今日精选
HOTGo 1.27
Openrouter is joining Stripe
Civic Hygiene – avoid building technologies that could be used by a police state (2013)
Moderna reports first positive Phase 3 for mRNA neoantigen therapy in melanoma
A joke domain purchase turned in geopolitical warfare
最新资讯
共 33714 篇We're experimenting with AI-powered anime-style documentation.
Instead of writing long build logs or recording traditional vlogs, my co-founder and I wanted to try something different. We're documenting our startup journey by turning it into an AI-generated anime series. Not for fiction. For real startup moments. Episode 2 follows our cold outreach journey: Finding an ICP Testing different niches Sending DMs Getting ignored Learning what works (and what doesn't) We're treating this as an experiment to see whether AI-generated storytelling can make the process of building a startup more engaging than the usual "build in public" content. The goal isn't perfect animation. It's authentic documentation—with AI as the creative medium. We're still figuring it out, improving every episode, and learning as we go. Would love to hear what fellow builders and developers think about this approach. Could AI-powered anime become a new way to document products, startups, and open-source projects? Feedback is always welcome. 🚀
Building a tiny Windows tray app with .NET 9 Native AOT and raw Win32
I built CreditMeter, a small Windows tray app that shows GitHub Copilot AI-credit usage like a taxi meter. Why I built it Agentic coding makes AI usage feel invisible until you look at the bill. Constraints no WinForms no WPF no backend no telemetry no dependency-heavy architecture Tech stack C# / .NET 9 Native AOT raw Win32 / PInvoke GitHub REST API DPAPI for local PAT storage What I learned For tiny tools, architecture is also about knowing what not to add. Repo https://github.com/cdilorenzo/CreditMeter
GPT-5.6 Claims to Solve a 50-Year-Old Math Problem. Nobody Can Confirm It.
OpenAI just published a 3-page proof of the Cycle Double Cover Conjecture. The conjecture has been open for 50 years. The proof was generated entirely by GPT-5.6 Sol Ultra using 64 cooperating agents. There is one problem. Nobody has verified that the proof is correct. The Cycle Double Cover Conjecture is one of those problems that sounds simple enough for an undergraduate to understand but has resisted some of the best graph theorists alive. Every bridgeless graph (a graph you cannot disconnect by removing a single edge) should have a collection of cycles that covers each edge exactly twice. That is it. Paul Seymour, Paul Tutte, and others posed versions of it going back to the 1970s. Nobody proved it. Until maybe now. What OpenAI Published On July 10, 2026, OpenAI released two documents. The first is a 3-page proof. The second is the prompt they used to get the model to produce it. Both are available on their CDN. The proof itself is compact. It reduces the problem to cubic graphs (graphs where every vertex has degree 3), uses the 8-flow theorem to label edges with elements of a finite field, and then converts that labeling into a cycle double cover through a linear algebra argument. The key step is Lemma 2.2, which claims that a certain system of equations always has a solution. The proof PDF states: "The proof in this note is entirely due to GPT 5.6 Sol Ultra and the writeup with Codex (with GPT 5.6 Sol)." That is a remarkable claim. No human mathematician is credited with the proof itself. You can read it yourself here: https://cdn.openai.com/pdf/04d1d1e4-bc75-476a-97cf-49055cd98d31/cdc_proof.pdf The Prompt Is the Real Story The prompt OpenAI used is just as interesting as the proof. It is not a simple "prove this" instruction. It is a detailed engineering document for a multi-agent search system. The prompt tells the model to use "multiagent v2" with up to 64 concurrent agents. It specifies how agents should explore different mathematical approaches independen
314 Lawmakers Voted Against EU Chat Control. It Passed Anyway. Here's What That Means for Your Messages.
On July 9, 2026, the European Parliament reauthorized a law that lets tech companies scan your private messages without a warrant. Here is the part that should worry you: a majority of lawmakers voted against it. 314 MEPs voted to kill the law. 276 voted to keep it. The law passed anyway. How? The rejection required an "absolute majority" of 361 votes out of 720 MEPs. Every absent MEP effectively counted as a yes. The vote was scheduled for the last day before summer recess, when many MEPs had already left Strasbourg. The European People's Party, Parliament's largest group, used a rarely invoked urgency procedure (Rule 170) to force the vote onto the floor on July 7. Two days later, the deed was done. What Chat Control 1.0 Actually Does The law is technically called the ePrivacy derogation. It allows tech companies to voluntarily scan private, unencrypted messages and emails for known child sexual abuse material (CSAM), without a warrant or prior suspicion. Platforms affected: Instagram DMs, Discord, Snapchat, Skype, Xbox messages, Gmail, and iCloud. Platforms not affected: WhatsApp and Signal, because they use end-to-end encryption. Parliament did adopt an E2EE exemption amendment with 369 votes, excluding "communications to which end-to-end encryption is, has been or will be applied" from the scanning scope. But here is the catch. Providers of E2EE services were not scanning messages anyway. The exemption preserves the status quo. It does not create new protections. The scanning is limited to "known" CSAM material, meaning previously identified photos and videos. It does not detect new or unknown material. And it remains in effect until 2028, or until a permanent regulation is agreed. The Numbers That Should Make You Doubt This Law The EU Commission's own evaluation report gives Chat Control a very poor assessment: Only 0.00000077% of messages scanned in the EU actually contained illegal material ( heise online ) False positive rates of filter technologies reach u
El Niño Is Already Wreaking Havoc on Pacific Fisheries
As the climate phenomenon sends warm water surging across the eastern Pacific, some parts of the fishing industry are suffering—but other regions are seeing a windfall.
