<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Gea-Suan Lin&#039;s BLOG</title>
	<atom:link href="https://blog.gslin.org/feed/" rel="self" type="application/rss+xml" />
	<link>https://blog.gslin.org</link>
	<description>幹壞事是進步最大的原動力</description>
	<lastBuildDate>Wed, 02 Sep 2026 09:16:02 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1</generator>
<atom:link rel="hub" href="https://pubsubhubbub.appspot.com"/>
<atom:link rel="hub" href="https://pubsubhubbub.superfeedr.com"/>
<atom:link rel="hub" href="https://websubhub.com/hub"/>
<atom:link rel="self" href="https://blog.gslin.org/feed/"/>
<site xmlns="com-wordpress:feed-additions:1">21326247</site>	<item>
		<title>經濟部的商工登記公示資料查詢系統有 permalink 了</title>
		<link>https://blog.gslin.org/archives/2026/09/02/13178/%e7%b6%93%e6%bf%9f%e9%83%a8%e7%9a%84%e5%95%86%e5%b7%a5%e7%99%bb%e8%a8%98%e5%85%ac%e7%a4%ba%e8%b3%87%e6%96%99%e6%9f%a5%e8%a9%a2%e7%b3%bb%e7%b5%b1%e6%9c%89-permalink-%e4%ba%86/</link>
					<comments>https://blog.gslin.org/archives/2026/09/02/13178/%e7%b6%93%e6%bf%9f%e9%83%a8%e7%9a%84%e5%95%86%e5%b7%a5%e7%99%bb%e8%a8%98%e5%85%ac%e7%a4%ba%e8%b3%87%e6%96%99%e6%9f%a5%e8%a9%a2%e7%b3%bb%e7%b5%b1%e6%9c%89-permalink-%e4%ba%86/#respond</comments>
		
		<dc:creator><![CDATA[Gea-Suan Lin]]></dc:creator>
		<pubDate>Wed, 02 Sep 2026 09:16:02 +0000</pubDate>
				<category><![CDATA[Computer]]></category>
		<category><![CDATA[Murmuring]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Search Engine]]></category>
		<category><![CDATA[WWW]]></category>
		<category><![CDATA[engine]]></category>
		<category><![CDATA[findbiz]]></category>
		<category><![CDATA[optimization]]></category>
		<category><![CDATA[search]]></category>
		<category><![CDATA[seo]]></category>
		<category><![CDATA[taiwan]]></category>
		<guid isPermaLink="false">https://blog.gslin.org/?p=13178</guid>

					<description><![CDATA[以前拿統編直接去搜尋引擎找，都會找到第三方蒐集的網站，不過前幾天找資料的時候發現在經濟部的系統上面有固定的 permalink 可以用了，像是 https://findbiz.nat.gov.tw/fts/company/53011857 這樣的網址： 算是 SEO 大進步 (?)，值得記錄一下...]]></description>
										<content:encoded><![CDATA[<p>以前拿統編直接去搜尋引擎找，都會找到第三方蒐集的網站，不過前幾天找資料的時候發現在經濟部的系統上面有固定的 permalink 可以用了，像是 <a href="https://findbiz.nat.gov.tw/fts/company/53011857">https://findbiz.nat.gov.tw/fts/company/53011857</a> 這樣的網址：</p>
<picture><source type="image/webp" srcset="https://i.gslin.com/s/1788340372-3c338194.webp" /><img decoding="async" src="https://i.gslin.com/s/1788340372-3c338194.png" alt="" /></picture>
<p>算是 <a href="https://en.wikipedia.org/wiki/Search_engine_optimization">SEO</a> 大進步 (?)，值得記錄一下...</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.gslin.org/archives/2026/09/02/13178/%e7%b6%93%e6%bf%9f%e9%83%a8%e7%9a%84%e5%95%86%e5%b7%a5%e7%99%bb%e8%a8%98%e5%85%ac%e7%a4%ba%e8%b3%87%e6%96%99%e6%9f%a5%e8%a9%a2%e7%b3%bb%e7%b5%b1%e6%9c%89-permalink-%e4%ba%86/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">13178</post-id>	</item>
		<item>
		<title>Mozilla 推出了殘廢版的 Ad Blocker for Firefox on iOS</title>
		<link>https://blog.gslin.org/archives/2026/09/02/13177/mozilla-%e6%8e%a8%e5%87%ba%e4%ba%86%e6%ae%98%e5%bb%a2%e7%89%88%e7%9a%84-ad-blocker-for-firefox-on-ios/</link>
					<comments>https://blog.gslin.org/archives/2026/09/02/13177/mozilla-%e6%8e%a8%e5%87%ba%e4%ba%86%e6%ae%98%e5%bb%a2%e7%89%88%e7%9a%84-ad-blocker-for-firefox-on-ios/#respond</comments>
		
		<dc:creator><![CDATA[Gea-Suan Lin]]></dc:creator>
		<pubDate>Wed, 02 Sep 2026 07:07:21 +0000</pubDate>
				<category><![CDATA[Browser]]></category>
		<category><![CDATA[Computer]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Murmuring]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[OS]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[ad]]></category>
		<category><![CDATA[advertisement]]></category>
		<category><![CDATA[blocker]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[ios]]></category>
		<category><![CDATA[mozilla]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">https://blog.gslin.org/?p=13177</guid>

