• maiweb v0.1.0
  • ★
  • Feedback
  • ESPN espn.com espn news sports 2026-08-03 19:52

    ↗

    Bears new safety Coby Bryant will miss eight to 10 weeks with a leg injury.

    Bears new safety Coby Bryant will miss eight to 10 weeks with a leg injury.
  • ESPN espn.com espn news sports 2026-08-03 19:52

    ↗

    Patriots wide receiver A.J. Brown told NFL Network that he dislocated his thumb in Monday's practice, but he didn't miss any time.

    Patriots wide receiver A.J. Brown told NFL Network that he dislocated his thumb in Monday's practice, but he didn't miss any time.
  • ESPN espn.com espn news sports 2026-08-03 19:52

    ↗

    The Padres, who desperately needed starting pitching help, have acquired left-hander Robbie Ray from the Giants, sources told ESPN.

    The Padres, who desperately needed starting pitching help, have acquired left-hander Robbie Ray from the Giants, sources told ESPN.
  • ESPN espn.com espn news sports 2026-08-03 19:52

    ↗

    USC and Notre Dame will renew their rivalry starting in 2030, however the Fighting Irish's home-and-home series vs. Indiana starting that year is now off.

    USC and Notre Dame will renew their rivalry starting in 2030, however the Fighting Irish's home-and-home series vs. Indiana starting that year is now off.
  • ESPN espn.com espn news sports 2026-08-03 19:52

    ↗

    Retired Heat superstar Chris Bosh offered some advice and issued a warning to Spurs star Victor Wembanyama about his blood clot diagnosis and maintaining his health during his career.

    Retired Heat superstar Chris Bosh offered some advice and issued a warning to Spurs star Victor Wembanyama about his blood clot diagnosis and maintaining his health during his career.
  • ESPN espn.com espn news sports 2026-08-03 19:52

    ↗

    Brewers ace Jacob Misiorowski dragged the Angel Stadium grounds crew through the dirt Sunday, calling the pitching mound "awful" and a possible injury risk.

    Brewers ace Jacob Misiorowski dragged the Angel Stadium grounds crew through the dirt Sunday, calling the pitching mound "awful" and a possible injury risk.
  • ESPN espn.com espn news sports 2026-08-03 19:52

    ↗

    The Phillies have acquired three-time batting champion Luis Arraez from the Giants in a trade that has the second baseman joining his fifth team in five years.

    The Phillies have acquired three-time batting champion Luis Arraez from the Giants in a trade that has the second baseman joining his fifth team in five years.
  • ESPN espn.com espn news sports 2026-08-03 19:52

    ↗

    Mauricio Pochettino has signed a new contract to continue as manager of the U.S. men's national team, U.S. Soccer announced Monday morning.

    Mauricio Pochettino has signed a new contract to continue as manager of the U.S. men's national team, U.S. Soccer announced Monday morning.
  • ESPN espn.com espn news sports 2026-08-03 19:52

    ↗

    With a trade seemingly inevitable, the two-time Cy Young winner tried to keep things normal amid the chaos.

    With a trade seemingly inevitable, the two-time Cy Young winner tried to keep things normal amid the chaos.
  • ESPN espn.com espn news sports 2026-08-03 19:49

    ↗

    Lions running back Jahmyr Gibbs said Monday that "only time will tell" when he will return to practice as he seeks a contract extension.

    Lions running back Jahmyr Gibbs said Monday that "only time will tell" when he will return to practice as he seeks a contract extension.
  • ESPN espn.com espn news sports 2026-08-03 19:49

    ↗

    null

    null
  • ESPN espn.com espn news sports 2026-08-03 19:07

    ↗

    UEFA has raised the possibility that it could take legal action against Gianni Infantino over his World Cup sell-off plan, sources told ESPN.

    UEFA has raised the possibility that it could take legal action against Gianni Infantino over his World Cup sell-off plan, sources told ESPN.
  • Kotaku kotaku.com culture gaming kotaku reviews 2026-08-03 19:00

    ↗

    We also finally get to see Game Freak's take on the Soulslike

    We also finally get to see Game Freak's take on the Soulslike
  • Polygon polygon.com gaming polygon reviews voxel-media 2026-08-03 19:00

    ↗

    Fields of Mistria launches its full 1.0 on Aug. 5, 2026. Time for new NPCs, new romance milestones, a chicken you can ride across the map, and more!

