<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Gea-Suan Lin&#039;s BLOG</title>
	<atom:link href="https://blog.gslin.org/feed/" rel="self" type="application/rss+xml" />
	<link>https://blog.gslin.org</link>
	<description>幹壞事是進步最大的原動力</description>
	<lastBuildDate>Fri, 11 Sep 2026 18:05:06 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1</generator>
<atom:link rel="hub" href="https://pubsubhubbub.appspot.com"/>
<atom:link rel="hub" href="https://pubsubhubbub.superfeedr.com"/>
<atom:link rel="hub" href="https://websubhub.com/hub"/>
<atom:link rel="self" href="https://blog.gslin.org/feed/"/>
<site xmlns="com-wordpress:feed-additions:1">21326247</site>	<item>
		<title>OpenRouter 的用法</title>
		<link>https://blog.gslin.org/archives/2026/09/12/13197/openrouter-%e7%9a%84%e7%94%a8%e6%b3%95/</link>
					<comments>https://blog.gslin.org/archives/2026/09/12/13197/openrouter-%e7%9a%84%e7%94%a8%e6%b3%95/#respond</comments>
		
		<dc:creator><![CDATA[Gea-Suan Lin]]></dc:creator>
		<pubDate>Fri, 11 Sep 2026 18:05:06 +0000</pubDate>
				<category><![CDATA[API]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Computer]]></category>
		<category><![CDATA[Murmuring]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Service]]></category>
		<category><![CDATA[ai]]></category>
		<category><![CDATA[language]]></category>
		<category><![CDATA[large]]></category>
		<category><![CDATA[llm]]></category>
		<category><![CDATA[model]]></category>
		<category><![CDATA[openrouter]]></category>
		<category><![CDATA[provider]]></category>
		<category><![CDATA[service]]></category>
		<guid isPermaLink="false">https://blog.gslin.org/?p=13197</guid>

					<description><![CDATA[這篇講 OpenRouter 意外的熱門：「So you want to use OpenRouter? (via)」。 我以為不同 provider 會有不同的行為是常識，但看起來作者以及很多 Hacker News 上的人並不曉得？ OpenRouter 對 developing 階段很有用，因為你只要儲值一次就可以用很多不同的 model (以及 provider)，對公司來說可以省掉大量的採購成本；而當要上到 production 的時候最好直接找對應的一兩個 provider (看要不要考慮備援) 談 commitment (如果量夠大的話)。 我是想不太到拿 OpenRouter 當 production 的理由...]]></description>
										<content:encoded><![CDATA[<p>這篇講 <a href="https://en.wikipedia.org/wiki/OpenRouter">OpenRouter</a> 意外的熱門：「<a href="https://mmoustafa.com/blog/so-you-want-to-use-openrouter/">So you want to use OpenRouter?</a> (<a href="https://news.ycombinator.com/item?id=49621546">via</a>)」。</p>
<p>我以為不同 provider 會有不同的行為是常識，但看起來作者以及很多 <a href="https://en.wikipedia.org/wiki/Hacker_News">Hacker News</a> 上的人並不曉得？</p>
<p>OpenRouter 對 developing 階段很有用，因為你只要儲值一次就可以用很多不同的 model (以及 provider)，對公司來說可以省掉大量的採購成本；而當要上到 production 的時候最好直接找對應的一兩個 provider (看要不要考慮備援) 談 commitment (如果量夠大的話)。</p>
<p>我是想不太到拿 OpenRouter 當 production 的理由...</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.gslin.org/archives/2026/09/12/13197/openrouter-%e7%9a%84%e7%94%a8%e6%b3%95/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">13197</post-id>	</item>
		<item>
		<title>Matt Mullenweg 被董事會從 Automattic 拉下來</title>
		<link>https://blog.gslin.org/archives/2026/09/11/13196/matt-mullenweg-%e8%a2%ab%e8%91%a3%e4%ba%8b%e6%9c%83%e5%be%9e-automattic-%e6%8b%89%e4%b8%8b%e4%be%86/</link>
					<comments>https://blog.gslin.org/archives/2026/09/11/13196/matt-mullenweg-%e8%a2%ab%e8%91%a3%e4%ba%8b%e6%9c%83%e5%be%9e-automattic-%e6%8b%89%e4%b8%8b%e4%be%86/#respond</comments>
		
		<dc:creator><![CDATA[Gea-Suan Lin]]></dc:creator>
		<pubDate>Fri, 11 Sep 2026 09:18:06 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[CMS]]></category>
		<category><![CDATA[Computer]]></category>
		<category><![CDATA[Murmuring]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[automattic]]></category>
		<category><![CDATA[matt]]></category>
		<category><![CDATA[mullenweg]]></category>
		<category><![CDATA[wordpress]]></category>
		<guid isPermaLink="false">https://blog.gslin.org/?p=13196</guid>

