recent bookmarks
| « earlier |
The Zen of Parallel Programming | Hacker News
2 minutes ago by Chirael
Fred Brooks and the mythical man month observed that communication between people expands faster than linear, and that adding more people to a project makes it later.
In my experience with more than a couple dozen software projects, the ideal team size to successfully deliver a non-trivial effort is between five to nine people.
One subject matter expert visionary
One technical architect visionary
One or two technical masters
One or two UI/UX masters
One or two padawans capable of becoming a master
Staffing exceeding the above for an individual team is more a managerial genitalia contest than anything focused on organizational success.
programming
In my experience with more than a couple dozen software projects, the ideal team size to successfully deliver a non-trivial effort is between five to nine people.
One subject matter expert visionary
One technical architect visionary
One or two technical masters
One or two UI/UX masters
One or two padawans capable of becoming a master
Staffing exceeding the above for an individual team is more a managerial genitalia contest than anything focused on organizational success.
2 minutes ago by Chirael
GitHub - nihe0909/zh-humanizer-literary: 中文去 AI 味与文采增强 Codex Skill,汲取 Mengke / 好事风格,让中文草稿更像人写。 · GitHub
6 minutes ago by w1zard
w1zard starred nihe0909/zh-humanizer-literary
from:ifttt
github
6 minutes ago by w1zard
GitHub - bojieli/ai-agent-book: 《深入理解 AI Agent:设计原理与工程实践》(李博杰 著)开源主仓库:全书正文、编译版 PDF 与按章配套代码 · GitHub
6 minutes ago by w1zard
w1zard starred bojieli/ai-agent-book
from:ifttt
github
6 minutes ago by w1zard
GitHub - lintsinghua/DeepAudit: DeepAudit:人人拥有的 AI 黑客战队,让漏洞挖掘触手可及。国内首个开源的代码漏洞挖掘多智能体系统。小白一键部署运行,自主协作审计 + 自动化沙箱 PoC 验证。支持 Oll
6 minutes ago by w1zard
w1zard starred lintsinghua/DeepAudit
from:ifttt
github
6 minutes ago by w1zard
GitHub - kolega-ai/Real-Vuln-Benchmark: A benchmark for SAST security scanners against a suite of realistic OS apps. · GitHub
6 minutes ago by w1zard
w1zard starred kolega-ai/Real-Vuln-Benchmark
from:ifttt
github
6 minutes ago by w1zard
How proprietary formats have become Microsoft's main tool for lock-in
7 minutes ago by mikael
An open format — a format whose specifications are published, freely available and implementable by any software without restrictions — stores information in such a way that any compliant application can read, write and reproduce it faithfully.
A proprietary format, by contrast, may contain undocumented features, private extensions or behaviours that only the original software implements correctly. The document may be opened by other applications, but it cannot always be reproduced faithfully.
The practical consequence is familiar to anyone who has tried to open a Microsoft Office document in another application: the formatting becomes distorted, bullet points shift, tables lose their proportions, and headings appear different.
A presentation that looked polished in PowerPoint seems slapdash in a different viewer: the content is all there, whilst the document, strictly speaking, is not.
This is “lock-in”: it is not a padlock, it is not a technical ban, it is not a contractual restriction, but a silent and persistent friction that makes any work outside the Microsoft ecosystem seem slightly off, slightly unreliable, slightly unprofessional — and ensures that the easiest route is to return to the tools that produce documents with the expected appearance.
word-processing
software
fileformats
standards
blog-posts
A proprietary format, by contrast, may contain undocumented features, private extensions or behaviours that only the original software implements correctly. The document may be opened by other applications, but it cannot always be reproduced faithfully.
The practical consequence is familiar to anyone who has tried to open a Microsoft Office document in another application: the formatting becomes distorted, bullet points shift, tables lose their proportions, and headings appear different.
A presentation that looked polished in PowerPoint seems slapdash in a different viewer: the content is all there, whilst the document, strictly speaking, is not.
This is “lock-in”: it is not a padlock, it is not a technical ban, it is not a contractual restriction, but a silent and persistent friction that makes any work outside the Microsoft ecosystem seem slightly off, slightly unreliable, slightly unprofessional — and ensures that the easiest route is to return to the tools that produce documents with the expected appearance.