    If you’ve played Harvest Moon or are looking for a Stardew-like with shades of Zelda and a ‘90s-inspired, Sailor Moon aesthetic, this is it. Fields of Mistria is a $14 farming and life-simulation RPG created by the independent team at NPC Studio. It’s been in early access for two years, and now the full game is launching on Steam on Aug. 5.

  • Phys.org phys.org phys-org physics research-news science 2026-08-03 19:00

    ↗

    Roll back the tape of Earth's history, and geologists and astrobiologists remain perplexed about the environmental conditions on early Earth. That's because conventional pathways for understanding Earth's history have been lost to time owing to the planet's active geology and...

    Roll back the tape of Earth's history, and geologists and astrobiologists remain perplexed about the environmental conditions on early Earth. That's because conventional pathways for understanding Earth's history have been lost to time owing to the planet's active geology and atmospheric weathering.
  • Gizmodo gizmodo.com gizmodo science scifi tech technology 2026-08-03 19:00

    ↗

    A new trailer is here to remind you that 'Star Wars: Visions Presents - The Ninth Jedi' hits Disney+ on August 5.

    A new trailer is here to remind you that 'Star Wars: Visions Presents - The Ninth Jedi' hits Disney+ on August 5.
  • Phys.org phys.org phys-org physics research-news science 2026-08-03 19:00

    ↗

    Cyanobacterial blooms, like the ones that occur in Lake Geneva, are rapid, dense growths of photosynthetic bacteria in fresh and marine waters that can threaten the health of swimmers and their pets.

    Cyanobacterial blooms, like the ones that occur in Lake Geneva, are rapid, dense growths of photosynthetic bacteria in fresh and marine waters that can threaten the health of swimmers and their pets.
  • Polygon polygon.com gaming polygon reviews voxel-media 2026-08-03 18:58

    ↗

    The release of Street Fighter 6's new character, Yasmine, has been overshadowed by complaints over the game's latest yearly balance patch.

    Street Fighter 6 just got its long-awaited Aug. 3 update, and the fan response has not been pretty. The short version is that the patch barely shakes up the game’s core systems, while making strange nerf and buff decisions for much of the roster.

  • DEV Community dev.to community dev-to software-dev technology 2026-08-03 18:57

    ↗

    Your Secrets Need a VDP, Not Just a Bug Bounty Bug bounty programs are valuable -- until they replace disclosure policies. Learn how unreasonable PoC demands or scope exclusions create security blind spots when it comes to leaked secrets. By Gaetan Ferry • 6 Feb 2026 • 8 min...

    Your Secrets Need a VDP, Not Just a Bug Bounty

    Bug bounty programs are valuable -- until they replace disclosure policies. Learn how unreasonable PoC demands or scope exclusions create security blind spots when it comes to leaked secrets.

    By Gaetan Ferry • 6 Feb 2026 • 8 min read

    Your Secrets Need a VDP, Not Just a Bug Bounty

    In recent years, more and more companies have launched bug bounty programs as proof of their commitment to security and as a way to implement continuous monitoring of their corporate attack surface. Those programs sometimes offer generous payouts to vulnerability reporters, and often partner with dedicated platforms that offer various services such as:

    • Payment and billing management
    • Triaging as a Service
    • Investigation assistance

    Platforms rely on a "hacker community", a group of people who hack on the programs to discover vulnerabilities and earn bounty money. Most of those "hackers" are self-employed in a way that allows them to comply with local applicable tax laws.

    Bug bounty programs are a great way to have a corporate perimeter or set of applications audited by a large set of people, nearly continuously. They can be a great addition to a company's security policy. In fact, GitGuardian has been running a bug bounty program for multiple years, as a complement to our periodic audits and overall security strategy.

    Bug Bounty Done Wrong

    The problem with bug bounty programs starts when they try to substitute for a proper Vulnerability Disclosure Policy. When they do, they no longer improve your security posture; they undermine it.

    Bug bounties, by design, are selective. From a "hacker" perspective, they come with limited scopes, opaque triage processes, gatekeeping platforms, or even eligibility requirements. As a result, valid, good-faith vulnerability reports can get ignored, rejected, or buried -- not because they lack accuracy or merit, but because they fall outside of the boundaries of the programs' terms or the opaque decision of a third-party triager. Payout levels also undermine this testing model, turning continuous monitoring into a blind spot shaped by market incentives; why search for or report vulnerabilities when they pay little or nothing?

