Friday, August 21, 2026 · No. 7
20 articles · ~3h 13m read · 8 sections
A personal morning paper, assembled daily; the selection is the reader's, the words are the authors'.
Sign in to read every article's full text and download the editions, or request access.
Top Stories
Rust Supply-Chain Attack: arrayref 0.3.10 and the proc-macro1 Typosquat
stepsecurity.io · Popular Posts on Scour Today · stepsecurity.io · 22 min
A compromised maintainer account publishes a malicious arrayref 0.3.10 that injects a same-day typosquat of proc-macro2; the build script downloads and runs a payload with TLS verification disabled. Three crates are poisoned in 23 minutes, and a scripted yank of clean releases lures developers into upgrading. The report includes a verified timeline, indicators of compromise, and a runtime reproduction in which Harden-Runner flags the C2 connection.
AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint
emctech · Hacker News: Best · blog.laserphile.com · 7 min
AliExpress's homepage silently creates two running WebAudio graphs from obfuscated Alibaba security scripts, collina.js and fireyejs.js, to fingerprint browsers. The zero-gain graphs connect to the audio destination, which prevents Bluetooth multipoint headphones from switching back to a phone; muting the tab does nothing because no media element exists. Two uBlock Origin filters block the scripts and restore normal audio.
Tech & Engineering
Andrei Lepikhov: Do Global Hash Tables Strike Back in PostgreSQL?
Planet PostgreSQL · postgr.es · 20 min
A weekend prototype tests whether a shared hash table can speed up parallel aggregation in PostgreSQL, and on uniform data it delivers up to 4.82× speedup with eight workers. But heavy-hitter skew flips the result to a 0.04× loss, and the post dissects the cost model, by-reference state handling, and the three issues hidden beneath the lock contention.
Issues in the Repo
Andrew Nesbitt · nesbitt.io · 11 min
GitHub's multi-hour outage makes the case for keeping issue trackers inside the repository. The article surveys two decades of tools—from Bugs Everywhere and ditz to git-bug and Forgejo's proposal—that store issues as files, orphan branches, notes, or custom refs, and shows how each handles conflicts, identity, and portability. It even verifies that git bundle packs every bug ref into a single file.
Why .tar.gz files can't be combined with cat
alexwlchan.net via gavinmorrow · Lobsters · alexwlchan.net · 6 min
Combining .tar.gz archives by concatenating bytes fails because tar readers stop at the first end-of-file marker, even though gzip itself happily concatenates members. The fix is to extract each archive's members and re-archive them into a single file with a single EOF marker, using Python's tarfile module in r:gz and w:gz modes. The explanation traces tar's design to tape drives and gzip's to patent-free streaming.
Hacker News: 9 points · 11 commentsLobsters: 6 points · 4 commentsComments
Run Rob Run: Building a Music-Reactive Goo with Three.js and WebGPU
Robert Aperios · Codrops · tympanus.net · 7 min
A developer's breakdown of a WebGPU/Three.js portfolio piece whose central goo morphs from organic blob to cube on scroll. The music reaction weighs only rhythmic hits — kicks and claps — while damping releases to give the object mass. Includes hover details and performance/accessibility notes.
Science & Space
An Early History of Space Stations: The Brick Moon Made Real
Al Williams · Hackaday · hackaday.com · 6 min
Traces the ancestry of orbital habitats from Edward Everett Hale's 1869 Brick Moon to von Braun's Collier's wheel, and explains why spin gravity shaped those designs. The physics get concrete: at 1 RPM a ring needs 1.79 km diameter for one g, and Coriolis effects make 4 RPM a practical limit. Notes Kubrick's 2001 got the floor direction right.
AI & Machine Learning
Show HN: I trained a 125M model to autocomplete piano on-device
simedw · Hacker News: Best · simedw.com · 12 min
A 125M-parameter transformer autocompletes piano performances in real time on an iPhone 15 at ~108 notes/sec. The project's biggest gains came from a custom note-level MIDI representation, aggressive training-data cleaning (outweighing a 5x larger noisy dataset), and DPO post-training, which lifted preference win rates from 24% to 69%. Failed approaches—note-on/off drift, grammar masking, broader data—are dissected alongside the final app, RollTab.
Debates over AI consciousness are a trap
Rumman Chowdhury · Top News - MIT Technology Review · technologyreview.com · 7 min
Consciousness debates about AI are a trap, argues the piece: framing models as autonomous or rights-bearing lets builders dodge liability. It points to Anthropic's 'J-space,' Sam Altman's singularity talk, and William MacAskill's moral-patient argument, then warns that AI personhood would turn product-liability cases like Sewell Setzer's suicide lawsuit into 'rogue employee' defenses.
Don't paste the AI, please
pjerem · Hacker News: Best · dontpastetheai.com · 2 min
The article argues that pasting a chatbot's answer into a personal message is a cop-out: the other person asked for your take, not a generic wall of text. It advises using AI as a drafting tool, then reading and rewriting the response, quoting the useful part with explanation, or simply saying you have no strong opinion. The piece positions itself alongside nohello.net and dontasktoask.com.