					<description><![CDATA[看到「Introducing Ad Blocker for Firefox on iOS: More Control, Fewer Distractions (via)」這個，裡面開頭： Ad Blocker won’t block every ad. Ads served directly by the site you’re visiting and ads shown in search results will still appear. 這什麼殘廢... 寧可用 Safari 搭 Raymond Hill 的 uBlock Origin Lite 就好。]]></description>
										<content:encoded><![CDATA[<p>看到「<a href="https://blog.mozilla.org/en/firefox/ad-blocker-on-ios/">Introducing Ad Blocker for Firefox on iOS: More Control, Fewer Distractions</a> (<a href="https://news.ycombinator.com/item?id=49521973">via</a>)」這個，裡面開頭：</p>
<blockquote><p>Ad Blocker won’t block every ad. Ads served directly by the site you’re visiting and ads shown in search results will still appear.</p></blockquote>
<p>這什麼殘廢... 寧可用 <a href="https://en.wikipedia.org/wiki/Safari_(web_browser)">Safari</a> 搭 <a href="https://en.wikipedia.org/wiki/Raymond_Hill">Raymond Hill</a> 的 <a href="https://apps.apple.com/us/app/ublock-origin-lite/id6745342698">uBlock Origin Lite</a> 就好。</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.gslin.org/archives/2026/09/02/13177/mozilla-%e6%8e%a8%e5%87%ba%e4%ba%86%e6%ae%98%e5%bb%a2%e7%89%88%e7%9a%84-ad-blocker-for-firefox-on-ios/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">13177</post-id>	</item>
		<item>
		<title>Fable 5.1 的改善</title>
		<link>https://blog.gslin.org/archives/2026/09/02/13176/fable-5-1-%e7%9a%84%e6%94%b9%e5%96%84/</link>
					<comments>https://blog.gslin.org/archives/2026/09/02/13176/fable-5-1-%e7%9a%84%e6%94%b9%e5%96%84/#respond</comments>
		
		<dc:creator><![CDATA[Gea-Suan Lin]]></dc:creator>
		<pubDate>Wed, 02 Sep 2026 06:58:28 +0000</pubDate>
				<category><![CDATA[API]]></category>
		<category><![CDATA[Computer]]></category>
		<category><![CDATA[Murmuring]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Service]]></category>
		<category><![CDATA[5.1]]></category>
		<category><![CDATA[ai]]></category>
		<category><![CDATA[anthropic]]></category>
		<category><![CDATA[cache]]></category>
		<category><![CDATA[cost]]></category>
		<category><![CDATA[fable]]></category>
		<category><![CDATA[language]]></category>
		<category><![CDATA[large]]></category>
		<category><![CDATA[llm]]></category>
		<category><![CDATA[model]]></category>
		<category><![CDATA[opus]]></category>
		<category><![CDATA[pricing]]></category>
		<category><![CDATA[read]]></category>
		<guid isPermaLink="false">https://blog.gslin.org/?p=13176</guid>

					<description><![CDATA[Anthropic 推出 Fable 5.1：「Introducing Claude Fable 5.1 and Claude Mythos 5.1 (via)」。 最直接的改善是 cache read 降價的部分，從本來的 $1 變成 $0.25 (Mtokens)： As mentioned above, we have reduced the price of Fable 5.1’s cache reads (where the model reuses context it has already processed) wherever usage is billed by token, such as on our API. Cache reads &#8230; <a href="https://blog.gslin.org/archives/2026/09/02/13176/fable-5-1-%e7%9a%84%e6%94%b9%e5%96%84/" class="more-link">Continue reading<span class="screen-reader-text"> "Fable 5.1 的改善"</span></a>]]></description>
										<content:encoded><![CDATA[<p><a href="https://en.wikipedia.org/wiki/Anthropic">Anthropic</a> 推出 Fable 5.1：「<a href="https://www.anthropic.com/claude-fable-and-mythos-5-1">Introducing Claude Fable 5.1 and Claude Mythos 5.1</a> (<a href="https://news.ycombinator.com/item?id=49525378">via</a>)」。</p>
<p>最直接的改善是 cache read 降價的部分，從本來的 $1 變成 $0.25 (Mtokens)：</p>
<blockquote><p>As mentioned above, we have reduced the price of Fable 5.1’s cache reads (where the model reuses context it has already processed) wherever usage is billed by token, such as on our API. Cache reads now cost 75% less, or $0.25 per million tokens.</p></blockquote>
<p>如果去看 Opus 5 的 cache read 會發現也還要 $0.5，所以這次的降價預期會蠻有感的，尤其是對 coding agent 這種一直 append context 的行為，所以官方的估算給了對應的下降：</p>
<picture><source type="image/webp" srcset="https://i.gslin.com/s/1788331928-93ef5a1f.webp" /><img decoding="async" src="https://i.gslin.com/s/1788331928-93ef5a1f.png" alt="" /></picture>
<p>但這樣可以預期過不久後也會更新 Opus？</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.gslin.org/archives/2026/09/02/13176/fable-5-1-%e7%9a%84%e6%94%b9%e5%96%84/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">13176</post-id>	</item>
		<item>
		<title>實際跑 iOS kernel 的 vphone-cli</title>
		<link>https://blog.gslin.org/archives/2026/09/01/13175/%e5%af%a6%e9%9a%9b%e8%b7%91-ios-kernel-%e7%9a%84-vphone-cli/</link>
					<comments>https://blog.gslin.org/archives/2026/09/01/13175/%e5%af%a6%e9%9a%9b%e8%b7%91-ios-kernel-%e7%9a%84-vphone-cli/#respond</comments>
		
