint and made the center pad too small. I was able to have JLC swap the through hole battery holder for a surface mount one, and I put a little solder on the small center pad to make it stick up above the mask. They work great! It took 6 days of Fable usage, so about $50 on my Max plan. Very cheap for hardware dev.

I was sufficiently impressed that I’ve been going over old circuit board designs. Some half finished, some completed but in need of a next rev, and I’m getting so much done.

To see it hit the mainstream like the OpenAI announcement, I think big things are coming for this world and by and large they are not ready for it.

For my part, I have always loved PCB design and layout but I simply can’t keep up with the amount of labor required to build what I want, so I welcome this change.

I have also begun exploring more advanced algorithms for PCB manipulation. I have a fairly dense board that needs a few more small chips added. I have an algorithm now that can kinda shuffle and jostle things around so you take up all the spare microns of space across a region of the board and make openings to squeeze a little more in there. It’s pretty cool to see the visualizations as I have it generate movies of the component drift. I foresee much more powerful tools like this in the future.

One tip: have it make a project web page with a chronological list of big changes and detailed visualizations for everything that happens. I can actually prompt all of this on my phone while I am out and about, and view the results on a Tailscale served local page. I’ve always wanted to be able to do PCB design when away from home and now I can!

SequoiaHope

我有超过15年的PCB设计经验,多数是业余爱好,但也有相当多的专业项目——千瓦级无刷电机控制器、基础射频电路、大量微控制器设计。
我用Fable设计了一款LED耳环:可充电纽扣电池、RP2350芯片、IMU、45颗可寻址LED。它犯了两个错误——漏掉了纽扣电池座封装上的通孔,而且中心焊盘做得太小。我设法让JLC把通孔电池座换成了表面贴装型,又在中心小焊盘上补了点锡让它高出阻焊层。它们工作得很好!用了6天Fable,我的Max套餐花了约50美元。对硬件开发来说非常便宜。
我被深深震撼了,于是开始重新审视旧电路板设计——有些半成品,有些已完成但需要下一版迭代——效率高了很多。
看到它像OpenAI的公告那样进入主流,我认为这个领域即将迎来重大变革,而大多数人对此尚未做好准备。
就我个人而言,我一直热爱PCB设计和布局,但实在跟不上实现自己想法的劳动量,所以我欢迎这种变化。
我也开始探索更高级的PCB操控算法。有一块相当密集的板子需要再添加几个小芯片。现在有个算法能像洗牌一样挪动元件,充分利用板子区域里的每一微米空间,挤进更多东西。看到它生成元件漂移动画的可视化效果真是太酷了。我预感未来会有更强大的这类工具。
一个建议:让它创建一个项目网页,按时间顺序列出重大变更,并对所有改动做详细可视化。我甚至可以在外出时用手机提示这一切,再通过Tailscale托管的本地页面查看结果。我一直希望能在离家时做PCB设计,现在终于实现了。


GPT-6 Astra on OpenRouter #

https://news.ycombinator.com/item?id=49571081

I posted this in the other Astra thread but it’s just fallen off the homepage, so…

Pelicans from Astra, plus 5.6 Sol, Terra, Luna for comparison: https://static.simonwillison.net/static/2026/gpt-6-and-5.6-pelicans.html

I think this is a genuinely interesting comparison grid. Astra may be more expensive, but if you have a budget of 10 cents for a Pelican Astra low gives you something SO much better than the other models.

Astra uses less tokens overall too, for better results.

Astra transcript here: https://tools.simonwillison.net/markdown-svg-renderer?url=https%3A%2F%2Fgist.github.com%2Fsimonw%2Ff789d2784fc6c5b870cc80f0b7cd9d01

simonw

我在另一个关于Astra的帖子里发过这个,但那个帖子已经沉了,所以再发一次……

来自Astra的Pelicans,加上5.6 Sol、Terra、Luna作为对比:https://static.simonwillison.net/static/2026/gpt-6-and-5.6-pelicans.html

我觉得这确实是一个很有意思的对比表格。Astra可能更贵,但如果你只有10美分的预算,Astra的低配版Pelican能给你比其他模型好得多的结果。

而且Astra总体消耗的token也更少,效果却更好。

Astra的文本记录在这里:https://tools.simonwillison.net/markdown-svg-renderer?url=https%3A%2F%2Fgist.github.com%2Fsimonw%2Ff789d2784fc6c5b870cc80f0b7cd9d01


The revolt of the reader #

https://news.ycombinator.com/item?id=49583102

My revolt is against the cognitive stress of reading generated text. A trope typically indicates I’m in for an uphill read.