    Using a bug bounty platform as the only possible communication channel for vulnerability disclosure creates unnecessary friction:

    • Mandatory registration forces researchers to trade their privacy for participation.
    • Non-disclosure clauses can silence conversation about systemic risks, and more generally hinder information sharing.
    • Platform gatekeeping can discourage reporters.
    • Worse: out-of-scope dismissals allow serious vulnerability reports to be voided, and never reported to security teams

    These blind spots don't make an organization more secure. They make it easier to overestimate the security posture, thinking that fewer reports mean fewer problems.

    A good Vulnerability Disclosure Policy (VDP) should promote openness. It should be a clear and accessible way for anyone -- a professional researcher, a student, or a concerned user -- to report a security issue safely, privately, and without process complexity. A good disclosure policy should enable communication rather than controlling it.

    One particular issue that highlights how bug bounty can fail as a disclosure channel lies in how they handle secret leak reports.

    GitGuardian's experience

    One of the core foundations of GitGuardian is the detection and remediation of secrets leaked in public spaces. Over the course of the past year, while working on improving our understanding of the secret sprawl issue, we performed responsible disclosures to hundreds of companies.

    GitGuardian's cybersecurity research team is not a bug bounty crew. We do not seek any reward for reporting incidents. For this reason, we usually attempt to contact affected companies directly, preferably via email, and sometimes through online forms dedicated to security incident reporting. We only fallback to the bug bounty program channel as a last resort, or when directly prompted to do so.

    While working with platforms, we experienced a variety of situations and answers that illustrate how bug bounty can fail as a disclosure channel.

    400 PoC or GTFO

    As a result of a large-scale research project, we recently reported leaked private keys related to valid X.509 certificates. The risk of such incidents can generally be considered high, as a leaked key can be used to set up Man-In-The-Middle attacks against the company's public assets. Some of our reports had to go through bug bounty platforms, which already create friction. As much as we can automate the sending of hundreds of e-mails, filling bug bounty reports at scale is challenging.

    In all our reports, the triagers asked for a proof of concept exploitation.

    HackerOne response asking for a proof of concept after private key leak

    HackerOne response asking for a proof of concept after private key leak

    BugCrowd response asking for a proof of concept after valid credential leak

    BugCrowd response asking for a proof of concept after valid credential leak

    First, proving a credential's impact has a clear ethical boundary: demonstrate the potential for harm without causing actual harm. This means verifying credentials are valid, confirming what resources they access, and documenting their privilege level, but without reading production data, modifying systems, or performing harmful actions. This is not always possible, depending on the credential type. In the case of leaked X.509 certificate private keys, creating such a proof-of-concept would have required decrypting real traffic or impersonating production services -- crossing from validation into active attack -- which could have severe legal consequences.

    Then, the main question is: what happens after the report gets closed as informative? There is a chance that no action will be taken. In some cases, the issue might never pass the triaging filter and reach the corporate security team.

    In our case, most reports were actually closed as informative, and none of the related certificates were revoked. Worst of all, some GitHub repositories containing leaked private keys have never been deleted. We later contacted the related certificates' issuer authorities to have the keys black listed and certificates revoked.

    403 Private Program

    Bug bounty programs can either be public or private. Public programs can be viewed, accessed, and interacted with by anyone. On the other hand, private programs are invite-only, so only selected members of the platform's community can report vulnerabilities.

    In that case, obviously, the program can not be considered a proper disclosure channel. However, there is a reporting flow that overlooks this issue:

    • You discover a vulnerability and attempt to report it through standard channels (security@, contact forms).
    • You receive a response: 'Please submit via our Bug Bounty Program.'
    • You navigate to the platform, only to find it's private and invitation-required.
    • Without an invitation, you hit a dead end with no alternative channel.

    Our team has faced this situation once, making the reporting process painful and highlighting how companies often lack awareness about vulnerability disclosure practices.

    Similarly, a documented program can have expired or been decommissioned. In this case, the communication channel is effectively nonexistent. This was the case when we reported a leaked API key to xAI in 2025.

    404 Secret Not Found In Scope

    The scope of a program includes the list of assets that are authorized to be worked on. It also includes the list of vulnerabilities that are accepted in reports. The purpose of this restriction is to limit the number of low-quality reports or reports for vulnerabilities that are widely recognized as lacking real-world impact.