Every Sports App Resets Your Streak Eventually. Mine Can't. 🔒⚡
This is a submission for Weekend Challenge: Passion Edition What I Built Loyalty Ledger —...
How HackerRank Scores Engineers
I reviewed HackerRank's open-sourced Hiring Agent - prompts, the scoring logic, and the GitHub enrichment code. I tested the tool with a few faked resumes. Post : https://blog.grandimam.com/posts/how-hacker-rank-scores-engineers/ Takeaways: * Open source is weighted at 35%, technical skills at 10% * A senior engineer with perfect production experience scored 71/100 * Job titles to "Founding Engineer" and "CTO" results in same score * Startup roles emphasis * Active development was 77 days Code: Hiring Agent submitted by /u/grandimam [link] [留言]
Are you filthy enough for a $700 portable shower?
Hot showers, like electricity, are a luxury that's easy to take for granted. That all changes after a few nights camping at a music festival, a week toiling at a backcountry job site, or overlanding all summer in the great unknown. An itchy scalp and the vague smell of warm clams suddenly make the idea […]
Stop Asking. Start Delegating: How I Actually Use AI On My Site
AI is not a smarter Google I am convinced most people are using AI in the worst possible way. They treat it like a slightly magical search bar. Type question. Get answer. Copy. Paste. Forget. I think that mindset is holding a lot of people back. Developers. Designers. Knowledge workers. Even my baseball kids who ask ChatGPT for homework help. AI is not a better Q&A machine. It is a delegation machine. You do not "ask" AI. You give it a job. This post is me making that shift concrete. I just shipped six AI gallery pages on my site, built entirely around that idea. Not as a gimmick. As infrastructure for how I work, learn, and build. Why I stopped asking AI questions The turning point was basically frustration. My workflow looked like this for months: Open ChatGPT Ask something like "How do I X in Astro / Svelte / Next" Skim the answer Try the snippet Debug for 30 minutes anyway The answers were fine. Sometimes even useful. But nothing stuck. I would ask the same class of questions over and over. Same concepts. Same patterns. Same gotchas. No real accumulation of knowledge. Just one-off transactions. Then I noticed something: the few times I actually got huge value from AI, I was not asking. I was delegating. "Rebuild this layout using CSS grid, but keep these class names." "Refactor this component, keep the same API, and annotate the performance tradeoffs in comments." "Act like my annoying senior engineer and poke holes in this data model." That felt different. Less like search. More like a teammate who does legwork while I keep steering. Delegation > questions So I made a decision: treat AI like a junior colleague with unlimited patience and questionable taste. That means: I do not ask "How do I do X". I say "You are responsible for X. Here is context. Here are constraints. Here is the definition of done." The shift sounds subtle. It is not. When you ask a question, the model guesses what you want. When you delegate a job, you tell it what you want and where it fit
Batch Audio and Video Conversion in Your Browser
A practical workflow for batch audio and video conversion Media conversion is rarely difficult because of one file. The friction appears when the same job has to be repeated across a queue: choose an output format, adjust quality, add another file, wait for the result, and then start the setup again. That is the problem Format Factory is designed to address. It is a browser-based workbench for common audio and video conversion jobs, with a workflow built around batches instead of isolated one-file sessions. You open the page, choose the task you need, set the shared options once, add compatible files, and run the queue. There are no installer bundles or cluttered download pages to work through, and there is no need to configure every file from scratch. Start with the job, not the file Different media tasks call for different settings. Format Factory organizes the workflow around the operation you want to complete: Convert video to a different format for playback or upload Extract the audio track from a video Compress video files with shared quality settings Merge 2 to 10 clips into one MP4 Remove audio and export a silent copy of a video Convert audio between MP3, WAV, AAC, M4A, OGG, and FLAC Compress MP3 files by choosing a lower bitrate Merge 2 to 20 audio tracks into one MP3 This task-first approach is useful when you already know the result you want. Instead of opening a separate configuration flow for every input, you define the conversion job once and then build a queue around it. A queue that keeps each file visible Batch processing should reduce repetitive setup, but it should not make individual files mysterious. The queue keeps the state of each row visible from upload to download. If one file needs a different setting, you can apply a per-file override without rebuilding the entire job. If a file fails, its error is shown at the row level. You can retry that item, cancel it, or download a specific result when only one file needs attention. That gives you
See how AI instructions decay, then write ones that hold