Culture & Essays
I should have loved biology (2020)
tyre · Hacker News: Best · jsomers.net · 18 min
In this excerpt, James Somers argues that biology classes presented astonishing facts without astonishment, killing curiosity. Adopting a programmer's view—cells as self-modifying programs and proteins as shapes bumping together—and studying methods like RNA-seq and Western blots finally made the subject click, aided by books like 'The Eighth Day of Creation.'
Aftermath of an Intervention, Part III
Nelly Reifler · Electric Literature · electricliterature.com · 24 min
Nelly Reifler returns to New York City two weeks after 9/11, sick with guilt and disbelief; she was one phone call from boarding United Flight 93. She grows reckless, drives drunk, and loses her filters, sobbing to a friend that she loves him. The essay closes with her attempt to see Elliott Smith before his Knitting Factory show, where a young woman lets her in—but only because she is 'that author.'
In Praise of “Wordy, Old Prose.” (Or, F*ck Your AI Reading Buddy)
Literary Hub · Popular Posts on Scour Today · lithub.com · 4 min
Maris Kreizman argues that using an AI to understand challenging books, as Axios publisher Nicholas Johnson brags about, devalues the productive struggle of reading. She champions 'literary friction,' recalling her own Middlemarch marathon and learning to sit with ambiguity in Missouri Williams's The Vivisectors, and ties the fear of discomfort to book bans.
How the Ancient Greeks Interpreted Their Dreams
Kristen French · Nautilus · nautil.us · 11 min
Classicist Mirjam Kotwick argues that ancient Greek dream interpretation, from Homer's Penelope to Aristotle, relied on a shared 'hermeneutics of similarity' that shaped how we read metaphor and poetic language today. She points to Penelope's eagle dream as the earliest recorded case, Aristotle's unexpectedly receptive take on symbolic interpretation, and Hippocrates' use of dreams to diagnose illness before symptoms appear.
Metal Gear Solid 4: Guns of the Patriots review
morgan.park@futurenet.com (Morgan Park) · PC Gamer · pcgamer.com · 8 min
The Master Collection PC port of Metal Gear Solid 4 gets a reappraisal: its stealth sandboxes still feel unmatched, with reactive guards and hidden routes, though the back half sags. The port runs at 4K and 60 fps on modern hardware and includes extras like a digital art book and an in-game database, even showing Steam Deck-specific art in cutscenes.
Boston & Local
Lobsters and acidic seas: can shellfish help neutralise one of the greatest threats to the ocean?
Alexandra Talty in Cape Cod, Massachusetts · Technology | The Guardian · theguardian.com · 9 min
Scientists in the Gulf of Maine are testing ocean alkalinity enhancement by releasing 65,000 liters of sodium hydroxide offshore, monitoring carbon uptake and lobster responses; preliminary results show no lethal effects on lobsters. But US federal funding cuts are drying up, leaving projects like LOC-NESS dependent on European grants, even as private carbon-removal credits race ahead of the science.
Archeologists uncover new artifacts and details about The Battle of Bunker Hill
GBH News · wgbh.org · 7 min
At the Bunker Hill site, archaeologists find musket balls, gun flints, and British soldiers' belongings, including an officer's wig curler. City archaeologist Joe Bagley explains the trench beneath the monument eroded back within months after the battle, preserving artifacts earlier than expected. Next, his crew will search 19th-century schoolhouse outhouses, a 90-foot privy.
Niche Corner
The Nape Pro Is Not Like Other Trackballs
Chris Person · Aftermath · aftermath.site · 7 min
Keychron's Nape Pro is a trackball embedded in a long macro bar, with a rotate key that reorients the ball in 1/8th turns, suiting it to lefties, righties, and split-keyboard gaps. It runs ZMK firmware with on-device macros and silent Huanao switches, while a scratchy scroll wheel is the weak point. Using it beside an Endgame trackball creates mirrored ambidextrous mousing, described as 'controlling an alien spaceship.'
Glitter, Mountains, and the Leadville 100 Mile: A Conversation with Michael Mitchell
Eszter Horanyi · iRunFar.com · 11 min
Michael Mitchell, the openly gay ultrarunner and influencer known as Mikey Mitch, recounts his chaotic first Leadville 100, the glitter-powered race video that made him famous, and his third go at the race this weekend. He also talks about finding community in running, leaving Denver for Buena Vista, and his plan to run Hope Pass, not walk it.
From the Blogroll
Don’t hire thoughtbot to write code
Ran Craycraft · Giant Robots Smashing Into Other Giant Robots · feed.thoughtbot.com · 5 min
With AI making code itself cheap, thoughtbot argues premium consultancies must earn their rates through judgment, not hours. The post contends that clients should hire for ownership and augment for capability, expect consultants to challenge assumptions, and accept that the right answer may be a smaller, senior team. It advises paying for outcomes, not backlogs.