    However, if the scope of a program is too restricted, valid and severe issues might get discarded by the triaging team without further notice. In that spirit, we faced bug bounty programs that explicitly marked leaked credentials as out of scope. The platforms sometimes even encourage their customers to ban secrets. The reason behind this is tied to the origin of the credentials, as we discussed with a platform representative:

    We strongly advise our clients to exclude leaked secrets from their bug bounty program scope. The reality is that compromised credentials frequently originate from illicit sources. There's a thriving underground market for stolen credentials, and by offering bounties for leaked secrets, we risk inadvertently incentivizing and legitimizing a secondary marketplace for compromised authentication data.

    While this concern is understandable, excluding leaked secrets creates a dangerous blind spot. Valid credentials represent immediate security risks: unauthorized access, data breaches, or compromised systems.

    The solution isn't to ban secret reports -- it's to require source transparency. Researchers should disclose where the credentials were found. This approach enables security teams to investigate the leak's origin and take appropriate remediation action, while distinguishing legitimate research from illicit activity.

    500 Triager error

    Triager gatekeeping can also be an issue in case of a misunderstanding about a security issue. While misunderstandings can occur with corporate security teams, triagers can close the communication channel when they deem an issue uninteresting. While it is often possible to ask to reopen closed reports or ask for mediation, this can prevent legitimate reports from reaching the corporate teams and create unnecessary friction.

    Triager closing issue while credentials were still valid

    In the above case, the triager closed the issue while the affected credentials were still valid. Such behaviors create frustration, discourage reporters and, again, prevent secrets from being reported.

    302 Redirect To Bug Bounty

    Even when a direct communication channel with corporate security teams exists, it happens that those teams redirect mailed reports to a bug bounty platform. The rationale is understandable: centralizing all vulnerability reports in one place simplifies triaging and tracking.

    Doing so not only slows the remediation process down, but also creates a dangerous bottleneck as the submission will likely have to comply with the bug bounty rules and scope definition, with the same pitfall as issues directly reported on platforms.

    It also goes against the potential privacy requirements of the reporter, who would have to create an account on the bug bounty platform and sometimes even fill out tax regulation documents.

    We received such a response when we contacted xAI for a leaked token last year. In that case, the corporate team also fixed the issue in the background, even before we could submit it to their program, demonstrating a clear lack of transparency.

    Dear Gaëtan,
    Thank you for your email.
    For us to analyze and also for you to receive proper credit, if applicable, would you please submit this to xAI's Bug Bounty Program on HackerOne?
    https://hackerone.com/x?type=team
    Thanks!
    xAI Team

    Vulnerability Disclosure Policy done right

    Writing a clear Vulnerability Disclosure Policy that provides an open and transparent communication channel is of prime importance to ensure your company receives vulnerability reports properly. As we explained above, such a policy should promote openness, transparency, and reporters' safety. Privacy is also a core concept of any proper VDP and should be emphasized, as is explained in documents from the US Cybersecurity & Infrastructure Security Agency:

    How should my agency treat vulnerability reports from anonymous sources?
    These reports should be treated the same as all other reports: like a gift. Knowing the source of a report can be a real benefit because it allows for rapport to develop. However, if the person who submits a report isn't known, the claim should simply be evaluated on its merits -- like every other report.

    When bug bounty platforms are your only security communication channel, such privacy can not be appropriately granted to vulnerability reporters.

    In fact, CISA published a complete template for Vulnerability Disclosure Policy that emphasizes those openness and transparency concepts. The document is meant to be a regulatory requirement for government agencies, but it can be used as a basis to write the VDP of any company.

    At GitGuardian, we are not against bug bounty programs, as we think they can be a great addition to a company's security policy. However, it is of prime importance to understand the limits and blind spots created by those platforms.

    Most importantly, bug bounty programs must complement -- not replace -- a public Vulnerability Disclosure Policy. Private, invitation-only programs create insurmountable barriers for new researchers and should never be the sole disclosure channel. Companies should maintain accessible public VDPs alongside any BBP, with clear escalation paths that allow critical reports to bypass platform restrictions when necessary. Direct reports to security@ should remain direct -- triaged by internal teams who understand the full context of their infrastructure, not filtered through external platform scopes that may dismiss legitimate threats on technicalities.

