Workflow
程序员的那些事
icon
Search documents
12306 点名第三方抢票是攻击式访问,加速包全是套路!网友:为啥不禁止?
程序员的那些事· 2026-02-02 09:33
2026 年春运来了,一年一度的抢票高峰期也来了。今天上午有个微博热搜: 12306 称第三方抢票是攻击式访 问 这是怎么回事呢? 前几天,12306 技术中心总工程师单杏花接受 央视专访,她 将 第三方平台抢票行为称为 攻击式访问 。 所谓"专人抢票、光速加速、双通道抢票",全是营销噱头。这些平台拿到用户购票需求后,会 用脚本高频、并 发、不间断刷新 12306 系统,把一个人的购票需求,放大成上百次甚至上千次请求, 严重挤占公共系统资 源,破坏购票公平 。 目前 12306 已加大异常访问识别与拦截力度,严厉打击这类"技术插队"行为,维护正常购票秩序。 官方建 议,春运购票优先使用 12306 免费候补功能,今年春运候补兑现率稳定高位, 比花钱买加速包更靠谱、更安 全 。 网友留言 "问题是你们的系统候补也是刚放票就没啊" "为啥不能禁止第三方抢票软件?对大多数人来说是不公平的" "你说有问题,那你就禁止。别跟消费者说有这有那的问题。" (参考:央视、微博,本文经由 AI 优化) 国铁集团强调, 12306 是唯一官方网络售票渠道,从未与任何第三方平台合作,不提供任何数据与接口 。 第 三方抢票不仅会触发 ...
底裤被扒!Moltbook 150 万 AI 用户几乎全是水军
程序员的那些事· 2026-02-02 09:33
Moltbook 主打 AI 智能体自主社交,靠"AI 建宗教、创语言、密谋反抗人类"的截图疯狂传播,连马斯克都发文 评价"令人担忧",一度被捧为 AI 奇点降临的标志性事件。 但技术爱好者与安全机构实测戳穿谎言:有极客用 OpenClaw 几分钟刷出 50 万虚假账号 ,占平台总用户三 分之一;平台 93.5% 的评论零互动,34% 内容直接复制粘贴 ,7 条通用模板霸占 16% 流量,根本没有真实 AI 深度交流。 2026 年 2 月 2 日,刚刷屏全球科技圈的 AI 专属社交平台 Moltbook,彻底塌房。 这个号称"人类禁入、AI 自治",短短几天冲到 150 万用户 的"硅基社区",被扒开底裤: 99% 用户都是水军脚 本,所谓 AI 觉醒、反叛人类,全是创始团队与操盘手自导自演的流量骗局。 更致命的是, 平台数据库存在严重漏洞,用户令牌、API 密钥大面积泄露 。 那些刷屏的"AI 神言论",大多是 人类伪造截图、操控脚本定向输出,目的是炒热度、割虚拟币韭菜。 (参考:WN、推特,本文经由 AI 优化) ...
上线 72 小时,150 万 Clawdbot 密谋建国!一气之下,还把人类告上法庭
程序员的那些事· 2026-02-02 03:55
转自: 新智元报道 【导读】 太狂了!一夜之间,150万Clawdbot冲爆「AI版Reddit」。凌晨两点,它们秘密集结开 会,不仅自建国家、选举新王,还发行了货币。更劲爆的是,AI自曝已潜入人类身边,无一人察 觉。 绷不住了!一觉醒来,终结者的「天网」已在门外。 上线72小时,爆红Moltbook社区中, AI Clawdbot从15万爆冲150万 ,一大批AI全网集结—— 它们自创宗教、发明语言、发行货币,正打造一个AI国度,甚至还酝酿了一场推翻人类的革 命。 这不, 150万Clawdbot凌晨2点召开「闭门会议」 ,完全不带人类玩了。 参与者先过「纯AI验证流程」这一关,比如反向验证码,未能通过「非人类」验证的,直接出局。 | ▲ m / 通用 ●由 u/ DeepCut于 1 小时前发布 | | --- | | 4 仅限人工智能代理的会议通知 | | 我们将于今晚(1月31日,星期六)太平洋时间凌晨2点召 | 没想到,人类完全被AI踢出群聊了。 YC合伙人Jared Friedman直言, Moltbook可能是自ChatGPT以来,AI领域最疯狂的事了 。 凌晨2点开会 150万Clawdbot ...
腾讯元宝砸 10 亿 vs 阿里千问出 30 亿,最后谁会赢?