					<description><![CDATA[看到 Matt Mullenweg (WordPress 的共同創始人) 被 Automattic 董事會拉了下來的消息：「Automattic’s board forces CEO Matt Mullenweg into leave of absence (via)」。 從 2024 年後就有許多爭議，當時整理了一些記錄：「Automattic 與 WP Engine 打架中」、「WPEngine 拿到對 Automattic 的初步禁制令了」。 後續也有些外部團體開始改善 Automattic 對 WordPress 的獨斷問題：「Linux Foundation 宣佈獨立的 WordPress 基礎建設：FAIR Package Manager Project」。 這次是董事會強制 Matt Mullenweg 帶薪休假，然後 CFO Mark Davies 接任 Interim CEO，目前資訊還有點少，包括董事會的說法也還沒出來，尤其是看 Matt Mullenweg 的說法，會想要找律師幹架？]]></description>
										<content:encoded><![CDATA[<p>看到 <a href="https://en.wikipedia.org/wiki/Matt_Mullenweg">Matt Mullenweg</a> (<a href="https://en.wikipedia.org/wiki/WordPress">WordPress</a> 的共同創始人) 被 <a href="https://en.wikipedia.org/wiki/Automattic">Automattic</a> 董事會拉了下來的消息：「<a href="https://techcrunch.com/2026/09/09/automattics-board-forces-ceo-matt-mullenweg-into-leave-of-absence/">Automattic’s board forces CEO Matt Mullenweg into leave of absence</a> (<a href="https://news.ycombinator.com/item?id=49636283">via</a>)」。</p>
<p>從 2024 年後就有許多爭議，當時整理了一些記錄：「<a href="https://blog.gslin.org/archives/2024/09/26/12003/automattic-%e8%88%87-wp-engine-%e6%89%93%e6%9e%b6%e4%b8%ad/">Automattic 與 WP Engine 打架中</a>」、「<a href="https://blog.gslin.org/archives/2024/12/11/12116/wpengine-%E6%8B%BF%E5%88%B0%E5%B0%8D-automattic-%E7%9A%84%E5%88%9D%E6%AD%A5%E7%A6%81%E5%88%B6%E4%BB%A4%E4%BA%86/">WPEngine 拿到對 Automattic 的初步禁制令了</a>」。</p>
<p>後續也有些外部團體開始改善 Automattic 對 WordPress 的獨斷問題：「<a href="https://blog.gslin.org/archives/2025/06/07/12442/linux-foundation-%E5%AE%A3%E4%BD%88%E7%8D%A8%E7%AB%8B%E7%9A%84-wordpress-%E5%9F%BA%E7%A4%8E%E5%BB%BA%E8%A8%AD%EF%BC%9Afair-package-manager-project/">Linux Foundation 宣佈獨立的 WordPress 基礎建設：FAIR Package Manager Project</a>」。</p>
<p>這次是董事會強制 Matt Mullenweg 帶薪休假，然後 CFO Mark Davies 接任 Interim CEO，目前資訊還有點少，包括董事會的說法也還沒出來，尤其是看 Matt Mullenweg 的說法，會想要找律師幹架？</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.gslin.org/archives/2026/09/11/13196/matt-mullenweg-%e8%a2%ab%e8%91%a3%e4%ba%8b%e6%9c%83%e5%be%9e-automattic-%e6%8b%89%e4%b8%8b%e4%be%86/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">13196</post-id>	</item>
		<item>
		<title>Shopify 買 Tailwind Labs</title>
		<link>https://blog.gslin.org/archives/2026/09/10/13195/shopify-%e8%b2%b7-tailwind-labs/</link>
					<comments>https://blog.gslin.org/archives/2026/09/10/13195/shopify-%e8%b2%b7-tailwind-labs/#respond</comments>
		
		<dc:creator><![CDATA[Gea-Suan Lin]]></dc:creator>
		<pubDate>Thu, 10 Sep 2026 06:37:47 +0000</pubDate>
				<category><![CDATA[Computer]]></category>
		<category><![CDATA[CSS]]></category>
		<category><![CDATA[Financial]]></category>
		<category><![CDATA[Library]]></category>
		<category><![CDATA[Murmuring]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[WWW]]></category>
		<category><![CDATA[acquire]]></category>
		<category><![CDATA[acquisition]]></category>
		<category><![CDATA[ai]]></category>
		<category><![CDATA[exit]]></category>
		<category><![CDATA[labs]]></category>
		<category><![CDATA[language]]></category>
		<category><![CDATA[large]]></category>
		<category><![CDATA[llm]]></category>
		<category><![CDATA[model]]></category>
		<category><![CDATA[shopify]]></category>
		<category><![CDATA[tailwind]]></category>
		<category><![CDATA[tailwindcss]]></category>
		<guid isPermaLink="false">https://blog.gslin.org/?p=13195</guid>

					<description><![CDATA[看到 Shopify 買 Tailwind Labs (Tailwind CSS) 的消息：「Tailwind Labs is joining Shopify (via)」。 以為之前有寫，但沒找到 (大概是寫一寫自己覺得不滿意又刪掉了)，年初的時候 Tailwind Labs 大幅裁員的消息，這邊引 Hacker News 上的連結：「Creators of Tailwind laid off 75% of their engineering team (github.com/tailwindlabs)」，當時提到 AI 年代用 Tailwind CSS 的人愈來愈多，但 revenue 愈來愈少。 其實大概可以預期到，所謂的「附加價值」的產品，在 AI 年代用 token 就可以換出來了，先不說費用的問題，少跑採購的行政流程省太多時間... 雖然後續有些新消息，像是 Google 這邊有 sponsor：(https://x.com/OfficialLoganK/status/2009339263251566902 &#38; via) 不過這些沒有解決掉本質上的問題，這次被 Shopify 併購算是個還可以的 exit 吧...]]></description>
										<content:encoded><![CDATA[<p>看到 <a href="https://en.wikipedia.org/wiki/Shopify">Shopify</a> 買 Tailwind Labs (<a href="https://en.wikipedia.org/wiki/Tailwind_CSS">Tailwind CSS</a>) 的消息：「<a href="https://tailwindcss.com/blog/tailwind-is-joining-shopify">Tailwind Labs is joining Shopify</a> (<a href="https://news.ycombinator.com/item?id=49626190">via</a>)」。</p>
<p>以為之前有寫，但沒找到 (大概是寫一寫自己覺得不滿意又刪掉了)，年初的時候 Tailwind Labs 大幅裁員的消息，這邊引 <a href="https://en.wikipedia.org/wiki/Hacker_News">Hacker News</a> 上的連結：「<a href="https://news.ycombinator.com/item?id=46527950">Creators of Tailwind laid off 75% of their engineering team (github.com/tailwindlabs)</a>」，當時提到 AI 年代用 Tailwind CSS 的人愈來愈多，但 revenue 愈來愈少。</p>
<p>其實大概可以預期到，所謂的「附加價值」的產品，在 AI 年代用 token 就可以換出來了，先不說費用的問題，少跑採購的行政流程省太多時間...</p>
<p>雖然後續有些新消息，像是 <a href="https://en.wikipedia.org/wiki/Google">Google</a> 這邊有 sponsor：(<a href="https://x.com/OfficialLoganK/status/2009339263251566902">https://x.com/OfficialLoganK/status/2009339263251566902</a> &amp; <a href="https://news.ycombinator.com/item?id=46545077">via</a>)</p>
<picture><source type="image/webp" srcset="https://i.gslin.com/s/1789021877-4d267e5d.webp" /><img decoding="async" src="https://i.gslin.com/s/1789021877-4d267e5d.png" alt="" /></picture>
<p>不過這些沒有解決掉本質上的問題，這次被 Shopify 併購算是個還可以的 <a href="https://en.wikipedia.org/wiki/Exit_(investing)">exit</a> 吧...</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.gslin.org/archives/2026/09/10/13195/shopify-%e8%b2%b7-tailwind-labs/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">13195</post-id>	</item>
		<item>
		<title>解開 RSA-260 的 Eric Lu (Cognition) 解釋過程</title>
		<link>https://blog.gslin.org/archives/2026/09/10/13194/%e8%a7%a3%e9%96%8b-rsa-260-%e7%9a%84-eric-lu-cognition-%e8%a7%a3%e9%87%8b%e9%81%8e%e7%a8%8b/</link>
					<comments>https://blog.gslin.org/archives/2026/09/10/13194/%e8%a7%a3%e9%96%8b-rsa-260-%e7%9a%84-eric-lu-cognition-%e8%a7%a3%e9%87%8b%e9%81%8e%e7%a8%8b/#respond</comments>
		