    Especially, if you manage a bug bounty program, make sure to include leaked credentials in its scope. Credentials-based attacks have become the number one cyber threat in the modern world, so those incidents should not be disregarded. Asking and verifying the source of the leaks will allow better investigation of the leak issue while reducing the risk of buying stolen credentials from the black market.

    To conclude, whatever communication channel you choose for your vulnerability reports, make sure to promote it and make it as visible as possible, for example, with an RFC 9116 security.txt file. There is nothing worse than a communication channel no one knows about.

    GitGuardian Interactive Demo

  • DEV Community dev.to community dev-to software-dev technology 2026-08-03 18:54

    ↗

    When running code reviews with local LLMs, a single model can either hallucinate non-existent bugs or generate generic advice you end up ignoring. To make local AI code review more useful, I built a closed Reviewer vs. Verifier loop for local Ollama workflows. The...

    When running code reviews with local LLMs, a single model can either hallucinate non-existent bugs or generate generic advice you end up ignoring.

    To make local AI code review more useful, I built a closed Reviewer vs. Verifier loop for local Ollama workflows.

    The Architecture: Two Local Agents, One Loop

    Instead of trusting one model's output, the workflow splits the job into two roles:

    1. Agent 1 (Reviewer): Reads the git diff or file changes. It searches specifically for logical flaws, security vulnerabilities, edge cases, or missing unit tests.
    2. Agent 2 (Verifier): Takes the Reviewer's list of findings and actively challenges them. If a finding is weak or unsupported, the Verifier pushes it out of the action list. If it holds up, the next step stays visible.

    The goal is not to make the model "always right". The goal is to make weak claims easier to catch before you act on them.

    Why Local-First?

    Many agent workflows eventually ask you to move private workspace context into somebody else's control plane.

    I packaged this workflow into HAICHI, a desktop workspace for Windows and Linux that connects to local Ollama models and keeps the workflow state inspectable.

    Key features:

    • Local-first workflow: Run Reviewer and Verifier style loops around local models.
    • Visible evidence trail: Keep task, review, challenge, and result in one workspace instead of scattered chat tabs.
    • Scoped execution: Keep actions bounded to the workflow you explicitly run.
    • Practical limits: Control how much concurrent agent work runs on your machine.

    Try it on your own code

    HAICHI Personal is free to try.

    • Website: https://haichi.app
    • Supported OS: Windows 10/11, Linux (Ubuntu/Debian/Arch)

    If you're already using Ollama for real development work, test the Reviewer vs. Verifier loop on one change and let me know where it helps, where it is too noisy, and what your local setup looks like.

  • TechCrunch techcrunch.com startups tech-news techcrunch technology 2026-08-03 18:54

    ↗

    Apple has appealed a new legal demand by the U.K. government, which critics say could threaten the privacy rights of users all over the world.

    Apple has appealed a new legal demand by the U.K. government, which critics say could threaten the privacy rights of users all over the world.
  • The Guardian - World theguardian.com guardian news uk world 2026-08-03 18:53

    ↗

    President says he will ‘let the families figure that out’ and calls situation ‘a very sad thing’ when asked if Ohio Republican should step downBlanche formally rescinds Trump’s $1.8bn ‘anti-weaponization fund’Sign up for the US Breaking News emailOn Tuesday, we’ll bring you...

    President says he will ‘let the families figure that out’ and calls situation ‘a very sad thing’ when asked if Ohio Republican should step down

    • Blanche formally rescinds Trump’s $1.8bn ‘anti-weaponization fund’

    • Sign up for the US Breaking News email

    On Tuesday, we’ll bring you the latest from Michigan where voters will head to the polls for competitive primaries in Senate and House races.

    The most closely watched competition is the Democratic primary for the US Senate, where congresswoman Haley Stevens is up against former public health official Abdul El-Sayed. They’re vying to ultimately win the seat of outgoing senator Gary Peters in November. The race has now turned into a proxy battle for the future of the Democratic party. Establishment-backed Stevens has received support from party leaders and her race has been buoyed by millions from the pro-Israel lobby. Meanwhile the insurgent El-Sayed has built a strong grassroots movement and is endorsed by progressives lawmakers in the Democratic caucus.