		<dc:creator><![CDATA[Gea-Suan Lin]]></dc:creator>
		<pubDate>Tue, 01 Sep 2026 13:01:50 +0000</pubDate>
				<category><![CDATA[Computer]]></category>
		<category><![CDATA[Murmuring]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[amfi]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[cli]]></category>
		<category><![CDATA[ios]]></category>
		<category><![CDATA[kernel]]></category>
		<category><![CDATA[mac]]></category>
		<category><![CDATA[macos]]></category>
		<category><![CDATA[simulator]]></category>
		<category><![CDATA[sip]]></category>
		<category><![CDATA[vphone]]></category>
		<category><![CDATA[xcode]]></category>
		<guid isPermaLink="false">https://blog.gslin.org/?p=13175</guid>

					<description><![CDATA[之前開發 iOS app 會用 Xcode Simulator，不過這個方式已知不是完全模擬 iOS 環境，而是 macOS 的 kernel 包出來的。 這次看到的 vphone-cli 專案 (via) 則是把 iOS kernel 包進來了： Boot a virtual iPhone via Apple's Virtualization.framework using PCC research VM infrastructure. 除了會比較吃資源以外 (可以預想到的)，另外一個缺點是需要放寬 SIP 與 AMFI (AppleMobileFileIntegrity)。 FAQ 的地方有個有趣的事情，模擬環境需要選擇 United States，不能選日本或是歐盟，因為這些地區的 system apps 會有額外的檢查，在 vphone-cli 裡面不會過： System apps won't install — during iOS setup, &#8230; <a href="https://blog.gslin.org/archives/2026/09/01/13175/%e5%af%a6%e9%9a%9b%e8%b7%91-ios-kernel-%e7%9a%84-vphone-cli/" class="more-link">Continue reading<span class="screen-reader-text"> "實際跑 iOS kernel 的 vphone-cli"</span></a>]]></description>
										<content:encoded><![CDATA[<p>之前開發 <a href="https://en.wikipedia.org/wiki/IOS">iOS</a> app 會用 <a href="https://en.wikipedia.org/wiki/Xcode">Xcode</a> Simulator，不過這個方式已知不是完全模擬 iOS 環境，而是 macOS 的 kernel 包出來的。</p>
<p>這次看到的 <a href="https://github.com/Lakr233/vphone-cli">vphone-cli</a> 專案 (<a href="https://news.ycombinator.com/item?id=49485267">via</a>) 則是把 iOS kernel 包進來了：</p>
<blockquote><p>Boot a virtual iPhone via Apple's Virtualization.framework using PCC research VM infrastructure.</p></blockquote>
<p>除了會比較吃資源以外 (可以預想到的)，另外一個缺點是需要放寬 <a href="https://en.wikipedia.org/wiki/System_Integrity_Protection">SIP</a> 與 AMFI (AppleMobileFileIntegrity)。</p>
<p>FAQ 的地方有個有趣的事情，模擬環境需要選擇 United States，不能選日本或是歐盟，因為這些地區的 system apps 會有額外的檢查，在 vphone-cli 裡面不會過：</p>
<blockquote><p>System apps won't install — during iOS setup, don't pick Japan or the EU as your region (extra regulatory checks the VM can't satisfy); pick e.g. United States.</p></blockquote>
<p>一般開發應該還是用 Xcode Simulator 就可以了，這種應該是要拿來測試比較底層的系統互動，或是研究核心？</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.gslin.org/archives/2026/09/01/13175/%e5%af%a6%e9%9a%9b%e8%b7%91-ios-kernel-%e7%9a%84-vphone-cli/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">13175</post-id>	</item>
		<item>
		<title>git.kernel.org 被 AI bot 掃的情況</title>
		<link>https://blog.gslin.org/archives/2026/09/01/13173/git-kernel-org-%e8%a2%ab-ai-bot-%e6%8e%83%e7%9a%84%e6%83%85%e6%b3%81/</link>
					<comments>https://blog.gslin.org/archives/2026/09/01/13173/git-kernel-org-%e8%a2%ab-ai-bot-%e6%8e%83%e7%9a%84%e6%83%85%e6%b3%81/#respond</comments>
		
		<dc:creator><![CDATA[Gea-Suan Lin]]></dc:creator>
		<pubDate>Tue, 01 Sep 2026 04:41:41 +0000</pubDate>
				<category><![CDATA[Computer]]></category>
		<category><![CDATA[Murmuring]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[WWW]]></category>
		<guid isPermaLink="false">https://blog.gslin.org/?p=13173</guid>