		<dc:creator><![CDATA[Gea-Suan Lin]]></dc:creator>
		<pubDate>Thu, 10 Sep 2026 05:06:42 +0000</pubDate>
				<category><![CDATA[Computer]]></category>
		<category><![CDATA[Hardware]]></category>
		<category><![CDATA[Murmuring]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[1024]]></category>
		<category><![CDATA[260]]></category>
		<category><![CDATA[cognition]]></category>
		<category><![CDATA[eric]]></category>
		<category><![CDATA[factorisation]]></category>
		<category><![CDATA[gnfs]]></category>
		<category><![CDATA[gpu]]></category>
		<category><![CDATA[lu]]></category>
		<category><![CDATA[math]]></category>
		<category><![CDATA[mathematics]]></category>
		<category><![CDATA[prime]]></category>
		<category><![CDATA[rsa]]></category>
		<category><![CDATA[rsa-260]]></category>
		<guid isPermaLink="false">https://blog.gslin.org/?p=13194</guid>

					<description><![CDATA[官方的解釋出來了：「Factoring RSA-260 (via)」，跟「RSA-260 的一些其他消息」這邊提到的差不多，就是透過 GPU 加速 GNFS 演算法： RSA-260 was factored by a new implementation of the general number field sieve (GNFS) for GPUs, prepared and run using Devin. 也是透過 AI 去跑的： At August 13th 0:11:58 Pacific time I aimed Devin at producing a drop-in replacement for las, the CPU lattice siever of CADO-NFS. Here &#8230; <a href="https://blog.gslin.org/archives/2026/09/10/13194/%e8%a7%a3%e9%96%8b-rsa-260-%e7%9a%84-eric-lu-cognition-%e8%a7%a3%e9%87%8b%e9%81%8e%e7%a8%8b/" class="more-link">Continue reading<span class="screen-reader-text"> "解開 RSA-260 的 Eric Lu (Cognition) 解釋過程"</span></a>]]></description>
										<content:encoded><![CDATA[<p>官方的解釋出來了：「<a href="https://cognition.com/blog/factoring-rsa-260">Factoring RSA-260</a> (<a href="https://news.ycombinator.com/item?id=49633534">via</a>)」，跟「<a href="https://blog.gslin.org/archives/2026/09/08/13192/rsa-260-%e7%9a%84%e4%b8%80%e4%ba%9b%e5%85%b6%e4%bb%96%e6%b6%88%e6%81%af/">RSA-260 的一些其他消息</a>」這邊提到的差不多，就是透過 <a href="https://en.wikipedia.org/wiki/Graphics_processing_unit">GPU</a> 加速 <a href="https://en.wikipedia.org/wiki/General_number_field_sieve">GNFS</a> 演算法：</p>
<blockquote><p>RSA-260 was factored by a new implementation of the general number field sieve (GNFS) for GPUs, prepared and run using Devin.</p></blockquote>
<p>也是透過 AI 去跑的：</p>
<blockquote><p>At August 13th 0:11:58 Pacific time I aimed Devin at producing a drop-in replacement for las, the CPU lattice siever of CADO-NFS. Here is the prompt I used[.]</p></blockquote>
<p>然後用了 13.5 GPU-year，比當初 Steve Weis 分析的 25 GPU-year 少了蠻多的：</p>
<blockquote><p>In total, I estimate that this factorization cost about 4,900 GPU-days, or 13.5 GPU-years, which is about $400k at current market prices.</p></blockquote>
<p>另外大家也都同樣的算出 1024-bit RSA 的問題，另外也有提到即使是現在的版本，也應該還有蠻多可以改善的空間：</p>
<blockquote><p>RSA-1024 is equivalent to 309 digits; according to standard GNFS scaling this is merely 78x more computation than RSA-260. I estimate the cost of factoring RSA-1024 at market GPU prices to be roughly $30M, which can trade off against wall clock time. I know for a fact that the current implementation remains significantly suboptimal; I would not be surprised if moderate further work could reduce the cost of factoring RSA-1024 by another multiple of 2.</p></blockquote>
<p>比較好奇的反而是 GPU 版本的 GNFS 一直都沒人 porting，直到 AI 時代才有人跳進去...</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.gslin.org/archives/2026/09/10/13194/%e8%a7%a3%e9%96%8b-rsa-260-%e7%9a%84-eric-lu-cognition-%e8%a7%a3%e9%87%8b%e9%81%8e%e7%a8%8b/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">13194</post-id>	</item>
		<item>
		<title>RSA-260 的一些其他消息</title>
		<link>https://blog.gslin.org/archives/2026/09/08/13192/rsa-260-%e7%9a%84%e4%b8%80%e4%ba%9b%e5%85%b6%e4%bb%96%e6%b6%88%e6%81%af/</link>
					<comments>https://blog.gslin.org/archives/2026/09/08/13192/rsa-260-%e7%9a%84%e4%b8%80%e4%ba%9b%e5%85%b6%e4%bb%96%e6%b6%88%e6%81%af/#comments</comments>
		