    Continue reading...
  • The Guardian - US News theguardian.com guardian news uk us 2026-08-03 18:53

    ↗

    President says he will ‘let the families figure that out’ and calls situation ‘a very sad thing’ when asked if Ohio Republican should step downBlanche formally rescinds Trump’s $1.8bn ‘anti-weaponization fund’Sign up for the US Breaking News emailOn Tuesday, we’ll bring you...

    President says he will ‘let the families figure that out’ and calls situation ‘a very sad thing’ when asked if Ohio Republican should step down

    • Blanche formally rescinds Trump’s $1.8bn ‘anti-weaponization fund’

    • Sign up for the US Breaking News email

    On Tuesday, we’ll bring you the latest from Michigan where voters will head to the polls for competitive primaries in Senate and House races.

    The most closely watched competition is the Democratic primary for the US Senate, where congresswoman Haley Stevens is up against former public health official Abdul El-Sayed. They’re vying to ultimately win the seat of outgoing senator Gary Peters in November. The race has now turned into a proxy battle for the future of the Democratic party. Establishment-backed Stevens has received support from party leaders and her race has been buoyed by millions from the pro-Israel lobby. Meanwhile the insurgent El-Sayed has built a strong grassroots movement and is endorsed by progressives lawmakers in the Democratic caucus.

    Continue reading...
  • The Guardian - US theguardian.com guardian headlines news us-news 2026-08-03 18:53

    ↗

    President says he will ‘let the families figure that out’ and calls situation ‘a very sad thing’ when asked if Ohio Republican should step downBlanche formally rescinds Trump’s $1.8bn ‘anti-weaponization fund’Sign up for the US Breaking News emailOn Tuesday, we’ll bring you...

    President says he will ‘let the families figure that out’ and calls situation ‘a very sad thing’ when asked if Ohio Republican should step down

    • Blanche formally rescinds Trump’s $1.8bn ‘anti-weaponization fund’

    • Sign up for the US Breaking News email

    On Tuesday, we’ll bring you the latest from Michigan where voters will head to the polls for competitive primaries in Senate and House races.

    The most closely watched competition is the Democratic primary for the US Senate, where congresswoman Haley Stevens is up against former public health official Abdul El-Sayed. They’re vying to ultimately win the seat of outgoing senator Gary Peters in November. The race has now turned into a proxy battle for the future of the Democratic party. Establishment-backed Stevens has received support from party leaders and her race has been buoyed by millions from the pro-Israel lobby. Meanwhile the insurgent El-Sayed has built a strong grassroots movement and is endorsed by progressives lawmakers in the Democratic caucus.

    Continue reading...
  • ZDNet zdnet.com tech tech-news technology 2026-08-03 18:50

    ↗

    Apple is starting to feel the global memory shortage, with MacBook Air shipments delayed by a month or more.

    Apple is starting to feel the global memory shortage, with MacBook Air shipments delayed by a month or more.
  • The Guardian - US News theguardian.com guardian news uk us 2026-08-03 18:49

    ↗

    US sees first fatalities due to intestinal illness, though both had significant ​underlying health conditionsTwo people have died from cyclosporiasis in Michigan, the state’s health department said on Monday, marking the first fatalities in the largest US outbreak ⁠of the...

    US sees first fatalities due to intestinal illness, though both had significant ​underlying health conditions

    Two people have died from cyclosporiasis in Michigan, the state’s health department said on Monday, marking the first fatalities in the largest US outbreak ⁠of the intestinal illness.

    “According to medical records, both individuals had significant underlying health conditions that may have been impacted by cyclosporiasis and dehydration,” a spokesperson for the Michigan health and human service department told the Guardian in a statement.

    Continue reading...
  • The Guardian - World theguardian.com guardian news uk world 2026-08-03 18:49

    ↗

    US sees first fatalities due to intestinal illness, though both had significant ​underlying health conditionsTwo people have died from cyclosporiasis in Michigan, the state’s health department said on Monday, marking the first fatalities in the largest US outbreak ⁠of the...

    US sees first fatalities due to intestinal illness, though both had significant ​underlying health conditions

    Two people have died from cyclosporiasis in Michigan, the state’s health department said on Monday, marking the first fatalities in the largest US outbreak ⁠of the intestinal illness.

    “According to medical records, both individuals had significant underlying health conditions that may have been impacted by cyclosporiasis and dehydration,” a spokesperson for the Michigan health and human service department told the Guardian in a statement.