This is a submission for Weekend Challenge: Passion Edition What I Built I told an agent Never write directly to the database . A long session later, context window full, it wrote directly to the database. The rule loading mark was still sitting in the prompt. The model had just stopped weighting and attending to it. It's an invisible failure. No error is being thrown. The task comes back subtly wrong, and the rule reads perfectly fine when you go back and check it. I wanted to make it visible, so I built an interactive field you can drag around. Every rule you write for an agent is a hill. Its height is how well the rule is written: a directive-led, backtick -anchored rule stands tall, a hedged and vague one sits low. Then you raise the water. The water is context load. As it rises the low rules go under first, in order of how well they were written. The weak ones drown while you watch. Three of the hills are high-stakes prohibitions, the Never... rules. They drown too. That is the whole point of the piece. A rule you cannot afford to lose does not belong in prose at all; it belongs on a runtime hook that runs as code, not attention. The field flags those in red the moment they go under. Underneath the field is a second tool: a client-side lint that reads an instruction and names the surface tells (hedges, shouting, politeness, a ban placed before its directive). It is deliberately not a score. It catches what a little regex can honestly catch, and points at the real analysis for the rest. Demo Play it on its own page. Drag to orbit, drag the load slider to raise the water: ▶ Open the live demo Each of the nine instruction patterns in the demo links to its rule page on reporails.com/rules . Code Code is available on Codepen: https://codepen.io/editor/G-bor-M-sz-ros-the-reactor/pen/019f4cad-e344-78bf-b7bc-919972f42a4e The whole thing is one self-contained HTML file: no build step, no dependencies, no backend. The CodePen above is the full source, so you can read eve
How My Open-Source Scanner Caught a Crypto Scammer Exposing Their Own Keys
Exposing the keys in the GitHub Issue The Phishing Site (Notice the Spotify option) There is a golden rule in cybersecurity: the weakest link is almost always human error. But what happens when that human error comes from a malicious actor trying to orchestrate a crypto phishing scam? The result is surprisingly comedic. Here is the story of how my newly built open-source secret scanner, Sentinel, accidentally neutralized a Tether (USDT) phishing operation during a routine benchmark. The Setup: Testing in the Wild I recently released Sentinel , a statically compiled, context-aware Git secret scanner and pre-commit hook written in Go. After fine-tuning its engine to achieve near-zero false positives, I decided to benchmark it "in the wild" by scanning random, recently updated repositories on GitHub. The goal was to see if Sentinel could catch edge-case credentials that traditional, regex-heavy tools often miss or drown in noise. During the scan, Sentinel instantly flagged a critical severity finding in a rather suspicious repository. The Catch: AI Copy-Paste Gone Wrong Upon inspecting the flagged file, the issue was immediately apparent: a fully exposed, hardcoded Firebase configuration object containing the API key, project ID, and messaging sender ID. It was a textbook case of a script kiddie asking an AI for a web login template and blindly copy-pasting the frontend code into a public repository. They had effectively handed over the administrative keys to their backend infrastructure before the project even launched. The Phishing Site: Logging into Crypto with Spotify? Out of professional curiosity, I checked the Vercel deployment linked to the repository. The project was attempting to impersonate Tether (USDT), the world's largest stablecoin. It featured the official logo, a catchy slogan, and a login prompt designed to harvest credentials. However, because the scammer had blindly copied a generic consumer application template, the authentication options presented
I put my fan streak on Solana so nobody could reset it
This is a submission for Weekend Challenge: Passion Edition What I Built Loyalty Ledger — a fan loyalty tracker where your check-in streak, badges, and history live on Solana instead of some app's database. Live app: https://loyalty-ledger-blond.vercel.app Here's the problem I kept coming back to. Every sports app wants you to check in, engage, "prove your loyalty" — collect points, build a streak, unlock a badge. And every single one of them throws that history away the moment you stop using it. Switch apps and your streak resets to zero. Get banned, or the app shuts down, or they just decide to wipe inactive accounts — your history is gone, because it was never really yours. It was a number in someone else's database, and they could reset it, inflate it, or delete it whenever they felt like it, and you'd have zero recourse. That felt like a weirdly solvable problem to just... not solve. We figured out how to make ownership portable for money, for domain names, for digital art. But "I've supported Argentina since 2019" still lives and dies inside one company's backend. So the scope for the weekend was deliberately narrow: prove one fan's loyalty to one team, for real, end to end, rather than sketch out ten features that are all half-fake. You connect a wallet, pick a sport and team, and check in. FIFA World Cup is the fully working path — that check-in sends a real transaction that creates or updates a program-owned account, not a row in my database. Your streak count, your badge tier, the actual badge tokens — none of it exists anywhere I control. Once that core loop worked, I built out the rest of the identity around it: a Fan Passport that shows your streak, a derived "Fan Score," your tier (Rookie → Devoted → Veteran → Legend), a progress bar toward the next tier, an achievements grid with locked/unlocked states, a recent-activity feed pulled from real on-chain transaction history, and a leaderboard ranking real fans by real streaks. There's also a "Demo Previe