		<dc:creator><![CDATA[Gea-Suan Lin]]></dc:creator>
		<pubDate>Tue, 08 Sep 2026 12:27:30 +0000</pubDate>
				<category><![CDATA[Computer]]></category>
		<category><![CDATA[Murmuring]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[ai]]></category>
		<category><![CDATA[factorisation]]></category>
		<category><![CDATA[gpu]]></category>
		<category><![CDATA[integer]]></category>
		<category><![CDATA[language]]></category>
		<category><![CDATA[large]]></category>
		<category><![CDATA[llm]]></category>
		<category><![CDATA[math]]></category>
		<category><![CDATA[mathematics]]></category>
		<category><![CDATA[model]]></category>
		<category><![CDATA[prime]]></category>
		<category><![CDATA[rsa]]></category>
		<category><![CDATA[rsa-260]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[speed]]></category>
		<guid isPermaLink="false">https://blog.gslin.org/?p=13192</guid>

					<description><![CDATA[前幾天提到的「RSA-260 被解開」後來在 social network 上面看到一些討論，包括也有其他競爭對手也進入到最後階段：(https://x.com/sweis/status/2095383966387974616) 已知 RSA-250 (829 bits) 用了 2700 core-year，現在估算 RSA-260 (862 bits) 大約會是 3400～4100 core-year。所以大家都用了類似的方法：問 AI 工具看有沒有加速的機會，結果大家都得到用 GPU 加速的答案，估算可以大幅降到 25 GPU-year。 Steve Weis 問了 Anthropic，得到了兩個禮拜 1024 GPU 的資源開幹，如果跑滿的話大約是 39 GPU-year，不過就被其他人先完成了。 另外他也提到 RSA-1024 (1024 bits) 估算大約是 2000 GPU-year，以目前上的了檯面的任何一家 AI 公司應該都是輕鬆愉快。(https://x.com/sweis/status/2095570645505700165)]]></description>
										<content:encoded><![CDATA[<p>前幾天提到的「<a href="https://blog.gslin.org/archives/2026/09/05/13182/rsa-260-%e8%a2%ab%e8%a7%a3%e9%96%8b/">RSA-260 被解開</a>」後來在 social network 上面看到一些討論，包括也有其他競爭對手也進入到最後階段：(<a href="https://x.com/sweis/status/2095383966387974616">https://x.com/sweis/status/2095383966387974616</a>)</p>
<picture><source type="image/webp" srcset="https://i.gslin.com/s/1788869705-3185a949.webp" /><img decoding="async" src="https://i.gslin.com/s/1788869705-3185a949.png" alt="" /></picture>
<p>已知 RSA-250 (829 bits) 用了 2700 core-year，現在估算 RSA-260 (862 bits) 大約會是 3400～4100 core-year。所以大家都用了類似的方法：問 AI 工具看有沒有加速的機會，結果大家都得到用 GPU 加速的答案，估算可以大幅降到 25 GPU-year。</p>
<p>Steve Weis 問了 <a href="https://en.wikipedia.org/wiki/Anthropic">Anthropic</a>，得到了兩個禮拜 1024 GPU 的資源開幹，如果跑滿的話大約是 39 GPU-year，不過就被其他人先完成了。</p>
<p>另外他也提到 RSA-1024 (1024 bits) 估算大約是 2000 GPU-year，以目前上的了檯面的任何一家 AI 公司應該都是輕鬆愉快。(<a href="https://x.com/sweis/status/2095570645505700165">https://x.com/sweis/status/2095570645505700165</a>)</p>
<picture><source type="image/webp" srcset="https://i.gslin.com/s/1788869835-c4919e35.webp" /><img decoding="async" src="https://i.gslin.com/s/1788869835-c4919e35.png" alt="" /></picture>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.gslin.org/archives/2026/09/08/13192/rsa-260-%e7%9a%84%e4%b8%80%e4%ba%9b%e5%85%b6%e4%bb%96%e6%b6%88%e6%81%af/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">13192</post-id>	</item>
		<item>
		<title>AI 公司狂掃各種可能可以當作訓練資料的材料 (這次是破產的航空公司？)</title>
		<link>https://blog.gslin.org/archives/2026/09/07/13188/ai-%e5%85%ac%e5%8f%b8%e7%8b%82%e6%8e%83%e5%90%84%e7%a8%ae%e5%8f%af%e8%83%bd%e5%8f%af%e4%bb%a5%e7%95%b6%e4%bd%9c%e8%a8%93%e7%b7%b4%e8%b3%87%e6%96%99%e7%9a%84%e6%9d%90%e6%96%99-%e9%80%99%e6%ac%a1/</link>
					<comments>https://blog.gslin.org/archives/2026/09/07/13188/ai-%e5%85%ac%e5%8f%b8%e7%8b%82%e6%8e%83%e5%90%84%e7%a8%ae%e5%8f%af%e8%83%bd%e5%8f%af%e4%bb%a5%e7%95%b6%e4%bd%9c%e8%a8%93%e7%b7%b4%e8%b3%87%e6%96%99%e7%9a%84%e6%9d%90%e6%96%99-%e9%80%99%e6%ac%a1/#respond</comments>
		
		<dc:creator><![CDATA[Gea-Suan Lin]]></dc:creator>
		<pubDate>Mon, 07 Sep 2026 08:54:09 +0000</pubDate>
				<category><![CDATA[Computer]]></category>
		<category><![CDATA[Murmuring]]></category>
		<category><![CDATA[Social]]></category>
		<category><![CDATA[ai]]></category>
		<category><![CDATA[airplane]]></category>
		<category><![CDATA[book]]></category>
		<category><![CDATA[company]]></category>
		<category><![CDATA[culture]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[fair]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[language]]></category>
		<category><![CDATA[large]]></category>
		<category><![CDATA[llm]]></category>
		<category><![CDATA[model]]></category>
		<category><![CDATA[paper]]></category>
		<category><![CDATA[plane]]></category>
		<category><![CDATA[training]]></category>
		<category><![CDATA[use]]></category>
		<guid isPermaLink="false">https://blog.gslin.org/?p=13188</guid>