7 minutes ago by mikael
Christos Nikolaidis - IB Diploma Mathematics (AA: Analysis & Approaches; AI: Applications & Interpretation)
11 minutes ago by unbeknownst
Lecture notes and exam-style questions.
edu
mathematics
resources
11 minutes ago by unbeknownst
GitHub - stupside/castor: Point it at any web page and it finds the video, extracts the stream, transcodes it and casts in real time to your TV. It even burns subtitles…. · GitHub
16 minutes ago by mandarine
Smart TVs won't cast arbitrary web video, and screen mirroring is laggy and drops resolution. Castor casts the real stream instead, at full quality, from your terminal.
tv
hack
16 minutes ago by mandarine
Immagini AI nei forum di birdwatching: a rischio i dati della citizen science
17 minutes ago by mgpf
L’aumento di foto di uccelli generate o ritoccate con AI sta creando falsi avvistamenti su piattaforme come iNaturalist e Macaulay Library, usate dai ricercatori per monitorare distribuzione e migrazioni delle specie. Gli esperti avvertono che anche modifiche non intenzionalmente fraudolente possono alterare dati cruciali per biodiversità, clima e conservazione.
N8N
#AI_and_Society
AI&SOCIETY
TW2026-30
17 minutes ago by mgpf
- YouTube
19 minutes ago by datorres
Found on YouTube: Turn WiFi completely ON/OFF with Siri on iPhone! 🤯 | Siri Se WiFi ON/OFF Kaise Kare https://www.youtube.com/watch?v=s6dY_JqH0Ok
YouTubeFeed
19 minutes ago by datorres
Debian11升级Debian13与每日Zero Touch Patching – IAM-LC
20 minutes ago by wogong
Debian11升级Debian13与每日Zero Touch Patching – IAM-LC via Instapaper https://iam.lc/2026/07/debian-in-place-upgrade-n-ztp.ping
IFTTT
Instapaper
20 minutes ago by wogong
Reviving a 15-year-old netbook with Arch Linux
28 minutes ago
by kabads
KO | EN I still have a netbook I bought back in 2009. The ASUS Eee PC 1000HE has an Intel Atom N280 and 1GB of DDR2 RAM. The Atom N series was Intel’s line of cheap, low-performance CPUs for netbooks. The chip has 56KB of L1 cache and 512KB of L2 cache, and its clock speed is 1.667GHz. Compare that ...
narcan expiration absolute - Brave Search
don't throw away expired narcan/generics. Expired is better than none.
there can be 90% potency for 30 years past expiration.
46 minutes ago
by WaltMG
there can be 90% potency for 30 years past expiration.
diabetes intoxication - Brave Search
wrongful dui arrests / breathalyzers cannot distinguish / blood tests recommended
49 minutes ago
by WaltMG
www.pinterest.com
50 minutes ago by littlebizresources
via Snappy Baby Flannel Fabric By The Yard https://www.pinterest.com/kimchristian_chattyreview/snappy-baby-flannel-fabric-by-the-yard
Snappy
Baby
Flannel
Fabric
By
The
Yard
50 minutes ago by littlebizresources
Market for “Lemons”: Quality Uncertainty and the Market Mechanism* | The Quarterly Journal of Economics | Oxford Academic
the aalsmeer flower auction prompted me to this paper
1 hour ago
by tonyyet
電車でタイピング|駅名で楽しく続ける無料タイピング練習サイト
全国の実在する駅名で続けられる無料のタイピング練習サイト。ローマ字入力の反復練習でプレイ記録は自動保存され、上達が実感できます。山手線周回・日本縦断・区間指定など、乗り鉄気分で全国の駅名を巡りながら練習できる多彩なモードを収録。
1 hour ago
by alviss
ridemountainpig/tw-metro-typing: A typing game powered by real Taiwan metro routes and station names.