					<description><![CDATA[昨天看到的，git.kernel.org 也是被 AI bot 掃：「Creepy crawlies (via)」。 依照作者的說法，目前放在 5 個區域的 git.kernel.org 有超過一半的 CPU resources 都在服務 crawler： 然後也提到現在 AI bot 在掃都是透過 residential proxy，而且都戳沒幾下，所以以前傳統的方法都沒什麼用 (像是 firewall、rate limit 這種方式)，到後來還是上了 PoW 類的 Anubis 來擋，一開始 difficulty=4 的時候馬上就有效，而有些使用者會反應，但勉強可以忍受： It was immediately extremely effective — the bots just gave up. For a few months, it was bliss: bots were blocked at the &#8230; <a href="https://blog.gslin.org/archives/2026/09/01/13173/git-kernel-org-%e8%a2%ab-ai-bot-%e6%8e%83%e7%9a%84%e6%83%85%e6%b3%81/" class="more-link">Continue reading<span class="screen-reader-text"> "git.kernel.org 被 AI bot 掃的情況"</span></a>]]></description>
										<content:encoded><![CDATA[<p>昨天看到的，<a href="https://git.kernel.org/">git.kernel.org</a> 也是被 AI bot 掃：「<a href="https://people.kernel.org/monsieuricon/creepy-crawlies">Creepy crawlies</a> (<a href="https://news.ycombinator.com/item?id=49491791">via</a>)」。</p>
<p>依照作者的說法，目前放在 5 個區域的 git.kernel.org 有超過一半的 CPU resources 都在服務 crawler：</p>
<picture><source type="image/webp" srcset="https://i.gslin.com/s/1788236611-74ae8750.webp" /><img decoding="async" src="https://i.gslin.com/s/1788236611-74ae8750.png" alt="" /></picture>
<p>然後也提到現在 AI bot 在掃都是透過 residential proxy，而且都戳沒幾下，所以以前傳統的方法都沒什麼用 (像是 firewall、rate limit 這種方式)，到後來還是上了 <a href="https://en.wikipedia.org/wiki/Proof_of_work">PoW</a> 類的 <a href="https://en.wikipedia.org/wiki/Anubis_(software)">Anubis</a> 來擋，一開始 difficulty=4 的時候馬上就有效，而有些使用者會反應，但勉強可以忍受：</p>
<blockquote><p>It was immediately extremely effective — the bots just gave up. For a few months, it was bliss: bots were blocked at the perimeter and gave up, moving on to easier targets; the users were mildly annoyed but tolerated it, and the Anubis stack was easy enough to deploy everywhere.</p></blockquote>
<p>後來 bot 開始也解 difficulty=4 的情況了，站方拉到 5 後有改善，但就有更多使用者反應變慢很多，尤其是手機上：</p>
<blockquote><p>A few months later, the bots were back, solving difficulty 4. No problem, we said, let's raise difficulty to 5.</p>
<p>The legitimate users were more annoyed now. Difficulty 5 takes a few seconds to solve on a mobile device, and the phone gets uncomfortably warm as it's doing the number crunching. However, it was effective and bought us a few more months of peace.</p></blockquote>
<p>結果後來又發現 bot 也開始接受挑戰... 解了 difficulty=5 的情況：</p>
<blockquote><p>Then... the bots started solving difficulty 5.</p></blockquote>
<p>這邊作者有一張 diffiuculty 與裝置分類的組合，所需要 PoW 的計算時間，以及大概可以接受的程度：</p>
<picture><source type="image/webp" srcset="https://i.gslin.com/s/1788237158-95576efe.webp" /><img decoding="async" src="https://i.gslin.com/s/1788237158-95576efe.png" alt="" /></picture>
<p>在 <a href="https://en.wikipedia.org/wiki/Hacker_News">Hacker News</a> 上的 <a href="https://news.ycombinator.com/item?id=49500040">id=49500040</a> 這篇則是另外一個面向，他用 <a href="https://en.wikipedia.org/wiki/IPhone_17">iPhone 17</a> 遇到 difficulty=6 的網站時，要跑 180 秒左右，所以他就寫了 C extension 掛進手機的 <a href="https://en.wikipedia.org/wiki/Safari_(web_browser)">Safari</a> 上面，利用硬體指令集大幅加速了這個部分：</p>
<blockquote><p>I noticed the other day that lists.ffmpeg.org had moved to Anubis difficulty level 6, which takes ~180sec for my iPhone 17 to solve at ~100KH/s, making the site unusable. So I spent ~10 minutes vibe coding a safari extension with a native bridge to an optimized C kernel using ARM SHA256H* instructions that can do 200+ MH/s on the same device. This solves Anubis difficulty level 6 in a handful of milliseconds.</p></blockquote>
<p>回到原來作者的文章，裡面提到這目前是個無解的情境，因為這是整體環境在驅動，一堆新的 AI 公司在抓資料，而一堆 app 為了獲利設計 malware 變成 proxy：</p>
<blockquote><p>Worst of all, there are no simple solutions to the problem. Companies offering custom “AI” models still pop up daily, all of them hungry for training data. App makers are still looking for ways to turn a profit, so they will continue to turn your household appliances into attack vectors.</p></blockquote>
<p>目前這塊的確是沒什麼好的解法，透過技術手段目前也只能緩解... 大概要等泡沫之類的時候才有機會改善？</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.gslin.org/archives/2026/09/01/13173/git-kernel-org-%e8%a2%ab-ai-bot-%e6%8e%83%e7%9a%84%e6%83%85%e6%b3%81/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">13173</post-id>	</item>
		<item>
		<title>Debian 投票通過生成式 AI 的使用方式</title>
		<link>https://blog.gslin.org/archives/2026/09/01/13172/debian-%e6%8a%95%e7%a5%a8%e9%80%9a%e9%81%8e%e7%94%9f%e6%88%90%e5%bc%8f-ai-%e7%9a%84%e4%bd%bf%e7%94%a8%e6%96%b9%e5%bc%8f/</link>
					<comments>https://blog.gslin.org/archives/2026/09/01/13172/debian-%e6%8a%95%e7%a5%a8%e9%80%9a%e9%81%8e%e7%94%9f%e6%88%90%e5%bc%8f-ai-%e7%9a%84%e4%bd%bf%e7%94%a8%e6%96%b9%e5%bc%8f/#respond</comments>
		
		<dc:creator><![CDATA[Gea-Suan Lin]]></dc:creator>
		<pubDate>Tue, 01 Sep 2026 00:34:05 +0000</pubDate>
				<category><![CDATA[Computer]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Murmuring]]></category>
		<category><![CDATA[OS]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[ai]]></category>
		<category><![CDATA[debian]]></category>
		<category><![CDATA[generative]]></category>
		<category><![CDATA[language]]></category>
		<category><![CDATA[large]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[llm]]></category>
		<category><![CDATA[model]]></category>
		<guid isPermaLink="false">https://blog.gslin.org/?p=13172</guid>