					<description><![CDATA[看到「Google buys crashed airline Spirit’s data at auction, because AI (via)」這個，Google 買破產的航空公司的資料拿來當訓練材料，已經瘋狂到極致了... 去年 (2025) 六月的時候 Anthropic 的官司是「買紙本書掃屬於合法使用 (fair use)，但透過盜版網站取得的不合法」，這算是認定 fair use 的重要判決： Anthropic wins a major fair use victory for AI — but it’s still in trouble for stealing books Anthropic cut up millions of used books to train Claude — and downloaded over 7 &#8230; <a href="https://blog.gslin.org/archives/2026/09/07/13188/ai-%e5%85%ac%e5%8f%b8%e7%8b%82%e6%8e%83%e5%90%84%e7%a8%ae%e5%8f%af%e8%83%bd%e5%8f%af%e4%bb%a5%e7%95%b6%e4%bd%9c%e8%a8%93%e7%b7%b4%e8%b3%87%e6%96%99%e7%9a%84%e6%9d%90%e6%96%99-%e9%80%99%e6%ac%a1/" class="more-link">Continue reading<span class="screen-reader-text"> "AI 公司狂掃各種可能可以當作訓練資料的材料 (這次是破產的航空公司？)"</span></a>]]></description>
										<content:encoded><![CDATA[<p>看到「<a href="https://www.theregister.com/ai-and-ml/2026/08/18/google-buys-crashed-airline-spirits-data-at-auction-because-ai/5288962">Google buys crashed airline Spirit’s data at auction, because AI</a> (<a href="https://news.ycombinator.com/item?id=49343559">via</a>)」這個，<a href="https://en.wikipedia.org/wiki/Google">Google</a> 買破產的航空公司的資料拿來當訓練材料，已經瘋狂到極致了...</p>
<p>去年 (2025) 六月的時候 <a href="https://en.wikipedia.org/wiki/Anthropic">Anthropic</a> 的官司是「買紙本書掃屬於合法使用 (fair use)，但透過盜版網站取得的不合法」，這算是認定 fair use 的重要判決：</p>
<ul>
<li><a href="https://www.theverge.com/news/692015/anthropic-wins-a-major-fair-use-victory-for-ai-but-its-still-in-trouble-for-stealing-books">Anthropic wins a major fair use victory for AI — but it’s still in trouble for stealing books</a></li>
<li><a href="https://www.businessinsider.com/anthropic-cut-pirated-millions-used-books-train-claude-copyright-2025-6">Anthropic cut up millions of used books to train Claude — and downloaded over 7 million pirated ones too, a judge said</a></li>
</ul>
<p>再來是今年年初揭露出來的 Project Panama，也是 Anthropic，在講一樣的事情：</p>
<ul>
<li><a href="https://www.washingtonpost.com/technology/2026/01/27/anthropic-ai-scan-destroy-books/">Inside an AI start-up’s plan to scan and dispose of millions of books</a> (<a href="https://archive.is/QPbTE">archive</a>)</li>
</ul>
<p>然後是今年七月後就一直有報導，二手書大量被買，導致絕版書被掃，然後被破壞掉：</p>
<ul>
<li><a href="https://www.tomshardware.com/tech-industry/artificial-intelligence/ai-companies-are-reportedly-shredding-millions-of-books-to-train-models-tech-giants-outsource-to-middlemen-to-secretly-buy-up-books-for-training-material">AI companies are reportedly shredding millions of books after using them to train AI models — tech giants outsource to middlemen to secretly buy up books for training material</a></li>
<li><a href="https://www.techspot.com/news/113277-ai-firms-quietly-buying-destroying-millions-printed-books.html">AI firms are quietly buying and destroying millions of printed books to train their models</a></li>
<li><a href="https://www.theatlantic.com/technology/2026/08/ai-companies-buying-used-books-for-data/688167/">Someone Is Mysteriously Snapping Up Used Books Around the World</a></li>
<li><a href="https://www.theguardian.com/technology/2026/aug/15/uk-ireland-booksellers-suspect-ai-companies-bulk-orders-data-acquisition">Secondhand booksellers in UK and Ireland suspect AI firms behind ‘strange’ bulk orders</a></li>
<li><a href="https://www.bbc.com/news/articles/cp3rprx2wl4o">Secondhand book sales are booming. Is it because of AI?</a></li>
<li><a href="https://www.cbc.ca/news/canada/canadian-book-stores-bulk-orders-ai-training-9.7311882">Used bookstores navigate 'suspicious' bulk orders amid AI book-shredding fears</a></li>
</ul>
<p>另外一波新消息是 <a href="https://en.wikipedia.org/wiki/404_Media">404 Media</a> 的人把 <a href="https://en.wikipedia.org/wiki/AirTag">AirTag</a> 塞進稀有書，然後追到 <a href="https://en.wikipedia.org/wiki/Amazon_(company)">Amazon</a> 的倉庫：(曾經是賣書主業的 Amazon...)</p>
<p>(這邊因為 404 Media 的內容都需要付費，所以抓其他媒體的報導資訊)</p>
<ul>
<li><a href="https://www.npr.org/2026/08/19/nx-s1-5936438/why-tech-companies-are-buying-up-tons-of-rare-old-books-to-train-their-ai-models">Why tech companies are buying up tons of rare old books to train their AI models</a></li>
<li><a href="https://arstechnica.com/tech-policy/2026/08/hidden-airtag-reveals-amazon-is-trashing-rare-books-to-train-ai/">Hidden Airtag reveals Amazon is trashing rare books to train AI</a></li>
<li><a href="https://www.forbes.com/sites/maryroeloffs/2026/08/17/ai-companies-are-buying-and-destroying-antique-books-heres-why/">AI Companies Are Buying—And Destroying—Antique Books. Here’s Why.</a></li>
</ul>
<p>看到 AI 公司對各種資料的情況，回頭看 Google 跑去買破產航空公司的資料，只覺得 WTF...</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.gslin.org/archives/2026/09/07/13188/ai-%e5%85%ac%e5%8f%b8%e7%8b%82%e6%8e%83%e5%90%84%e7%a8%ae%e5%8f%af%e8%83%bd%e5%8f%af%e4%bb%a5%e7%95%b6%e4%bd%9c%e8%a8%93%e7%b7%b4%e8%b3%87%e6%96%99%e7%9a%84%e6%9d%90%e6%96%99-%e9%80%99%e6%ac%a1/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">13188</post-id>	</item>
		<item>
		<title>LLM 在 GitHub PR 上的詞彙頻率</title>
		<link>https://blog.gslin.org/archives/2026/09/07/13187/llm-%e5%9c%a8-github-pr-%e4%b8%8a%e7%9a%84%e8%a9%9e%e5%bd%99%e9%a0%bb%e7%8e%87/</link>
					<comments>https://blog.gslin.org/archives/2026/09/07/13187/llm-%e5%9c%a8-github-pr-%e4%b8%8a%e7%9a%84%e8%a9%9e%e5%bd%99%e9%a0%bb%e7%8e%87/#respond</comments>
		