A typing game powered by real Taiwan metro routes and station names. - ridemountainpig/tw-metro-typing
1 hour ago
by alviss
Eli Lilly is reinventing the pharma business
1 hour ago by spondaic
Since the start of 2023 its share price has more than tripled. *Analysts expect its revenue to grow by 15% a year, on average, until the end of the decade, more than three times the median of its peers.*
Zepbound, Lilly’s slimming jab, generated $4.9bn in sales in its first full year on the market in 2024. This year analysts expect sales to be quadruple that figure. *The company now accounts for 60% of GLP-1 sales in America.* Bloomberg Intelligence estimates that Lilly could capture 66% of a global obesity-drug market worth more than $120bn a year by 2030.
Novo Nordisk launched its treatment in America more than two years before Lilly. Yet by 2025 Zepbound had overtaken Novo’s drug. Mr Ricks credits both superior science and execution. Zepbound produced greater weight loss with fewer side-effects. Lilly also invested early in manufacturing, priced lower and quickly recognised that obesity would become a consumer market as much as a medical one.
More than 120 companies are developing drugs, with at least 190 candidates in clinical trials. Lilly’s answer is to “cover the chessboard” with treatments offering different combinations of efficacy, tolerability and convenience. Manufacturing is another advantage. Since 2020 Lilly has committed more than $50bn to expanding production, betting that the ability to make these medicines at scale will matter as much as discovering them.
GLP-1s are proving useful beyond their original purpose, reducing the risk of cardiovascular disease, sleep apnoea and chronic kidney disease. Early evidence suggests they may also help with addiction and psychiatric illness.
A business built on prevention has to stay much closer to patients than pharma traditionally has. It must persuade people to start treatment earlier, make medicines easy to obtain and keep them on therapy for years. Today more than half of new patients starting on its GLP-1s come through online channels including LillyDirect.
investing
drug
Zepbound, Lilly’s slimming jab, generated $4.9bn in sales in its first full year on the market in 2024. This year analysts expect sales to be quadruple that figure. *The company now accounts for 60% of GLP-1 sales in America.* Bloomberg Intelligence estimates that Lilly could capture 66% of a global obesity-drug market worth more than $120bn a year by 2030.
Novo Nordisk launched its treatment in America more than two years before Lilly. Yet by 2025 Zepbound had overtaken Novo’s drug. Mr Ricks credits both superior science and execution. Zepbound produced greater weight loss with fewer side-effects. Lilly also invested early in manufacturing, priced lower and quickly recognised that obesity would become a consumer market as much as a medical one.
More than 120 companies are developing drugs, with at least 190 candidates in clinical trials. Lilly’s answer is to “cover the chessboard” with treatments offering different combinations of efficacy, tolerability and convenience. Manufacturing is another advantage. Since 2020 Lilly has committed more than $50bn to expanding production, betting that the ability to make these medicines at scale will matter as much as discovering them.
GLP-1s are proving useful beyond their original purpose, reducing the risk of cardiovascular disease, sleep apnoea and chronic kidney disease. Early evidence suggests they may also help with addiction and psychiatric illness.
A business built on prevention has to stay much closer to patients than pharma traditionally has. It must persuade people to start treatment earlier, make medicines easy to obtain and keep them on therapy for years. Today more than half of new patients starting on its GLP-1s come through online channels including LillyDirect.
1 hour ago by spondaic
Peter's Field Trip From Hell by chvotic
1 hour ago by barmy_bunk
12,145 words. “Calling my kid a liar and a thief. Insinuating that he and his friend wouldn’t be smart enough for an internship in the future. One of your students pushing Peter into a desk, among plenty other things I’ve heard be said to Peter.”
“Your kid?” Mr. Harrington squeaked.
Or
Peter goes on a field trip to his own home. It goes just as well as you'd think.
// Peter seems to live with Tony, though May is still his guardian? Anyway, Peter starts getting sick before the field trip, but decides to tough it out and ends up vomiting in the robotics lab. FRIDAY sends Tony footage from the field trip and he gets Flash expelled and Mr Harrington fired.
10k+
MCU
Gen
FieldTrip
Illness/Injury
Irondad
zz:chvotic
“Your kid?” Mr. Harrington squeaked.
Or
Peter goes on a field trip to his own home. It goes just as well as you'd think.
// Peter seems to live with Tony, though May is still his guardian? Anyway, Peter starts getting sick before the field trip, but decides to tough it out and ends up vomiting in the robotics lab. FRIDAY sends Tony footage from the field trip and he gets Flash expelled and Mr Harrington fired.