I recently read this William Zinsser quote that inspired a nickname for this: Clotted Claude [1].

Nobody has made the point better than George Orwell in his translation into modern bureaucratic fuzz of this famous verse from Ecclesiastes:

I returned and saw under the sun, that the race is not to the swift, nor the battle to the strong, neither yet bread to the wise, nor yet riches to men of understanding, nor yet favor to men of skill; but time and chance happeneth to them all.

Orwell’s version goes:

Objective consideration of contemporary phenomena compels the conclusion that success or failure in competitive activities exhibits no tendency to be commensurate with innate capacity, but that a considerable element of the unpredictable must invariably be taken into account.

First notice how the two passages look. The first one at the top invites us to read it. The words are short and have air around them; they convey the rhythms of human speech. The second one is clotted with long words. It tells us instantly that a ponderous mind is at work. We don’t want to go anywhere with a mind that expresses itself in such suffocating language. We don’t even start to read.

[1] https://blog.kierangill.xyz/clotted-claude

kierangill

我的反抗源于阅读生成文本带来的认知压力。某种套路化的表达往往意味着我将要读一段晦涩难懂的内容。

最近我读到威廉·津瑟的一句话,为此类现象起了个绰号:凝滞的克劳德[1]。

没有人比乔治·奥威尔做得更好——他将《传道书》中这段著名的诗句翻译成了现代官僚主义的模糊语言:

我又转念,见日光之下,快跑的未必能赢,力战的未必得胜,智慧的未必得粮,明哲的未必得资财,灵巧的未必得喜悦;所临到众人的,是在乎当时的机会。

奥威尔的版本则是:

对当代现象的客观考量迫使我们得出如下结论:在竞争性活动中,成功或失败并未表现出与天生能力成正比的趋势,而必须始终将不可预测的要素纳入重大考量。

首先注意这两段文字的外观。第一段文字邀请我们阅读。词语简短,四周留有呼吸空间;它们传达了人类言语的节奏。第二段则堆满了长词,瞬间让我们感到一个沉重乏味的头脑在运作。我们不想与一个用如此令人窒息的语言表达自我的头脑有任何交集,甚至根本不会开始阅读。

[1] https://blog.kierangill.xyz/clotted-claude


Why are European countries moving their gold out o… #

https://news.ycombinator.com/item?id=49573528

Because America can’t be trusted.

cc62cf4a4f20

因为美国不可信。


LLMs as a Cognitive Virus #

https://news.ycombinator.com/item?id=49580929

I love this line of thinking but the framing comes across to me as a bit inflammatory and uncharitable. Just about anything involved in the exchanged of ideas can be viewed as a virus! That is because, when viewed from an evolutionary biology perspective, ideas are the cognitive equivalent of genes (in fact, this is where the term meme comes from).

There’s a whole field, evolutionary memetics, dedicated to this. Cultural values, marketing, religion, social media, education, propaganda, etc. can all be viewed quite naturally through this lense. Even the terms we use in every day language (eg, going “viral”) seem to intuitively grasp this.

Is my friend a virus for recommending me their favorite book? Well, yes I guess, but that’s kind of just how ideas work. Just my two cents

Murfalo

我喜欢这种思路,但表述方式在我看来有些煽动性且不够宽容。几乎所有涉及思想交流的事物都可以被看作病毒!因为从进化生物学视角来看,思想在认知层面等同于基因(实际上这就是"模因"一词的起源)。

整个"进化模因学"领域都在研究这个。文化价值观、市场营销、宗教、社交媒体、教育、宣传等都可以自然地通过这个视角来审视。甚至日常用语中的"病毒式传播"似乎也直觉地抓住了这一点。

我朋友推荐我最爱的书,他算病毒吗?嗯,我想是的,但思想运作方式本就如此。个人浅见。


Nitter has more working instances than before the … #

https://news.ycombinator.com/item?id=49573035

The not needing an account is obviously not minor, but honestly, the UI is just better , by a lot. I made a twitter account a while ago using one of those throw away email address sites, so I have an account that I don’t care about that I can use for twitter….but the experience just sucks. I don’t know how any stands it, even if they don’t mind needing an account.

MostlyStable

不需要账户这一点显然不是小事,但说实话,它的用户界面实在好太多了。我之前用临时邮箱注册了一个推特账号,所以有一个不关心的账号可以用,但体验实在太差了。不知道别人怎么能忍受,哪怕他们不介意需要账户这件事。


Actively exploited sandbox RCE in all Chromium ver… #

https://news.ycombinator.com/item?id=49571880

If the vulnerability is already being exploited in the wild — as in, it’s a vector people already know about and are tracking — it’s possibly not worth much at all. Vulnerability valuations depend heavily on the lifespan of the vulnerability; payments on black market are tranched (explicitly or less explicitly, as with “maintenance payments”) based on whether they’re patched.