    Continue reading...
  • The Guardian - US theguardian.com guardian headlines news us-news 2026-08-03 18:49

    ↗

    US sees first fatalities due to intestinal illness, though both had significant ​underlying health conditionsTwo people have died from cyclosporiasis in Michigan, the state’s health department said on Monday, marking the first fatalities in the largest US outbreak ⁠of the...

    US sees first fatalities due to intestinal illness, though both had significant ​underlying health conditions

    Two people have died from cyclosporiasis in Michigan, the state’s health department said on Monday, marking the first fatalities in the largest US outbreak ⁠of the intestinal illness.

    “According to medical records, both individuals had significant underlying health conditions that may have been impacted by cyclosporiasis and dehydration,” a spokesperson for the Michigan health and human service department told the Guardian in a statement.

    Continue reading...
  • DEV Community dev.to community dev-to software-dev technology 2026-08-03 18:47

    ↗

    A few months back I was running Sales Navigator searches for a client project — filtering down to "VP Sales, fintech, based in Italy or Spain" type lists — and the results were genuinely good. 60, 80 leads that actually matched. Then I hit the part nobody warns you about:...

    A few months back I was running Sales Navigator searches for a client project — filtering down to "VP Sales, fintech, based in Italy or Spain" type lists — and the results were genuinely good. 60, 80 leads that actually matched. Then I hit the part nobody warns you about: there's no button on that page that says "save this."

    So I did what everyone does. Opened a spreadsheet, alt-tabbed back and forth, typed names and job titles by hand. Around profile 40 I gave up and went looking for a better way. This is what I found, roughly in the order I found it, including the tool I ended up building because none of the existing options quite fit what I needed.

    First: the export LinkedIn actually gives you

    LinkedIn has a real, built-in data export, and most people don't realize how narrow it is. It's under your profile photo → Settings & Privacy → Data Privacy → Get a copy of your data. From there you either tick specific categories (that email usually lands within minutes) or request the full archive, which takes closer to a day and sometimes arrives in two batches. Either way you get a download link that expires after 72 hours — and it's desktop only, the mobile app won't let you request one.

    What you get back is genuinely thorough: connections, messages, your own profile history, activity, even the ad-targeting data LinkedIn holds on you. A couple of quirks worth knowing before you rely on it: some connections' email addresses will just be missing, because sharing an email on download is something each person opts into individually, and you won't get a list of who viewed your profile or any "People You May Know" data. If you're in the EU, EEA, or Switzerland, LinkedIn also runs a separate API for pulling your data on a schedule rather than as a one-off request.

    Here's what this export is not built for, though: it has no idea what you searched for yesterday. It's an archive of your own account, not a way to capture a live search. Run a Sales Navigator query and pull 80 leads, and this tool won't touch them — those results aren't "your data," they're a page LinkedIn rendered for you a minute ago. If you want a yearly backup of your own connections and messages, or you're about to deactivate and want a copy first, start here and you're done. If you're trying to get a search result out of the browser, keep reading.

    Second: the manual way, which is what most people actually do

    Copy the name. Copy the title. Copy the company. Paste into a column. Repeat.

    It's fine for five profiles before a call. It's genuinely miserable past fifteen — you lose track of who you've already copied, columns drift out of alignment, and an hour later you've got a spreadsheet that looks like it survived a fall down some stairs. I don't think anyone picks this method so much as ends up in it by default, since it's the only option that needs zero setup.

    If you only do this occasionally, don't overthink it. A blank spreadsheet and fifteen minutes beats installing anything. It only turns into a real problem once you're doing it every week.

    Third: browser extensions, which read what's already on the page

    Once you're pulling data regularly, the next step people reach for is a browser extension, and it's worth understanding what these actually do under the hood — "LinkedIn tool" covers a wide range of behavior, and the range matters.

    The category I trust reads the DOM of the page you're already looking at, the same rendered HTML your browser downloaded to show you the search results, and turns the visible fields into rows in a file. It doesn't call a private API, doesn't need anything beyond the session you're already logged into, and doesn't do anything you didn't ask it to.

    The category I don't trust is the one that also automates actions on your behalf: auto-sending connection requests, auto-messaging, "warming up" a profile with likes. That's a fundamentally different product, and it's the kind of behavior that gets accounts restricted, because LinkedIn's abuse detection is watching for exactly that pattern — a lot of actions, very fast, in a rhythm no human clicks in. Reading a page you're already viewing and writing what you see to a CSV is a much smaller ask than pretending to be a human sending 200 connection requests an hour.