1 hour ago by barmy_bunk
LOCKED: General Grogu, Coruscant Guard Mascot by SnowyEgret (Snowy1138)
1 hour ago by caelulum
“What is this?”
“A mini Yoda,” Thire says, grinning.
“Bu,” says the kid.
Fox’s right eyelid twitches.
———
Or, Grogu worms his way into the hearts of the Coruscant Guard and saves the Galaxy.
F:Star_Wars
T:Fic
W:01-5K
St:Complete
Cat:Gen
Ch:CC-4477_|_Thire_(Star_Wars)
Ch:Grogu_|_Baby_Yoda_(Star_Wars)
Ch:CC-1010_|_Fox_(Star_Wars)
Ch:Coruscant_Guard_(Star_Wars)
Ch:
Kelleran_Beq_(Star_Wars)
P:Minor_or_background
AU:Canon_AU
AU:Time:SW_Prequel
OT:KidFic
G:Fluff
Ep:SW_Clone_Wars
A:SnowyEgret_(Snowy1138)
L:LOCKED
L:AO3
D:TBA
Read:1
“A mini Yoda,” Thire says, grinning.
“Bu,” says the kid.
Fox’s right eyelid twitches.
———
Or, Grogu worms his way into the hearts of the Coruscant Guard and saves the Galaxy.
1 hour ago by caelulum
„wp2shell“: Kritische WordPress-Lücke erlaubt Codeeinschleusung über API | heise online
1 hour ago by igorette
Sicherheitsforscher haben zwei Sicherheitslücken in WordPress gefunden, die sich zu einem Exploit verketten lassen und dann das Einschleusen von Schadcode ermöglichen. Administratoren des beliebten Blog-Systems sollten zügig updaten oder ein Mini-Plugin als Notfallflicken einspielen.
Eine kritische SQL-Injection-Lücke (CVE-2026-60137) hat einen CVSS-Wert von 9,1/10 und kann durch Angreifer aus der Ferne ausgenutzt werden. Die Lücke betrifft den author__not_in-Parameter von WP_Query, der nicht korrekt validiert wird.
Die zweite der beiden Sicherheitslücken haben die Forscher von Searchlight Cyber entdeckt – und dem Trend gehorchend direkt mit einem Spitznamen versehen: „WP2Shell“. Die Sicherheitslücke mit der CVE-Kennung CVE-2026-63030 ist für sich genommen „nur“ mit einem hohen Risiko bedacht (CVSS 7.5/10) und basiert auf einem Fehler im REST-API des freien CMS. Nur wenige Details sind bekannt, doch der API-Endpunkt /wp-json/batch/v1 scheint der Schuldige zu sein.
Die Finder haben unter wp2shell.com eine Prüfmöglichkeit für Blogbetreiber veröffentlicht. Sie erlaubt eine erste Einschätzung und enthält einen praktischen Flicken: Ein wenige Zeilen PHP-Code umfassendes WordPress-Plugin, das die schadhafte API-Route mit einer Authentifizierung versieht. Wer sein WordPress nicht sofort auf den neuesten Stand bringen kann – die empfohlene Vorgehensweise –, sollte zu diesem Behelf greifen.
Unheilvolle Verkettung – updaten!
Problematisch ist die Verkettung beider Lücken – sie führt zu einer Möglichkeit, Code ohne vorherige Anmeldung in verwundbare WordPress-Installationen einzuschleusen. Derlei Sicherheitslücken sind leicht automatisierbar und können etwa zu Großangriffen führen: Derzeit sind etwa 500 Millionen Installationen von WordPress im Internet zu finden.
Das WordPress-Team hat bereits reagiert und neue Versionen publiziert:
WordPress 7.0.2,
6.9.5,
6.8.6 sowie
7.1 beta 2
Versionen vor WordPress 6.8 sind nicht betroffen. Admins sollten die Aktualisierung schnellstmöglich einspielen – es ist zu erwarten, dass Angreifer die Sicherheitsflicken mit KI-Hilfe analysieren und noch am Wochenende erste Exploitversuche starten.