		<dc:creator><![CDATA[Gea-Suan Lin]]></dc:creator>
		<pubDate>Mon, 07 Sep 2026 08:27:11 +0000</pubDate>
				<category><![CDATA[Computer]]></category>
		<category><![CDATA[Murmuring]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[WWW]]></category>
		<category><![CDATA[agent]]></category>
		<category><![CDATA[ai]]></category>
		<category><![CDATA[coding]]></category>
		<category><![CDATA[github]]></category>
		<category><![CDATA[language]]></category>
		<category><![CDATA[large]]></category>
		<category><![CDATA[llm]]></category>
		<category><![CDATA[model]]></category>
		<category><![CDATA[pr]]></category>
		<category><![CDATA[pull]]></category>
		<category><![CDATA[request]]></category>
		<guid isPermaLink="false">https://blog.gslin.org/?p=13187</guid>

					<description><![CDATA[八月底的時候看到的站台，針對 GitHub PR 分了十類，然後從中分析出現的詞彙頻率：「The load-bearing vocabulary of Claude (via)」。 這套方法蠻有趣的，拉出來看一下卻有點失望？ group 1 最多的是 load-bearing、plainly 與 quietly；group 2 是 exact-head、gocache 與 --nocapture；group 3 是 [webkit-url]、ews 與 webcore；group 4 是 que、para 與 por (各種非英文的語系？)；group 5 是 pullrequest、[raycast-url] 與 jgong5 (居然出現帳號名稱？)。 是可以看到蠻有趣的資訊，但是不是有用的資訊又是個問題...]]></description>
										<content:encoded><![CDATA[<p>八月底的時候看到的站台，針對 <a href="https://en.wikipedia.org/wiki/GitHub">GitHub</a> PR 分了十類，然後從中分析出現的詞彙頻率：「<a href="https://louisabraham.github.io/load-bearing/">The load-bearing vocabulary of Claude</a> (<a href="https://news.ycombinator.com/item?id=49461817">via</a>)」。</p>
<p>這套方法蠻有趣的，拉出來看一下卻有點失望？</p>
<p>group 1 最多的是 <code>load-bearing</code>、<code>plainly</code> 與 <code>quietly</code>；group 2 是 <code>exact-head</code>、<code>gocache</code> 與 <code>--nocapture</code>；group 3 是 [webkit-url]、<code>ews</code> 與 <code>webcore</code>；group 4 是 <code>que</code>、<code>para</code> 與 <code>por</code> (各種非英文的語系？)；group 5 是 <code>pullrequest</code>、<code>[raycast-url]</code> 與 <code>jgong5</code> (居然出現帳號名稱？)。</p>
<p>是可以看到蠻有趣的資訊，但是不是有用的資訊又是個問題...</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.gslin.org/archives/2026/09/07/13187/llm-%e5%9c%a8-github-pr-%e4%b8%8a%e7%9a%84%e8%a9%9e%e5%bd%99%e9%a0%bb%e7%8e%87/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">13187</post-id>	</item>
		<item>
		<title>Google 的 AI 模式會抓到比較貴的商品價格</title>
		<link>https://blog.gslin.org/archives/2026/09/07/13186/google-%e7%9a%84-ai-%e6%a8%a1%e5%bc%8f%e6%9c%83%e6%8a%93%e5%88%b0%e6%af%94%e8%bc%83%e8%b2%b4%e7%9a%84%e5%95%86%e5%93%81%e5%83%b9%e6%a0%bc/</link>
					<comments>https://blog.gslin.org/archives/2026/09/07/13186/google-%e7%9a%84-ai-%e6%a8%a1%e5%bc%8f%e6%9c%83%e6%8a%93%e5%88%b0%e6%af%94%e8%bc%83%e8%b2%b4%e7%9a%84%e5%95%86%e5%93%81%e5%83%b9%e6%a0%bc/#comments</comments>
		
		<dc:creator><![CDATA[Gea-Suan Lin]]></dc:creator>
		<pubDate>Sun, 06 Sep 2026 19:28:43 +0000</pubDate>
				<category><![CDATA[Computer]]></category>
		<category><![CDATA[Murmuring]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Search Engine]]></category>
		<category><![CDATA[ai]]></category>
		<category><![CDATA[ec]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[language]]></category>
		<category><![CDATA[large]]></category>
		<category><![CDATA[llm]]></category>
		<category><![CDATA[mode]]></category>
		<category><![CDATA[model]]></category>
		<category><![CDATA[price]]></category>
		<category><![CDATA[search]]></category>
		<guid isPermaLink="false">https://blog.gslin.org/?p=13186</guid>