					<description><![CDATA[Debian 通過對生成式 AI 的使用方式了：「Results for LLM usage in Debian (via)」。 通過的是「Option 5 "Responsible Use of Generative AI"」，在 Proposal E 的 Choice 5 最後一句可以看到這個方案的結論： The responsibility for every contribution rests with the contributor who submits it, who remains accountable for its technical quality, legal acceptability, and suitability for inclusion in Debian. Hacker News 上的 id=49490252 也把重點抓出來了，重點是人，你送上來就是要對送上來的 &#8230; <a href="https://blog.gslin.org/archives/2026/09/01/13172/debian-%e6%8a%95%e7%a5%a8%e9%80%9a%e9%81%8e%e7%94%9f%e6%88%90%e5%bc%8f-ai-%e7%9a%84%e4%bd%bf%e7%94%a8%e6%96%b9%e5%bc%8f/" class="more-link">Continue reading<span class="screen-reader-text"> "Debian 投票通過生成式 AI 的使用方式"</span></a>]]></description>
										<content:encoded><![CDATA[<p><a href="https://en.wikipedia.org/wiki/Debian">Debian</a> 通過對生成式 AI 的使用方式了：「<a href="https://lwn.net/ml/all/E1x06W1-00AjNI-1i@vento.debian.org/">Results for LLM usage in Debian</a> (<a href="https://news.ycombinator.com/item?id=49489982">via</a>)」。</p>
<p>通過的是「Option 5 "Responsible Use of Generative AI"」，在 <a href="https://www.debian.org/vote/2026/vote_002#texte">Proposal E</a> 的 Choice 5 最後一句可以看到這個方案的結論：</p>
<blockquote><p>The responsibility for every contribution rests with the contributor who submits it, who remains accountable for its technical quality, legal acceptability, and suitability for inclusion in Debian.</p></blockquote>
<p><a href="https://en.wikipedia.org/wiki/Hacker_News">Hacker News</a> 上的 <a href="https://news.ycombinator.com/item?id=49490252">id=49490252</a> 也把重點抓出來了，重點是人，你送上來就是要對送上來的 code 或是文件負責：</p>
<blockquote><p>New policy boils down to "AI or not, it's still your code and you're responsible for it". I can get on board with that.</p></blockquote>
<p>Debian 的治理模式與各種政策的結論在社群裡面算是蠻指標性的存在，這次投票的結論應該也會影響其他 community...</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.gslin.org/archives/2026/09/01/13172/debian-%e6%8a%95%e7%a5%a8%e9%80%9a%e9%81%8e%e7%94%9f%e6%88%90%e5%bc%8f-ai-%e7%9a%84%e4%bd%bf%e7%94%a8%e6%96%b9%e5%bc%8f/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">13172</post-id>	</item>
		<item>
		<title>Google 正式拔掉 Manifest V2 (MV2) 了</title>
		<link>https://blog.gslin.org/archives/2026/09/01/13171/google-%e6%ad%a3%e5%bc%8f%e6%8b%94%e6%8e%89-manifest-v2-mv2-%e4%ba%86/</link>
					<comments>https://blog.gslin.org/archives/2026/09/01/13171/google-%e6%ad%a3%e5%bc%8f%e6%8b%94%e6%8e%89-manifest-v2-mv2-%e4%ba%86/#respond</comments>
		
		<dc:creator><![CDATA[Gea-Suan Lin]]></dc:creator>
		<pubDate>Tue, 01 Sep 2026 00:22:15 +0000</pubDate>
				<category><![CDATA[Browser]]></category>
		<category><![CDATA[Computer]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[GoogleChrome]]></category>
		<category><![CDATA[Murmuring]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[WWW]]></category>
		<category><![CDATA[ad]]></category>
		<category><![CDATA[advertisement]]></category>
		<category><![CDATA[block]]></category>
		<category><![CDATA[blocker]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[chrome]]></category>
		<category><![CDATA[extension]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[manifest]]></category>
		<category><![CDATA[v2]]></category>
		<guid isPermaLink="false">https://blog.gslin.org/?p=13171</guid>