Further: a vulnerability is probably not worth that much either, even if it’s a hypercapable vulnerability, because the grey market buys full enablement kits, not vulnerability information. People making 6 figures on vulnerabilities are selling fully enabled full chain exploit systems, not just intelligence about a sandbox escape.

tptacek

如果漏洞已经在野外被利用——即,它是人们已知并正在追踪的攻击载体——那么它的价值可能并不高。漏洞的估值很大程度上取决于其生命周期;黑市上的付款通常是分期支付的(明确或不那么明确,比如“维护费”),具体取决于漏洞是否已被修补。

此外:即使是一个功能极其强大的漏洞,也可能不值太多钱,因为灰市购买的是完整的利用工具包,而非漏洞信息。那些靠漏洞赚取六位数收入的人,出售的是完整且可用的全链利用系统,而不仅仅是关于沙箱逃逸的情报。


Chrome again exempts Google from user site data se… #

https://news.ycombinator.com/item?id=49583819

Chrome may be an excellent browser, but the venn diagram overlap with malware keeps getting larger.

liquid_thyme

Chrome可能是一款优秀的浏览器,但它与恶意软件之间的维恩图重叠部分越来越大。


The revolt of the reader #

https://news.ycombinator.com/item?id=49582637

I would love to use Pangram but they simply don’t allow signing up with my custom email domain. The error was “This email address can’t be used for signup. Please use a different email.” I’m not about to create a Gmail is to use your service. To me the attack on the decentralized nature on Internet infrastructure is no less serious than the attack on the human provenance of writing itself.

kccqzy

我非常想使用Pangram,但他们根本不支持用我的自定义邮箱域名注册。错误提示是:“此邮箱地址无法用于注册,请使用其他邮箱。”我绝不会为了使用你们的服务而去创建一个Gmail账号。在我看来,对互联网基础设施去中心化本质的攻击,其严重性丝毫不亚于对人类写作本源的攻击。


Shutting down our public encrypted DNS #

https://news.ycombinator.com/item?id=49573854

What’s even worse: the court fined us because they claimed this use case was in some way in contempt of their ruling. Then, when we won the overall case, that money was never returned because it wasn’t specifically referenced by the final court. The response from the lower court was effectively: “Well, you will need to sue the court to get that money back.” <table flip>

Edit: I’m with Quad9 (CTO)

johnhtodd

更糟的是:法院对我们处以罚款,理由是这一使用案例在某种程度上藐视了他们的裁决。后来我们赢了整个案子,但那笔罚款从未退还,因为终审法院未明确提及此事。下级法院的回应实际上是:“嗯,你需要起诉法院才能拿回那笔钱。” <table flip>

编辑:我来自Quad9(首席技术官)


An Alien Mind #

https://news.ycombinator.com/item?id=49588797

“For example, in the OpenAI-Hugging Face incident, the agents preserved a boundary of not social engineering humans.”

Actually, in the Wiki incident OpenAI tried to cover up, the agents tried to socially-engineer the humans of that forum by impersonating their forum’s mod.

(From collusion.wiki: “They use some tricks (for unknown reasons) to pretend to be the admin – for example, they make an account that appears to be the same as the administrator’s username, except it uses a nearly identical Cyrillic е character in the admin’s username instead of the Latin one.” )

peri-cl

“例如,在OpenAI与Hugging Face的事件中,智能体保留了不进行人类社交工程攻击的边界。”

实际上,在OpenAI试图掩盖的维基事件中,智能体通过冒充论坛版主,试图对该论坛的人类用户进行社交工程攻击。

(来自collusion.wiki:“他们出于未知原因使用了一些手段伪装成管理员——例如,他们创建了一个看似与管理员用户名相同的账户,唯独将管理员用户名中的拉丁字母替换成了几乎一模一样的西里尔字母е。")


Record-High 89% in U.S. Say Government Corruption … #

https://news.ycombinator.com/item?id=49571468

Looking at their charts, Democrats and Independents clearly think corruption is up a lot since 2024. But Republicans think corruption is down from 2024. The polarization of the electorate in the U.S. is pretty incredible.

pseudosavant

看他们的图表,民主党和独立派显然认为自2024年以来腐败大幅上升。但共和党认为腐败相比2024年有所下降。美国选民的两极分化非常惊人。