Workflow
程序员的那些事
icon
Search documents
把 Bug 曝光到全网,谷歌逼 FFmpeg 维护者“按时修复”,遭怒怼:别光用 AI 找 Bug,有本事你自己修啊!
程序员的那些事· 2025-11-09 05:10
Core Viewpoint - The article discusses the conflict between Google Project Zero and the open-source framework FFmpeg regarding the responsibility of fixing bugs discovered by AI tools, raising questions about the ethics of relying on volunteer maintainers for critical software security [1][17]. Group 1: Triggering Event - Google Project Zero announced a new policy called "Reporting Transparency" in July 2025, which requires the disclosure of bugs within a week of discovery, even if they are not yet fixed, while maintaining a standard 90-day repair window for vendors [3][5]. - The policy aims to reduce the "upstream patch lag," where fixes are available but not yet distributed to users, facilitated by Google's AI security engine, Big Sleep [3][5]. Group 2: Bug Discovery and Response - In August 2025, Big Sleep identified approximately 20 bugs in major open-source projects, including FFmpeg, which is widely used in browsers and media applications [5][6]. - Although most bugs were rated as low or medium risk, the public nature of the disclosures pressured FFmpeg maintainers to fix the bugs quickly without providing any direct patches from Google [6][7]. Group 3: FFmpeg's Reaction - FFmpeg developers expressed their frustration on social media, arguing that Google’s approach places undue pressure on volunteers to fix bugs without offering any support or solutions [8][12]. - They criticized the situation as a form of "corporate coercion," where a wealthy company uses AI to find vulnerabilities and then shifts the repair responsibility to unpaid volunteers [8][12]. Group 4: Diverging Perspectives - The security research camp, supporting Google, argues that FFmpeg, as a critical internet supplier, has an obligation to fix vulnerabilities and that the responsibility lies with maintainers [9][10]. - Conversely, the open-source camp, supporting FFmpeg, contends that Google should also contribute by providing patches alongside bug reports, emphasizing the strain on volunteer developers [12][13]. Group 5: Historical Context - This conflict is not unprecedented; similar frustrations have been voiced by other open-source maintainers, such as Nick Wellnhofer from libxml2, who highlighted the pressure from Google Project Zero [16]. - The article references the XZ Utils incident, where over-reliance on a few volunteers led to significant security risks, underscoring the vulnerabilities in the open-source ecosystem [16][18]. Group 6: Broader Implications - The ongoing debate highlights the fragile nature of the internet's foundational infrastructure, which often relies on a small number of volunteers, raising concerns about sustainability and security in the face of increasing bug reports from AI tools [17][18].
突发!黄仁勋断言中国赢得 AI 竞赛,拆解 2 个关键优势还戳穿西方困境
程序员的那些事· 2025-11-08 01:47
Core Viewpoint - The CEO of Nvidia, Jensen Huang, stated that China will win the AI competition, highlighting the advantages of China's regulatory environment and lower energy costs as key factors in this assertion [5][6]. Group 1: China's Key Advantages - China benefits from a more favorable regulatory environment, which is described as "efficient and agile," providing certainty for AI industry development. In contrast, Western countries are mired in skepticism and regulatory hurdles that may stifle innovation [8]. - Lower energy costs in China are a significant advantage for AI development, as data centers, which are crucial for AI operations, incur high energy expenses. Huang emphasized that Chinese tech giants can maintain AI operations at lower costs due to substantial energy subsidies [8][9]. Group 2: Timing and Industry Landscape - Huang's comments came at a critical time following a recent summit between US and Chinese leaders, where discussions on Nvidia's latest Blackwell chip sales to China were not included in the agenda, complicating Nvidia's market strategies [10]. - The rise of China's AI capabilities is evident, with local labs like DeepSeek producing advanced language models that challenge the technological edge of companies like OpenAI and Anthropic [10]. Group 3: Nvidia's Market Dilemma and Interests - Nvidia, which holds over 80% of the global AI chip market, has seen its market share decline from 27% in China to a complete exit due to escalating US export controls [12]. - The company has faced challenges in adapting its product offerings for the Chinese market, including the introduction of downgraded chips and special versions for China, but these efforts have been met with obstacles [12]. - Huang's statements reflect a recognition of China's AI strength and serve as a message to the US government that market openness is essential for mutual benefit, as policies that harm China may ultimately hurt the US [12].