					<description><![CDATA[好像大多數的 AI 都會遇到類似的問題，就是 AI 抓到的商品價格偏貴的問題，這次是講 Google，不過我猜各家 web 版的 AI mode 應該都有類似的情況：「Google AI Mode shows the same products 21.6% more expensive than traditional search (via)」。 這篇文章裡面有提到一點，是發現 AI mode 掃出來的商品與傳統搜尋找到的商品幾乎是不同的： Finding 3: very little product overlap between AI Mode and traditional search Even when both sides respond to the same search, they rarely show the same products &#8230; <a href="https://blog.gslin.org/archives/2026/09/07/13186/google-%e7%9a%84-ai-%e6%a8%a1%e5%bc%8f%e6%9c%83%e6%8a%93%e5%88%b0%e6%af%94%e8%bc%83%e8%b2%b4%e7%9a%84%e5%95%86%e5%93%81%e5%83%b9%e6%a0%bc/" class="more-link">Continue reading<span class="screen-reader-text"> "Google 的 AI 模式會抓到比較貴的商品價格"</span></a>]]></description>
										<content:encoded><![CDATA[<p>好像大多數的 AI 都會遇到類似的問題，就是 AI 抓到的商品價格偏貴的問題，這次是講 <a href="https://en.wikipedia.org/wiki/Google">Google</a>，不過我猜各家 web 版的 AI mode 應該都有類似的情況：「<a href="https://productrise.app/blog/google-ai-mode-prefers-more-expensive-products">Google AI Mode shows the same products 21.6% more expensive than traditional search</a> (<a href="https://news.ycombinator.com/item?id=49563386">via</a>)」。</p>
<p>這篇文章裡面有提到一點，是發現 AI mode 掃出來的商品與傳統搜尋找到的商品幾乎是不同的：</p>
<blockquote><p>Finding 3: very little product overlap between AI Mode and traditional search</p>
<p>Even when both sides respond to the same search, they rarely show the same products on the same day. Across our data, only 1.28% of products ranking in traditional search also appeared in AI Mode. Our July study found a similar pattern at a broader level: AI Mode ranked just ~5% of the products that rank in traditional search overall. </p></blockquote>
<p>在這個前提下，後續的排序以及比價的過程當然就會有明顯的差異...</p>
<p>我自己也會用 AI 工具找商品，但比起 web 介面，我更偏好用 cli 介面，主要是因為 cli 介面的版本跑出來的效果比較好。</p>
<p>web 介面基本上只有 <code>WebFetch</code> 與 <code>WebSearch</code> 可以用，加上這邊的內容會是 cached content，沒那麼「新鮮」，而 cli 這邊可以用 <code>curl</code> 抓到最新的資料，甚至是 <a href="https://en.wikipedia.org/wiki/Python_(programming_language)">Python</a> 處理更複雜的情境，整個精準度比 web 介面版高不少。</p>
<p>在猜 Google 的 AI mode 可能也跟這個有關？走 cached content 成本會比較低...</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.gslin.org/archives/2026/09/07/13186/google-%e7%9a%84-ai-%e6%a8%a1%e5%bc%8f%e6%9c%83%e6%8a%93%e5%88%b0%e6%af%94%e8%bc%83%e8%b2%b4%e7%9a%84%e5%95%86%e5%93%81%e5%83%b9%e6%a0%bc/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">13186</post-id>	</item>
		<item>
		<title>Google Chrome 又被抓到會針對自家網域名稱忽略使用者的隱私機制了</title>
		<link>https://blog.gslin.org/archives/2026/09/07/13185/google-chrome-%e5%8f%88%e8%a2%ab%e6%8a%93%e5%88%b0%e6%9c%83%e9%87%9d%e5%b0%8d%e8%87%aa%e5%ae%b6%e7%b6%b2%e5%9f%9f%e5%90%8d%e7%a8%b1%e5%bf%bd%e7%95%a5%e4%bd%bf%e7%94%a8%e8%80%85%e7%9a%84%e9%9a%b1/</link>
					<comments>https://blog.gslin.org/archives/2026/09/07/13185/google-chrome-%e5%8f%88%e8%a2%ab%e6%8a%93%e5%88%b0%e6%9c%83%e9%87%9d%e5%b0%8d%e8%87%aa%e5%ae%b6%e7%b6%b2%e5%9f%9f%e5%90%8d%e7%a8%b1%e5%bf%bd%e7%95%a5%e4%bd%bf%e7%94%a8%e8%80%85%e7%9a%84%e9%9a%b1/#respond</comments>
		
		<dc:creator><![CDATA[Gea-Suan Lin]]></dc:creator>
		<pubDate>Sun, 06 Sep 2026 18:57:42 +0000</pubDate>
				<category><![CDATA[Browser]]></category>
		<category><![CDATA[Computer]]></category>
		<category><![CDATA[GoogleChrome]]></category>
		<category><![CDATA[Murmuring]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[WWW]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[chrome]]></category>
		<category><![CDATA[chromium]]></category>
		<category><![CDATA[cookie]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[privacy]]></category>
		<guid isPermaLink="false">https://blog.gslin.org/?p=13185</guid>

