Sign up

davewiner's subscription list, hackerNewsStars category. List created by feedlandDatabase v0.9.1.

An external list from lists.opml.org.
https://lists.opml.org/hackerNewsStars.xml

Simon Willison's Weblog Supports Webmention

The Design & Implementation of Sprites

The Design & Implementation of Sprites I wrote about Sprites last week Here's Thomas Ptacek from Fly with the insider details on how they work under the hood. I like this framing of them as "disposable computers": Sprites are ball-point disposable computers. Whatever ma...

Jeff Geerling
• Jeff Geerling

Raspberry Pi's new AI HAT adds 8GB of RAM for local LLMs

Raspberry Pi AI HAT+ 2

Today Raspberry Pi launched their new $130 AI HAT+ 2 which includes a Hailo 10H and 8 GB of LPDDR4X RAM.

With that, the Hailo 10H is capable of running LLMs entirely standalone, freeing the Pi's CPU and system RAM for other tasks. The chip runs at a maximum of 3W, with 40 TOPS of INT8 NPU inference performance in addition to the equivalent 26 TOPS INT4 machine vision performance on the earlier AI HAT with Hailo 8.

Simon Willison's Weblog Supports Webmention

Quoting Boaz Barak, Gabriel Wu, Jeremy Chen and Manas Joglekar

When we optimize responses using a reward model as a proxy for “goodness” in reinforcement learning, models sometimes learn to “hack” this proxy and output an answer that only “looks good” to it (because coming up with an answer that is actually good can be hard). The philos...

Simon Willison's Weblog Supports Webmention

Claude Cowork Exfiltrates Files

Claude Cowork Exfiltrates Files

Claude Cowork defaults to allowing outbound HTTP traffic to only a specific list of domains, to help protect the user against prompt injection attacks that exfiltrate their data.

Prompt Armor found a creative workaround: Anthropic's API domain is on that list, so they constructed an attack that includes an attacker's own Anthropic API key and has the agent upload any files it can see to the https://api.anthropic.com/v1/files endpoint, allowing the attacker to retrieve their content later.

Via Hacker News

Tags: security, ai, prompt-injection, generative-ai, llms, anthropic, exfiltration-attacks, ai-agents, claude-code, lethal-trifecta

Computer Things Supports Webmention

My Gripes with Prolog

Pluralistic: Daily links from Cory Doctorow
• Cory Doctorow

Pluralistic: It's not normal (14 Jan 2026)

Today's links It's not normal: Remember when you owned stuff? Hey look at this: Delights to delectate. Object permanence: Telco rats out protesters; Rogers v Net Neutrality; Jailhouse lawyer v Stingrays; Black Panther self-care. Upcoming appearances: Where to find me. Recent ...

Krebs on Security
• BrianKrebs

Patch Tuesday, January 2026 Edition

Microsoft today issued patches to plug at least 113 security holes in its various Windows operating systems and supported software. Eight of the vulnerabilities earned Microsoft's most-dire "critical" rating, and the company warns that attackers are already exploiting one of the bugs fixed today.

Simon Willison's Weblog Supports Webmention

Anthropic invests $1.5 million in the Python Software Foundation and open source security

Anthropic invests $1.5 million in the Python Software Foundation and open source security This is outstanding news, especially given our decision to withdraw from that NSF grant application back in October. We are thrilled to announce that Anthropic has entered into a two-y...

Simon Willison's Weblog Supports Webmention

TIL from taking Neon I at the Crucible

TIL from taking Neon I at the Crucible

Things I learned about making neon signs after a week long intensive evening class at the Crucible in Oakland.

Tags: art, til

Fabien Sanglard

Building a 1997 Quake PC: Benchmarking GLquake

Pluralistic: Daily links from Cory Doctorow
• Cory Doctorow

Pluralistic: Sorry, eh (13 Jan 2026)

Today's links Sorry, eh: I sincerely regret that all my ideas will not lose billions of dollars, destroy jobs or make your country more dependent on American tech. Hey look at this: Delights to delectate. Object permanence: 20 years a blogger; Woz on Network Neutrality; Moveo...

Troy Hunt Supports Webmention
• Troy Hunt

Who Decides Who Doesn’t Deserve Privacy?

Who Decides Who Doesn’t Deserve Privacy?

Remember the Ashley Madison data breach? That was now more than a decade ago, yet it arguably remains the single most noteworthy data breach of all time. There are many reasons for this accolade, but chief among them is that by virtue of the site being expressly designed to facilitate

Keygen Blog

SaaS is not dead

On the fundamentals of build vs buy.

Anil Dash Valid

How to know if that job will crush your soul Last week, we talked about one huge question, “How the hell are you supposed to have a career in tech in 2026?” That’s pretty specific to this current moment, but there are some timeless, more perennial questions I've been sharing...

Fabien Sanglard

Building a 1997 Quake PC: Benchmarking Vquake

Dr Paris Buttfield-Addison

Why We Don't Use AI

My company Yarn Spinner published a post today explaining why we don’t use AI and won’t be adding it to our products.

The TL;DR:

AI companies make tools for hurting people and we don’t want to support that.

From the post:

If you look at what AI companies promote now, it’s not what we wanted. When you boil down everything they say and strip it right back, what they make are tools to either fire people or demand more work without hiring anyone new to help. That’s the problem AI companies want to solve.

Tom Renner on My place to put things Supports Webmention
• Tom Renner

LLMs are a 400-year-long confidence trick

In 1623 the German Wilhelm Schickard produced the first known designs for a mechanical calculator. Twenty years later Blaise Pascal produced a machine of an improved design, aiming to help with the large amount of tedious arithmetic required in his role as a tax collector. T...

Simon Willison's Weblog Supports Webmention

Superhuman AI Exfiltrates Emails

Superhuman AI Exfiltrates Emails

Classic prompt injection attack:

When asked to summarize the user’s recent mail, a prompt injection in an untrusted email manipulated Superhuman AI to submit content from dozens of other sensitive emails (including financial, legal, and medical information) in the user’s inbox to an attacker’s Google Form.

To Superhuman's credit they treated this as the high priority incident it is and issued a fix.

The root cause was a CSP rule that allowed markdown images to be loaded from docs.google.com - it turns out Google Forms on that domain will persist data fed to them via a GET request!

Via Hacker News

Tags: security, ai, prompt-injection, generative-ai, llms, exfiltration-attacks, content-security-policy

Simon Willison's Weblog Supports Webmention

First impressions of Claude Cowork, Anthropic's general agent

New from Anthropic today is Claude Cowork, a "research preview" that they describe as "Claude Code for the rest of your work". It's currently available only to Max subscribers ($100 or $200 per month plans) as part of the updated Claude Desktop macOS application. I've been s...

Anil Dash Valid

How to know if that job will crush your soul

Last week, we talked about one huge question, “How the hell are you supposed to have a career in tech in 2026?” That’s pretty specific to this current moment, but there are some timeless, more perennial questions I've been sharing with friends for years that I wanted to give...