史上最高薪酬诞生!马斯克 1 万亿美元薪酬方案获批,解锁条件堪称“地狱难度”
程序员的那些事· 2025-11-08 01:47
Core Viewpoint - Elon Musk has secured a groundbreaking $1 trillion compensation package from Tesla, which has redefined salary benchmarks in the industry [1][2][3]. Group 1: Compensation Package Details - The compensation plan was approved with over 75% of votes at Tesla's annual shareholder meeting [3]. - The package is structured to unlock in 12 phases, contingent on achieving ambitious performance targets [11][12]. - To fully unlock the compensation, Tesla's market value must increase nearly 8 times to approximately $8.5 trillion, and profits must rise nearly 24 times to reach $400 billion [13]. Group 2: Performance Targets - Key performance metrics include delivering 20 million Tesla vehicles, achieving 10 million active Full Self-Driving (FSD) subscriptions, delivering 1 million Tesla robots, and operating 1 million Robotaxis [13]. - If all targets are met, Musk's stake in Tesla could increase from 13% to about 25%, potentially making him the world's first trillionaire [15][16]. Group 3: Strategic Focus - Alongside automotive goals, Tesla is shifting its strategic focus towards robotics and AI, with a proposal to invest in xAI, Musk's AI startup, gaining traction [6][7]. - Musk believes the robotics industry will surpass the smartphone market in size, indicating a significant future direction for Tesla [8]. Group 4: Challenges Ahead - The ambitious targets set for the robot production highlight the challenges Tesla faces, particularly in achieving precision engineering and large-scale manufacturing [21]. - Musk's confidence in Tesla's unique capabilities in AI and robotics is a driving factor behind his high compensation demands [22]. Group 5: Comparison with Industry Peers - In contrast to Musk's high-stakes compensation, OpenAI's CEO has publicly stated he holds no equity in the company, highlighting a stark difference in compensation strategies within the tech industry [26][27].
IBM 新一轮大裁员!基础设施部门或缩减 50%,30 天内转岗失败就走人
程序员的那些事· 2025-11-07 10:40
Core Viewpoint - IBM is planning to lay off thousands of employees as part of a strategic shift towards AI and software, highlighting a significant change in priorities within the tech industry [1][10]. Group 1: Layoff Details - IBM will cut at least several thousand jobs, affecting less than a single-digit percentage of its global workforce of approximately 270,000 employees, which translates to an estimated 2,700 to 24,300 positions [4][3]. - The layoffs are expected to primarily impact employees in the U.S. infrastructure department, with reports suggesting that this department may see a reduction of nearly 50% [10][4]. - Employees notified of "resource adjustments" will have 30 days to find new positions within the company before being laid off with severance pay [4]. Group 2: Strategic Shift - The layoffs are part of a broader strategic adjustment led by CEO Arvind Krishna, focusing on higher-margin areas such as software and cloud services, including the previously acquired Red Hat [10]. - IBM's software business has shown a 10% year-over-year revenue growth, although the growth rate for Red Hat has slowed, which may be a factor in the restructuring [10]. - The company is reallocating resources to areas with greater growth potential, such as software development and its generative AI platform, watsonx [10]. Group 3: Industry Context - IBM is not alone in this trend; since 2025, the U.S. tech industry has experienced a wave of layoffs as companies shift focus to AI and streamline operations [12]. - Other tech giants, such as Amazon and Meta, have also announced significant layoffs, with Amazon planning to cut 14,000 jobs and Meta reducing 600 positions in its AI department [12][14]. - Despite exceeding financial expectations, IBM's decision to proceed with layoffs underscores a broader industry movement towards operational efficiency and a focus on profitable AI and cloud computing sectors [14].
又上热搜!网友称山姆 APP 支付跳转色情网站。。。
程序员的那些事· 2025-11-07 10:40
Core Viewpoint - The incident involving the Sam's Club app has raised significant concerns among users, particularly regarding potential security vulnerabilities and the company's response to the issue [1][4]. Group 1: Incident Overview - On November 6, a user reported that while attempting to pay with a "Minsheng Sam's Club co-branded credit card," the app redirected them to a pornographic website [1]. - Initial customer service responses suggested that the issue might be due to the user downloading the app from an unverified source, offering a compensation of 30 yuan, which was rejected by the user [2]. Group 2: Company Responses - Following media coverage, Sam's Club acknowledged the incident and indicated that it might be related to DNS hijacking, distancing themselves from direct responsibility [3]. - On November 7, Sam's Club issued a second statement, emphasizing that they take the feedback seriously and that their technical team believes the issue is likely due to network hijacking attacks on the user's device. They committed to enhancing security measures and stated that they had not received other similar complaints [4]. Group 3: Public Reaction - User comments on social media suggested that the issue might be attributed to the internet service provider rather than Sam's Club, with some users humorously blaming the incident on the company's management [5].