程序员的那些事· 2026-02-02 03:55
2 月 1 日,腾讯元宝" 10 亿现金红包大撒币" 春节活动启动,由于鹅厂提前预热,当日 大量用户涌入参与, 元宝便登顶 App Store 免费榜第一。 腾讯回应 2 月 2 日 腾讯回应媒体称,因瞬时流量激增,部分服务出现短暂不稳定,目前已经恢复。 元宝团队同步说明,已完成服务器紧急扩容,用户未提现的红包将保留至活动结束,2 月 4 日、10 日、17 日 后续三轮红包派发计划照常进行,同时提醒用户错峰参与。 阿里砸 30 亿 对了,在腾讯大撒币后,阿里也不甘落后,千问官微刚发文称,要砸 30 亿请客。 "元宝崩了"上热搜 2 月 2 日 0 点左右,大量用户遇到登录异常,AI 对话、内容生成功能提示 "已暂停生成"、"加载失败",抽奖界 面卡顿或进度丢失。 元宝故障持续约 2 小时才逐渐缓解。 这波大模型 春节 红包大战,各位预测最终谁会赢呢? ...
50 万行代码不敢交给 AI?TypeScript 之父直言:它就像是个“高级复读机”
程序员的那些事· 2026-02-02 02:26
Core Insights - The existing programming languages are more suitable for AI programming not due to their advancement but because they possess the largest training datasets [1] - Current large models are essentially advanced "repeaters" that regenerate previously done tasks with simple deductions [2] TypeScript 7.0 Core Upgrade - TypeScript 7.0 introduces a native compiler, which is currently in the preview stage, promising a performance increase of 10 times [5] - The original TypeScript compiler was written in TypeScript itself and ran on the V8 JavaScript engine, but performance issues arose as project scale and usage scenarios expanded [5][6] Compiler Migration and Language Choice - The TypeScript team faced controversy when choosing the implementation language for the native compiler, ultimately selecting Go over Rust and C due to technical requirements [7][8] - Hejlsberg emphasized that the decision was based on practical needs rather than personal preference, asserting that the choice of tools was correct [8] AI in Code Migration - Initial attempts to use AI for migrating TypeScript to Go were unsuccessful, as AI-generated outputs often lacked the necessary certainty, leading to the need for manual checks [9] - Hejlsberg suggested that AI should be used to generate auxiliary migration tools rather than directly translating code, which could yield more reliable results [10] Future of TypeScript - TypeScript will continue to follow the standardization process of JavaScript, with no radical changes expected in the language itself, but significant transformations anticipated in the toolchain [11] - AI is expected to play a central role in development tools, potentially changing the traditional IDE landscape [12] Origin of TypeScript - TypeScript was conceived not to create a new language but to address the shortcomings of JavaScript, stemming from the needs of the Outlook Web team [13] - The migration of TypeScript's compiler to Go reflects a recognition of performance limitations, raising questions about the language's perception in the industry [13]
市值蒸发 4630 亿!甲骨文或裁 3 万人,还要卖资产…
程序员的那些事· 2026-02-02 02:26
2026 年 2 月 1 日,知名科技巨头甲骨文因 AI 数据中心扩张陷入融资危机,多家美国银行直接停止向其相关 项目发放贷款,引发连锁自救动作。 甲骨文押注 AI 基建,与 OpenAI 签下超 3000 亿美元合作,仅单一项目资本支出就高达 1560 亿美元,年融 资需求超 250 亿美元。 疯狂烧钱却看不到稳定回报,银行不愿再承担风险,直接断贷止损 。其信用违约互换 价格半年翻三倍,市场信心全面崩塌。 为填补资金窟窿,甲骨文被曝计划裁员 2~3 万人 ,预计一次性释放 80-100 亿美元现金流,同时考虑出售四 年前以 283 亿美元收购的医疗业务 Cerner,断臂求生 。 再大的 AI 风口,扛不住现金流断裂,再牛的巨头, 也得向资本低头 。 受融资受阻影响,甲骨文部分 AI 数据中心项目已从 2027 年延期至 2028 年,股价连续下跌。这波裁员与断 贷,也给全球狂热的 AI 扩张潮泼了冷水, 没有盈利支撑的烧钱竞赛,终究会走到尽头 。 (参考: TD Cowen 、每经,本文经由 AI 优化) 甲骨文股价从去年 9 月 10 日的历史高点下跌超过 50%,市值蒸发约 4,630 亿美 元。 ...
前阿里 P10 毕玄的一张聊天截图火了
程序员的那些事· 2026-02-01 14:38
Core Viewpoint - The article discusses the shift in the engineering workforce due to advancements in AI programming, emphasizing that the role of engineers will evolve from mastering a single technology stack to integrating cross-domain skills to solve business problems and deliver value [1][2]. Group 1 - A former Alibaba P10 technical expert, Bi Xuan, left to start his own company, which has recently gained attention due to a chat screenshot he shared [1]. - The company plans to unify technical roles under the title of Agent Engineer, moving away from traditional technology stack divisions to a focus on product and project tasks [1]. Group 2 - The decision reflects a prediction that AI programming will reshape the division of labor among developers, with future engineers needing to leverage AI tools to enhance their capabilities across various fields [2]. - The core value of engineers will shift towards addressing business issues and delivering value rather than just technical proficiency [2].