					<description><![CDATA[基於「Manifest V2 support timeline (via)」這邊的 timeline 在 2026/08/31 移除 MV2 了。 拔 MV2 最直接的影響就是 Google 對直接危害廣告本業，看不爽很久的 ad blocker 大幅在技術上限縮能力，把 webRequest 給閹割了。 是有陣營繼續維護 Chromium 平台上的 MV2 extension，但跳 Firefox 應該還是目前中長期比較好的選擇，在 Chromium 平台上的 MV2 webRequest 本身就有各種討厭但刻意不修的 bug，像是我自己之前經常會遇到的幾個問題： 瀏覽器打開時會漏攔截：「Resource loading should be deferred until webRequest extensions have finished loading」。 某些開啟方式會跳過攔截：「onBeforeRequest doesn't intercept HTTP requests from a tab, which is &#8230; <a href="https://blog.gslin.org/archives/2026/09/01/13171/google-%e6%ad%a3%e5%bc%8f%e6%8b%94%e6%8e%89-manifest-v2-mv2-%e4%ba%86/" class="more-link">Continue reading<span class="screen-reader-text"> "Google 正式拔掉 Manifest V2 (MV2) 了"</span></a>]]></description>
										<content:encoded><![CDATA[<p>基於「<a href="https://developer.chrome.com/docs/extensions/develop/migrate/mv2-deprecation-timeline">Manifest V2 support timeline</a> (<a href="https://news.ycombinator.com/item?id=49514878">via</a>)」這邊的 timeline 在 2026/08/31 移除 MV2 了。</p>
<p>拔 MV2 最直接的影響就是 <a href="https://en.wikipedia.org/wiki/Google">Google</a> 對直接危害廣告本業，看不爽很久的 ad blocker 大幅在技術上限縮能力，把 <a href="https://developer.mozilla.org/en-US/docs/Mozilla/Add-ons/WebExtensions/API/webRequest">webRequest</a> 給閹割了。</p>
<p>是有陣營繼續維護 <a href="https://en.wikipedia.org/wiki/Chromium_(web_browser)">Chromium</a> 平台上的 MV2 extension，但跳 <a href="https://en.wikipedia.org/wiki/Firefox">Firefox</a> 應該還是目前中長期比較好的選擇，在 Chromium 平台上的 MV2 webRequest 本身就有各種討厭但刻意不修的 bug，像是我自己之前經常會遇到的幾個問題：</p>
<ul>
<li>瀏覽器打開時會漏攔截：「<a href="https://issues.chromium.org/issues/41196549">Resource loading should be deferred until webRequest extensions have finished loading</a>」。</li>
<li>某些開啟方式會跳過攔截：「<a href="https://issues.chromium.org/issues/41297391">onBeforeRequest doesn't intercept HTTP requests from a tab, which is opened from a browserAction popup iframe</a>」。</li>
</ul>
<p>遷移到 Firefox 成本不算太高，因為比較重要的大功能都「學」過來了，加上現在有 AI 可以問，很多搬遷時想要找的功能都可以透過 AI 直接問出來...</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.gslin.org/archives/2026/09/01/13171/google-%e6%ad%a3%e5%bc%8f%e6%8b%94%e6%8e%89-manifest-v2-mv2-%e4%ba%86/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">13171</post-id>	</item>
		<item>
		<title>中央社開賣 MCP 服務</title>
		<link>https://blog.gslin.org/archives/2026/09/01/13170/%e4%b8%ad%e5%a4%ae%e7%a4%be%e9%96%8b%e8%b3%a3-mcp-%e6%9c%8d%e5%8b%99/</link>
					<comments>https://blog.gslin.org/archives/2026/09/01/13170/%e4%b8%ad%e5%a4%ae%e7%a4%be%e9%96%8b%e8%b3%a3-mcp-%e6%9c%8d%e5%8b%99/#respond</comments>
		
		<dc:creator><![CDATA[Gea-Suan Lin]]></dc:creator>
		<pubDate>Mon, 31 Aug 2026 23:50:08 +0000</pubDate>
				<category><![CDATA[API]]></category>
		<category><![CDATA[Computer]]></category>
		<category><![CDATA[Murmuring]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Service]]></category>
		<category><![CDATA[ai]]></category>
		<category><![CDATA[cna]]></category>
		<category><![CDATA[language]]></category>
		<category><![CDATA[large]]></category>
		<category><![CDATA[llm]]></category>
		<category><![CDATA[model]]></category>
		<category><![CDATA[news]]></category>
		<guid isPermaLink="false">https://blog.gslin.org/?p=13170</guid>

					<description><![CDATA[在 Threads 上看到中央社的這則貼文： 產品頁是 https://ask.cna.com.tw/，看起來打算提供兩個方案，一個是 NT$200/mo 的 MCP 方案，另外一個是 NT$300/mo 的 AI chat 方案 (看起來是幫你接好直接用，不過目前掛 coming soon)。 不過如果這些 MCP 接的都是公開資料的話... 理論上 AI 自己就可以查到了，而且還可以多查其他家的 cross reference，有點微妙？ 我直接拿「查詢1991年李登輝宣布廢止動員戡亂時期臨時條款 當時各界相關討論」這個官方拿出來的範例： 前面加上「請參考中央社的資料。」，然後丟進 Anthropic 的 Claude Opus 5 (High)，可以看到這樣的整理： 如果不加上的話，可以看到 reference 會更散：]]></description>
										<content:encoded><![CDATA[<p>在 <a href="https://en.wikipedia.org/wiki/Threads_(social_network)">Threads</a> 上看到中央社的這則<a href="https://www.threads.com/@cnanews_tw/post/DctCbPmDKSQ">貼文</a>：</p>
<picture><source type="image/webp" srcset="https://i.gslin.com/s/1788218947-6ea7f0ed.webp" /><img decoding="async" src="https://i.gslin.com/s/1788218947-6ea7f0ed.png" alt="" /></picture>
<p>產品頁是 <a href="https://ask.cna.com.tw/">https://ask.cna.com.tw/</a>，看起來打算提供兩個方案，一個是 NT$200/mo 的 <a href="https://en.wikipedia.org/wiki/Model_Context_Protocol">MCP</a> 方案，另外一個是 NT$300/mo 的 AI chat 方案 (看起來是幫你接好直接用，不過目前掛 coming soon)。</p>
<p>不過如果這些 MCP 接的都是公開資料的話... 理論上 AI 自己就可以查到了，而且還可以多查其他家的 cross reference，有點微妙？</p>
<p>我直接拿「查詢1991年李登輝宣布廢止動員戡亂時期臨時條款 當時各界相關討論」這個官方拿出來的範例：</p>
<picture><source type="image/webp" srcset="" /><img decoding="async" src="https://i.gslin.com/s/1788219506-d808a592.png" alt="" /></picture>
<p>前面加上「請參考中央社的資料。」，然後丟進 <a href="https://en.wikipedia.org/wiki/Anthropic">Anthropic</a> 的 Claude Opus 5 (High)，可以看到這樣的整理：</p>
<picture><source type="image/webp" srcset="https://i.gslin.com/s/1788219867-75e4ca74.webp" /><img decoding="async" src="https://i.gslin.com/s/1788219867-75e4ca74.png" alt="" /></picture>
<p>如果不加上的話，可以看到 reference 會更散：</p>
<picture><source type="image/webp" srcset="https://i.gslin.com/s/1788220049-3c011a4d.webp" /><img decoding="async" src="https://i.gslin.com/s/1788220049-3c011a4d.png" alt="" /></picture>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.gslin.org/archives/2026/09/01/13170/%e4%b8%ad%e5%a4%ae%e7%a4%be%e9%96%8b%e8%b3%a3-mcp-%e6%9c%8d%e5%8b%99/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">13170</post-id>	</item>
		<item>
		<title>用 LLM 寫了 Caddy 的 DNSBL 套件</title>
		<link>https://blog.gslin.org/archives/2026/08/30/13169/%e7%94%a8-llm-%e5%af%ab%e4%ba%86-caddy-%e7%9a%84-dnsbl-%e5%a5%97%e4%bb%b6/</link>
					<comments>https://blog.gslin.org/archives/2026/08/30/13169/%e7%94%a8-llm-%e5%af%ab%e4%ba%86-caddy-%e7%9a%84-dnsbl-%e5%a5%97%e4%bb%b6/#respond</comments>
		