再见 Office!国际刑事法院放弃微软,转向开源
程序员的那些事· 2025-11-07 03:42
Core Viewpoint - The International Criminal Court (ICC) has decided to abandon Microsoft Office in favor of the German-developed open-source office system, openDesk, due to concerns over digital sovereignty and the risk of being cut off by U.S. authorities [3][10]. Group 1: Background and Trigger Events - The decision was prompted by a March 2024 incident where the U.S. government sanctioned ICC officials, leading to the freezing of the ICC Chief Prosecutor's Microsoft email account, raising alarms about digital dependency on U.S. companies [5]. - Following this incident, the ICC's IT department reassessed its entire technology stack, identifying reliance on U.S. suppliers as a significant risk [5][6]. Group 2: Features of openDesk - openDesk is an open-source office and collaboration platform developed under the German government's Digital Sovereignty Center (ZenDiS), designed to be a European alternative to Microsoft 365 [6]. - The platform has three key features that differentiate it from Microsoft: 1. Open-source transparency with all code hosted on Germany's OpenCoDE platform, allowing for public auditing [7]. 2. Modular architecture with components provided by eight European software companies, allowing for flexible customization [8]. 3. Data sovereignty, with all data stored on European servers and protected by European laws, thus avoiding U.S. Cloud Act constraints [9]. Group 3: Broader Trends in Europe - The ICC's move reflects a broader trend of "de-Microsoftization" across Europe, driven by concerns over technological independence and geopolitical risks [10]. - Several European countries have initiated similar transitions: - In April 2024, Schleswig-Holstein, Germany, announced the migration of over 30,000 accounts from Microsoft to Linux and LibreOffice [11]. - In May 2025, Denmark's Digital Affairs Ministry plans to completely stop using Microsoft products [12]. - In September 2025, the Austrian military announced its switch from Microsoft Office to LibreOffice [13]. - These transitions signify a strategic shift in Europe towards ensuring that critical systems remain under local control, even at the cost of higher expenses and operational challenges [10][14]. Group 4: Implications for Microsoft - The ICC's decision not only results in a loss of a client but also signifies a loss of trust in U.S. technology companies among European institutions [10]. - The move by the ICC sends a strong message to other government entities regarding the potential risks of relying on U.S. technology, particularly in sensitive areas like international law and security [10]. - Microsoft's response emphasizes its commitment to the ICC, but the credibility of such assurances may be questioned in light of recent events [10].
哈哈!台湾投诚 APP 火了,还能一键呼叫解放军。网友:起初还以为是恶搞软件…
程序员的那些事· 2025-11-07 03:42
Group 1 - The article discusses the emergence of various versions of a satirical "Taiwan Loyalty APP" created by netizens, which has sparked discussions in Taiwan and among people on the mainland [1][2] - The spokesperson for the Taiwan Affairs Office, Zhang Han, responded on November 5, stating that the software is merely a personal creation by netizens and does not exist as a real application, reflecting the strong desire for reunion and unification among compatriots on both sides [2] Group 2 - Initial perceptions of the APP were that it was a joke, but as discussions progressed, it gained more traction and seriousness among users [4] - The article includes user comments and interactions, indicating a mix of humor and political sentiment surrounding the concept of the APP [4]
美国一软件巨头撤出中国,解雇 400 名员工,赔偿 N+2
程序员的那些事· 2025-11-06 11:06
Core Points - SAS Institute has completely withdrawn from the Chinese market after 25 years of operation, laying off all 400 employees [1][4] - The decision was announced on October 30 via internal email and a brief video conference, described as a result of "organizational optimization" [3][4] - SAS will continue to operate in China through third-party partners despite ceasing direct business operations [4] Summary by Sections Company Operations - SAS Institute has ceased all direct business operations in China, marking a significant shift in its global operational strategy aimed at optimizing business layout for long-term sustainability [4] - The company has laid off all 400 employees in China, requiring them to sign a departure agreement by November 14 [4] Employee Compensation - Employees will receive compensation based on their years of service, including N+2 months' salary, year-end bonuses, and salaries up to the end of 2025 [4] Company Background - SAS Institute, founded in 1976 and headquartered in Cary, North Carolina, provides comprehensive solutions in data management, statistical analysis, predictive modeling, data mining, and business intelligence [5] - The company entered the Chinese market in 1999 and established a research and support center in Beijing in 2005, previously recognized as one of China's "Best Employers" for 17 consecutive years [5]
趣图:做一个APP,接入微信支付,主要功能仿摇一摇,只要用户摇一下,他的微信零钱都…
程序员的那些事· 2025-11-06 02:11
Group 1 - The article discusses a concept for an app that integrates WeChat Pay, allowing users to transfer their WeChat balance to the app owner's account by simply shaking their device [1] - The idea is presented as a potentially innovative approach to facilitate transactions through a gamified experience [1] Group 2 - The article includes humorous illustrations and commentary, suggesting a light-hearted take on the challenges faced by startups [3][4][5][6] - The visuals serve to engage readers while highlighting the struggles and creativity often associated with new business ventures [3][4][5][6]
华硕向腾讯致歉
程序员的那些事· 2025-11-06 02:11
Core Viewpoint - ASUS issued an apology to Tencent Games Security ACE for a misleading video that raised concerns about software safety and computer performance among players [1][2]. Group 1: Incident Overview - ASUS removed the controversial video and is conducting an internal investigation to address management lapses regarding content creation and verification processes [2][3]. - The misleading video claimed that the ACE anti-cheat system caused significant memory usage and performance issues, including game lag and potential system crashes [5]. Group 2: Response and Future Actions - ASUS plans to implement a stricter multi-level content review mechanism to ensure the accuracy and truthfulness of published content and will take disciplinary action against responsible personnel [3][5]. - Tencent Games Security acknowledged ASUS's apology and expressed a desire to continue collaborating for the healthy development of the gaming industry and public discourse [3][5]. Group 3: Background on ACE - Tencent's ACE is a comprehensive security solution for games, having evolved from an early anti-cheat system to cover various protective functions, including anti-cheat, content safety, and economic security [5]. - ACE serves hundreds of games and over 700 million players, with partnerships for developing security solutions for popular titles [5].