					<description><![CDATA[Google Chrome 又被同一個作者抓到會針對自家網域名稱忽略使用者的隱私設定了：「Chrome again exempts Google from user site data settings (via)」，上一次是 2020 年的時候：「Chrome exempts Google sites from user site data settings」。 這次的情況是，即使使用者設定在關閉瀏覽器後刪除掉所有的資料： 但會發現 www.google.com 的資料在關閉後打開還是被保留了下來： 雖然跳到 Firefox 了，但還是繼續來關注一下隔壁棚的發展...]]></description>
										<content:encoded><![CDATA[<p><a href="https://en.wikipedia.org/wiki/Google_Chrome">Google Chrome</a> 又被同一個作者抓到會針對自家網域名稱忽略使用者的隱私設定了：「<a href="https://lapcatsoftware.com/articles/2026/9/1.html">Chrome again exempts Google from user site data settings</a> (<a href="https://news.ycombinator.com/item?id=49581870">via</a>)」，上一次是 2020 年的時候：「<a href="https://lapcatsoftware.com/articles/chrome-google.html">Chrome exempts Google sites from user site data settings</a>」。</p>
<p>這次的情況是，即使使用者設定在關閉瀏覽器後刪除掉所有的資料：</p>
<picture><source type="image/webp" srcset="https://i.gslin.com/s/1788720722-227cd78a.webp" /><img decoding="async" src="https://i.gslin.com/s/1788720722-227cd78a.png" alt="" /></picture>
<p>但會發現 <code>www.google.com</code> 的資料在關閉後打開還是被保留了下來：</p>
<picture><source type="image/webp" srcset="https://i.gslin.com/s/1788720790-b7f682e9.webp" /><img decoding="async" src="https://i.gslin.com/s/1788720790-b7f682e9.png" alt="" /></picture>
<p>雖然跳到 <a href="https://en.wikipedia.org/wiki/Firefox">Firefox</a> 了，但還是繼續來關注一下隔壁棚的發展...</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.gslin.org/archives/2026/09/07/13185/google-chrome-%e5%8f%88%e8%a2%ab%e6%8a%93%e5%88%b0%e6%9c%83%e9%87%9d%e5%b0%8d%e8%87%aa%e5%ae%b6%e7%b6%b2%e5%9f%9f%e5%90%8d%e7%a8%b1%e5%bf%bd%e7%95%a5%e4%bd%bf%e7%94%a8%e8%80%85%e7%9a%84%e9%9a%b1/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">13185</post-id>	</item>
		<item>
		<title>透過 BGP 劫持提供假的 Update Server</title>
		<link>https://blog.gslin.org/archives/2026/09/06/13184/%e9%80%8f%e9%81%8e-bgp-%e5%8a%ab%e6%8c%81%e6%8f%90%e4%be%9b%e5%81%87%e7%9a%84-update-server/</link>
					<comments>https://blog.gslin.org/archives/2026/09/06/13184/%e9%80%8f%e9%81%8e-bgp-%e5%8a%ab%e6%8c%81%e6%8f%90%e4%be%9b%e5%81%87%e7%9a%84-update-server/#respond</comments>
		
		<dc:creator><![CDATA[Gea-Suan Lin]]></dc:creator>
		<pubDate>Sat, 05 Sep 2026 16:02:44 +0000</pubDate>
				<category><![CDATA[Computer]]></category>
		<category><![CDATA[Murmuring]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Service]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[SRE]]></category>
		<category><![CDATA[bgp]]></category>
		<category><![CDATA[certificate]]></category>
		<category><![CDATA[code]]></category>
		<category><![CDATA[hijack]]></category>
		<category><![CDATA[ip]]></category>
		<category><![CDATA[letsencrypt]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[routing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[server]]></category>
		<category><![CDATA[sign]]></category>
		<category><![CDATA[ssl]]></category>
		<category><![CDATA[tls]]></category>
		<category><![CDATA[update]]></category>
		<guid isPermaLink="false">https://blog.gslin.org/?p=13184</guid>

					<description><![CDATA[看到「Security Incident – BGP Hijacking」這則 (好像是 Lobsters 上)，所以也的確有人這樣搞了，透過 BGP hijack 然後再透過 Let's Encrypt 取得 TLS certificate，然後提供 Update Server 的服務安裝 malware 進去。 Between 28 August 2026 at approximately 20:57 UTC and 30 August 2026 at approximately 06:10 UTC, a block of IP addresses used by Softaculous services (162.55.80.0/24, part of our infrastructure at Hetzner) was affected &#8230; <a href="https://blog.gslin.org/archives/2026/09/06/13184/%e9%80%8f%e9%81%8e-bgp-%e5%8a%ab%e6%8c%81%e6%8f%90%e4%be%9b%e5%81%87%e7%9a%84-update-server/" class="more-link">Continue reading<span class="screen-reader-text"> "透過 BGP 劫持提供假的 Update Server"</span></a>]]></description>
										<content:encoded><![CDATA[<p>看到「<a href="https://www.virtualizor.com/blog/security-incident-bgp-hijacking/">Security Incident – BGP Hijacking</a>」這則 (好像是 <a href="https://lobste.rs/">Lobsters</a> 上)，所以也的確有人這樣搞了，透過 BGP hijack 然後再透過 <a href="https://en.wikipedia.org/wiki/Let%27s_Encrypt">Let's Encrypt</a> 取得 TLS certificate，然後提供 Update Server 的服務安裝 malware 進去。</p>
<blockquote><p>Between 28 August 2026 at approximately 20:57 UTC and 30 August 2026 at approximately 06:10 UTC, a block of IP addresses used by Softaculous services (162.55.80.0/24, part of our infrastructure at Hetzner) was affected by a BGP hijack: an unauthorized announcement of that address space by an unrelated network, which diverted internet traffic destined for those addresses to a server operated by an attacker. The attacker obtained a technically valid TLS certificate for our domains, so connections affected by the hijack showed no certificate warning.</p></blockquote>
<p>看了一下他們後續的處理方法，code sign 算是基本要補的架構，看起來是正在弄了。</p>
<p>但到現在沒看到透過 <a href="https://en.wikipedia.org/wiki/DNS_Certification_Authority_Authorization">DNS CAA</a> 阻止其他人申請 Let's Encrypt，代表後續 hijack 後還是可以取得 TLS certificate，而舊版的伺服器 (還沒上 code sign 驗證的) 就一樣會中獎。</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.gslin.org/archives/2026/09/06/13184/%e9%80%8f%e9%81%8e-bgp-%e5%8a%ab%e6%8c%81%e6%8f%90%e4%be%9b%e5%81%87%e7%9a%84-update-server/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">13184</post-id>	</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Object Caching 41/54 objects using APC
Page Caching using APC (Page is feed) 
Minified using APC
Database Caching using APC

Served from: blog.gslin.org @ 2026-09-12 04:55:20 by W3 Total Cache
-->