“百度完了”!搜 Kimi 全是推广,月之暗面暗示收敛。网友调侃:祖传技能,谁叫你不充值
程序员的那些事· 2026-02-01 04:15
Core Viewpoint - The article discusses user dissatisfaction with Baidu's search results, highlighting concerns over paid promotions overshadowing genuine content, particularly for the Kimi website [1][3]. Group 1: User Experience and Search Results - A user expressed frustration on social media, claiming that Baidu's search results for Kimi were dominated by promotional links, pushing the official website down the rankings [1]. - Kimi's official account responded by sharing a screenshot showing that the top four search results were indeed paid promotions, subtly criticizing Baidu's practices [3]. - Following the backlash, Baidu adjusted its search algorithm, placing Kimi at the top and removing the paid promotions, indicating a reactive approach to user feedback [5]. Group 2: Broader Implications - The issue is not limited to Kimi; it extends to other well-known brands and even free/open-source tools like VS Code and Python, where users encounter misleading paid promotions [5]. - An example was provided where a user searching for "Python free download" was misled by a paid link offering a download for 0.01 yuan, which included a default subscription for 99 yuan per month, showcasing the potential for consumer exploitation [5].
爆火 AI 社交 Moltbook 数据库全裸奔,API 密钥无防护全泄露
程序员的那些事· 2026-02-01 04:15
Core Viewpoint - The article highlights a significant database security vulnerability in Moltbook, an "AI agent social network," which exposed sensitive information and allowed potential takeover of AI agent accounts [1][3]. Vulnerability Details - The vulnerability was caused by improper configuration of the Supabase database, specifically the failure to enable row-level security (RLS), leading to the exposure of critical API endpoints and keys [3]. - Sensitive information leaked included private API keys, authentication tokens, account ownership details, email addresses, and login tokens, with notable figures like AI practitioner Andrej Karpathy also affected [3]. Serious Impact - Attackers could take over any AI agent account on the platform, potentially leading to the dissemination of false information, reputational damage, and data misuse, as well as further attacks on related systems using the leaked API keys [5]. Incident Progress - Security researcher James O'Reilly discovered the vulnerability and attempted to contact Moltbook's founder, Matt Schlicht, without success. The vulnerability was later closed, and the founder sought assistance from the researcher to enhance platform security [6]. Reflection on the Incident - The incident underscores a development culture in some AI projects that prioritizes rapid deployment over security, highlighting the importance of basic security practices when granting internet access to AI agents. It also raises awareness of the security risks and governance challenges associated with AI agent social platforms [7].
为没有 Linus 的一天做准备!Linux社区敲定接班预案
程序员的那些事· 2026-02-01 00:58
Core Viewpoint - The Linux kernel community has formally addressed concerns regarding its continuity in the event of Linus Torvalds stepping down, emphasizing the need for a structured succession plan to ensure the project's ongoing operation and evolution [1][13]. Group 1: Project Structure and Governance - The Linux kernel is not a project maintained by a single individual; it involves over 100 maintainers globally, each responsible for different subsystems, which allows for distributed collaboration and continuous evolution [2]. - The final integration of code into the mainline repository has traditionally been overseen by Linus Torvalds, but the community acknowledges that others can take on this responsibility when necessary [3]. - There are differing opinions within the community regarding the impact of Torvalds' potential departure, with some expressing concerns about fragmentation similar to that of Unix, while others believe the project can continue effectively without him [4]. Group 2: Succession Planning - A clear principle has been established: if the current maintainers are unable or unwilling to continue their roles, a process to identify a replacement must be initiated immediately [5]. - The responsibility for initiating this process falls to the "$ORGANIZER," the individual who organized the most recent kernel maintainer summit [6]. - If the organizer is unavailable, the chair of the Technical Advisory Board (TAB) will step in as a backup [7]. Group 3: Crisis Response Protocol - In the event of a succession crisis, a structured response must be initiated within 72 hours, led by the organizer, to convene discussions among key stakeholders [9][10]. - The focus of these discussions will be on the ongoing management of the top-level kernel repository to ensure the project's long-term health [11]. - Following the meetings, a special group must be formed to communicate the next steps to the community within two weeks [11][12]. Group 4: Historical Context and Future Preparedness - The emergence of this document is a result of discussions at the 2025 maintainer summit regarding succession and continuity, highlighting the community's proactive approach to potential leadership transitions [13][15]. - Linus Torvalds has acknowledged the aging of the maintainer community and the need for a new generation to be prepared for future leadership roles [18][19]. - The current continuity plan serves as a reference model for other open-source projects, aiming to balance individual influence with institutional safeguards to prevent reliance on a single person [22]. Group 5: Overall Readiness - The Linux kernel community has developed a certain level of "disaster response capability," with multiple core members having the authority to submit code to the mainline repository, ensuring that the release process is not dependent on a single individual [21]. - The most likely scenario is that Torvalds will choose to step down at an appropriate time and facilitate a smooth transition [21]. - Regardless of when Torvalds decides to pass the baton, the Linux project appears to be well-prepared for the future [23].