Das freie CMS WordPress erfreut sich vor allem durch sein reichhaltiges Angebot an Vorlagen und Plugins großer Beliebtheit. Letztere sind häufiges Einfallstor für Sicherheitslücken, ein Fehler im Kern der Software ist mittlerweile seltener geworden.
(cku)
s
Eine kritische SQL-Injection-Lücke (CVE-2026-60137) hat einen CVSS-Wert von 9,1/10 und kann durch Angreifer aus der Ferne ausgenutzt werden. Die Lücke betrifft den author__not_in-Parameter von WP_Query, der nicht korrekt validiert wird.
Die zweite der beiden Sicherheitslücken haben die Forscher von Searchlight Cyber entdeckt – und dem Trend gehorchend direkt mit einem Spitznamen versehen: „WP2Shell“. Die Sicherheitslücke mit der CVE-Kennung CVE-2026-63030 ist für sich genommen „nur“ mit einem hohen Risiko bedacht (CVSS 7.5/10) und basiert auf einem Fehler im REST-API des freien CMS. Nur wenige Details sind bekannt, doch der API-Endpunkt /wp-json/batch/v1 scheint der Schuldige zu sein.
Die Finder haben unter wp2shell.com eine Prüfmöglichkeit für Blogbetreiber veröffentlicht. Sie erlaubt eine erste Einschätzung und enthält einen praktischen Flicken: Ein wenige Zeilen PHP-Code umfassendes WordPress-Plugin, das die schadhafte API-Route mit einer Authentifizierung versieht. Wer sein WordPress nicht sofort auf den neuesten Stand bringen kann – die empfohlene Vorgehensweise –, sollte zu diesem Behelf greifen.
Unheilvolle Verkettung – updaten!
Problematisch ist die Verkettung beider Lücken – sie führt zu einer Möglichkeit, Code ohne vorherige Anmeldung in verwundbare WordPress-Installationen einzuschleusen. Derlei Sicherheitslücken sind leicht automatisierbar und können etwa zu Großangriffen führen: Derzeit sind etwa 500 Millionen Installationen von WordPress im Internet zu finden.
Das WordPress-Team hat bereits reagiert und neue Versionen publiziert:
WordPress 7.0.2,
6.9.5,
6.8.6 sowie
7.1 beta 2
Versionen vor WordPress 6.8 sind nicht betroffen. Admins sollten die Aktualisierung schnellstmöglich einspielen – es ist zu erwarten, dass Angreifer die Sicherheitsflicken mit KI-Hilfe analysieren und noch am Wochenende erste Exploitversuche starten.
Das freie CMS WordPress erfreut sich vor allem durch sein reichhaltiges Angebot an Vorlagen und Plugins großer Beliebtheit. Letztere sind häufiges Einfallstor für Sicherheitslücken, ein Fehler im Kern der Software ist mittlerweile seltener geworden.
(cku)
1 hour ago by igorette
IndieWeb
1 hour ago by sanjayjc
"Site deaths are one of the big reasons why you should own your own identity and content on the web. This is a chronology of content hosting sites that have died"
tech
1 hour ago by sanjayjc
| « earlier |
| per page: 20 ‧ 40 ‧ 80 ‧ 160 |
recent tags
2012 @dump API Amnesiafic Avengers Business CSS DemonsLexicon Fandom:Avengers Fandom:Marvel Feed From Holiday_rentals Ideas Me Medicaid PPACA ProgrammableWeb: SCOTUS SD:Fic StateAndLocal TheChristianLft Tips apps architecture art article au:aria avengers biz blogs browser business carlmedearis cats code commentary cpan crack culture design dev development editor education energy facebook fandom:Avengers fandom:avengers fanfic faves favorites framework game google googlereader government headline headlines humor ifttt ifttt:twitter inquiry inspiration ios iphone ironman javascript jquery js kvo lggm! mac maps mobile music nodejs osx pairing:Tony/Steve pairing:dean/castiel pairing:loki/tony pairing:sam/castiel performance perl politics presentations programming python rails rating:r read-later recipes ruby russian rwdweekly11 scanner security shopping socialism software tea thor tips tool tools training tutorial twitter twitter-follow twitterlink type:slash user via via:grandin via:reddit video web webdev westfielddevfeed wordpress youtube