		<dc:creator><![CDATA[Gea-Suan Lin]]></dc:creator>
		<pubDate>Sat, 29 Aug 2026 23:13:35 +0000</pubDate>
				<category><![CDATA[Computer]]></category>
		<category><![CDATA[Murmuring]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[WWW]]></category>
		<category><![CDATA[address]]></category>
		<category><![CDATA[ai]]></category>
		<category><![CDATA[caddy]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[dnsbl]]></category>
		<category><![CDATA[filter]]></category>
		<category><![CDATA[filtering]]></category>
		<category><![CDATA[http]]></category>
		<category><![CDATA[https]]></category>
		<category><![CDATA[ip]]></category>
		<category><![CDATA[ipv4]]></category>
		<category><![CDATA[ipv6]]></category>
		<category><![CDATA[language]]></category>
		<category><![CDATA[large]]></category>
		<category><![CDATA[llm]]></category>
		<category><![CDATA[model]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[spam]]></category>
		<guid isPermaLink="false">https://blog.gslin.org/?p=13169</guid>

					<description><![CDATA[之前在「Caddy 上用 DNSBL 擋 bot」這邊提過透過 DNSBL 的方式阻擋一些 bot，裡面提到的 https://git.madhouse-project.org/caddy/http.matchers.dnsbl 不見了，在 GitHub 上也沒找到，想了一下乾脆讓 LLM 實作一套出來，順便把觀察到的一些問題處理掉，成果丟在 https://github.com/gslin/caddy-http-matchers-dnsbl2 這邊，基本的用法跟之前類似： wiki.gslin.org { @badactors dnsbl2 { providers "b.barracudacentral.org." "spam.spamrats.com." } respond @badactors 403 } 這邊用 dnsbl2 是避免跟之前的套件撞名字，但又不知道怎麼取，就先這樣... 其他的用法可以參考 GitHub 上面的 README.md 範例，主要是多了對 DNSBL 的回答判斷，以及自己的 cache 控制。 算是先補回來一些簡單的東西...]]></description>
										<content:encoded><![CDATA[<p>之前在「<a href="https://blog.gslin.org/archives/2025/07/04/12498/caddy-%E4%B8%8A%E7%94%A8-dnsbl-%E6%93%8B-bot/">Caddy 上用 DNSBL 擋 bot</a>」這邊提過透過 <a href="https://en.wikipedia.org/wiki/Domain_Name_System_blocklist">DNSBL</a> 的方式阻擋一些 bot，裡面提到的 <a href="https://git.madhouse-project.org/caddy/http.matchers.dnsbl">https://git.madhouse-project.org/caddy/http.matchers.dnsbl</a> 不見了，在 <a href="https://en.wikipedia.org/wiki/GitHub">GitHub</a> 上也沒找到，想了一下乾脆讓 <a href="https://en.wikipedia.org/wiki/Large_language_model">LLM</a> 實作一套出來，順便把觀察到的一些問題處理掉，成果丟在 <a href="https://github.com/gslin/caddy-http-matchers-dnsbl2">https://github.com/gslin/caddy-http-matchers-dnsbl2</a> 這邊，基本的用法跟之前類似：</p>
<pre>wiki.gslin.org {
        @badactors dnsbl2 {
                providers "b.barracudacentral.org." "spam.spamrats.com."
        }
        respond @badactors 403
}</pre>
<p>這邊用 dnsbl2 是避免跟之前的套件撞名字，但又不知道怎麼取，就先這樣...</p>
<p>其他的用法可以參考 GitHub 上面的 README.md 範例，主要是多了對 DNSBL 的回答判斷，以及自己的 cache 控制。</p>
<p>算是先補回來一些簡單的東西...</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.gslin.org/archives/2026/08/30/13169/%e7%94%a8-llm-%e5%af%ab%e4%ba%86-caddy-%e7%9a%84-dnsbl-%e5%a5%97%e4%bb%b6/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">13169</post-id>	</item>
		<item>
		<title>PHP 8 上的 Taint</title>
		<link>https://blog.gslin.org/archives/2026/08/29/13168/php-8-%e4%b8%8a%e7%9a%84-taint/</link>
					<comments>https://blog.gslin.org/archives/2026/08/29/13168/php-8-%e4%b8%8a%e7%9a%84-taint/#respond</comments>
		
		<dc:creator><![CDATA[Gea-Suan Lin]]></dc:creator>
		<pubDate>Sat, 29 Aug 2026 05:41:46 +0000</pubDate>
				<category><![CDATA[Computer]]></category>
		<category><![CDATA[Murmuring]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[ai]]></category>
		<category><![CDATA[jit]]></category>
		<category><![CDATA[language]]></category>
		<category><![CDATA[large]]></category>
		<category><![CDATA[laruence]]></category>
		<category><![CDATA[llm]]></category>
		<category><![CDATA[max]]></category>
		<category><![CDATA[model]]></category>
		<category><![CDATA[php]]></category>
		<category><![CDATA[php5]]></category>
		<category><![CDATA[php7]]></category>
		<category><![CDATA[php8]]></category>
		<category><![CDATA[qwen]]></category>
		<category><![CDATA[qwen3.8]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[taint]]></category>
		<category><![CDATA[tainted]]></category>
		<category><![CDATA[variable]]></category>
		<guid isPermaLink="false">https://blog.gslin.org/?p=13168</guid>

					<description><![CDATA[Taint checking 是一種在 runtime 時檢查資料安全性的技巧，很久前在 Perl 上有看過 (維基百科上也是給 Perl 的例子)，把外部讀入的資料當作是 tainted variable (被污染的變數)，直接用到這個變數而產生的變數也當作 tainted variable，直到「處理」後的衍生變數才標為正常的變數，這樣就可以在 i/o 端把 tainted variable 攔截下來。 最經典的就是 XSS 或是 SQL injection 了，像是這樣就會繼承污染值： $sql = "INSERT INTO foo SET bar = $input_a"; 後來不太流行這樣的方法，主要是這個方式不能保證就一定沒問題，加上有其他方式可以處理 (像是 code review 與 static program analysis)，但畢竟就是有這個玩法... 在「Taint支持PHP8啦！」這邊看到中國的鳥哥 (Laruence) 之前在 2012 年時對 PHP 5.2 寫了第一版，然後一路到 PHP 7 都還有支援，直到 PHP &#8230; <a href="https://blog.gslin.org/archives/2026/08/29/13168/php-8-%e4%b8%8a%e7%9a%84-taint/" class="more-link">Continue reading<span class="screen-reader-text"> "PHP 8 上的 Taint"</span></a>]]></description>
										<content:encoded><![CDATA[<p><a href="https://en.wikipedia.org/wiki/Taint_checking">Taint checking</a> 是一種在 runtime 時檢查資料安全性的技巧，很久前在 <a href="https://en.wikipedia.org/wiki/Perl">Perl</a> 上有看過 (維基百科上也是給 Perl 的例子)，把外部讀入的資料當作是 tainted variable (被污染的變數)，直接用到這個變數而產生的變數也當作 tainted variable，直到「處理」後的衍生變數才標為正常的變數，這樣就可以在 i/o 端把 tainted variable 攔截下來。</p>
<p>最經典的就是 <a href="https://en.wikipedia.org/wiki/Cross-site_scripting">XSS</a> 或是 <a href="https://en.wikipedia.org/wiki/SQL_injection">SQL injection</a> 了，像是這樣就會繼承污染值：</p>
<pre>$sql = "INSERT INTO foo SET bar = $input_a";</pre>
<p>後來不太流行這樣的方法，主要是這個方式不能保證就一定沒問題，加上有其他方式可以處理 (像是 <a href="https://en.wikipedia.org/wiki/Code_review">code review</a> 與 <a href="https://en.wikipedia.org/wiki/Static_program_analysis">static program analysis</a>)，但畢竟就是有這個玩法...</p>
<p>在「<a href="https://www.laruence.com/2026/08/07/6340.html">Taint支持PHP8啦！</a>」這邊看到中國的鳥哥 (Laruence) 之前在 2012 年時對 <a href="https://en.wikipedia.org/wiki/PHP">PHP</a> 5.2 寫了第一版，然後一路到 PHP 7 都還有支援，直到 PHP 8 的時候他認為因為 PHP 內部結構的變化，變得難以維護了：</p>
<blockquote><p>但是，到了PHP8以后，因为JIT的引入，和大量内部结构的改写，我觉得要迁移的成本实在是太大，太难，甚至觉得不太可能了。因为原来的标记我们是保存在GC_FLAGS里面，而到PHP8.0以后，已经没有任何一个bit是可用的了。再加上，这些bits是非常内部的，也就是说如果要维护这个扩展可用，我需要随时监控对这些bits的使用，发现破坏就需要调整。</p></blockquote>
<p>而這篇看起來是拿 <a href="https://huggingface.co/Qwen/Qwen3.8-2.4T-A95B">Qwen3.8-2.4T-A95B</a>，直接叫 <a href="https://en.wikipedia.org/wiki/Large_language_model">LLM</a> 移植到 PHP 8 上面，結果就順利輾了過去的記錄，最終大約是消耗了 200M tokens，大約 US$60 左右：</p>
<blockquote><p>全程耗时接近5个小时，今天一共消耗了2亿Token（当然其中有点其他工作，但应该影响不大），花费406RMB，客观讲这个消耗量有点大，2000多行的项目来说，大量的Token应该消耗在了理解PHP庞大的代码库内的各种细节吧，后续类似的项目应该有很大提升空间。</p></blockquote>
<p>之後應該會有愈來愈多這樣的例子，尤其是「你知道大概可行，但想到要分析與實作的規模就覺得懶」的情境...</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.gslin.org/archives/2026/08/29/13168/php-8-%e4%b8%8a%e7%9a%84-taint/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">13168</post-id>	</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Object Caching 40/52 objects using APC
Page Caching using APC (Page is feed) 
Minified using APC
Database Caching using APC

Served from: blog.gslin.org @ 2026-09-02 17:30:35 by W3 Total Cache
-->