    What I ended up building

    I looked for something that just read search results — Profile, Company, Jobs, and Posts on regular LinkedIn, plus Lead and Account search on Sales Navigator — and either couldn't find it or found it bundled with a dozen automation features I didn't want anywhere near my account. So I built the Mastros LinkedIn & Sales Navigator exporter.

    It's read-only, on purpose. You run a search, the extension recognizes the page and shows you every field it found before you export anything, so you know what you're getting instead of finding out after. Set a limit, hit export, and it drops a CSV, JSON, or JSONL file. CSV opens straight in Excel or Sheets and imports cleanly into a CRM — something like:

    full_name,job_title,company,location
    Marco Bianchi,Head of Partnerships,Nordic Robotics,Turin
    Sara Klein,VP Marketing,Fjord & Co,Copenhagen
    Tomás Silva,Founder,Casa Verde,Lisbon
    

    A few decisions I made on purpose, mostly because they were the things that annoyed me about other tools:

    • Nothing leaves your machine. Extraction runs in your browser; the data never touches a Mastros server. We don't see the names or profiles you save, only that a save happened.
    • No email guessing. It doesn't derive or buy anyone's email address. What's on the page is what you get.
    • Only new records. Turn this on and it skips anything you've already exported, so re-running a search doesn't just duplicate last week's file.
    • Safety pacing. There's an hourly cap that's separate from your monthly plan quota, specifically so a big export doesn't turn into the kind of rapid-fire activity that flags an account. Same reasoning as the automation point above: reading slower, on purpose.
    • No actions, ever. It doesn't send invites, messages, or InMails, and it doesn't like, follow, or apply to anything. You trigger every export yourself; it never acts on your behalf.

    It's free for 250 records a month across all six search types, no card required. Pro is $9/month for 10,000 records with rollover on unused ones, and Scale is $18/month with no record cap from our side — LinkedIn's own rate limits still apply, because claiming otherwise would just be a lie.

    Picking one

    • Backing up your own connections and messages, or prepping to deactivate → LinkedIn's own export. It's free, official, and already good at this.
    • A handful of profiles before a call, once in a while → copy-paste. Don't install anything for five rows.
    • Recurring prospecting, recruiting pipelines, or keeping a CRM fed from live searches → an extension built specifically to read search results, with pacing and dedup baked in. That's the gap the LinkedIn exporter is built to fill.

    One last thing, easy to skip past: whichever method you use, the data is still about real people who didn't sign up to end up in your spreadsheet. Export what you're actually allowed to see, follow LinkedIn's terms, and don't turn a clean CSV into a cold-email blast nobody asked for. That's not a legal disclaimer, it's just the difference between doing research and being the reason someone locks down their privacy settings next week.

    If you want to try it: it's a free Chrome install, 250 records a month, no card needed.

  • The Guardian - US theguardian.com guardian headlines news us-news 2026-08-03 18:46

    ↗

    US president claims talks are ‘not very complex’ as he speaks at White House as Iran’s foreign ministry says there are no talks taking place with USIran in talks with Oman over shipping route but not US, says TehranPeople walk near a billboard depicting Iran’s late supreme...

    US president claims talks are ‘not very complex’ as he speaks at White House as Iran’s foreign ministry says there are no talks taking place with US

    • Iran in talks with Oman over shipping route but not US, says Tehran

    People walk near a billboard depicting Iran’s late supreme leader Ayatollah Ali Khamenei, on a street in Tehran, Iran, earlier today.

    Six Saudi-flagged supertankers have changed course in the Gulf of Aden in recent days amid threats from the Iran-aligned Houthis, Reuters reports.

    Continue reading...
  • The Guardian - World theguardian.com guardian news uk world 2026-08-03 18:46

    ↗

    US president claims talks are ‘not very complex’ as he speaks at White House as Iran’s foreign ministry says there are no talks taking place with USIran in talks with Oman over shipping route but not US, says TehranPeople walk near a billboard depicting Iran’s late supreme...

    US president claims talks are ‘not very complex’ as he speaks at White House as Iran’s foreign ministry says there are no talks taking place with US

    • Iran in talks with Oman over shipping route but not US, says Tehran

    People walk near a billboard depicting Iran’s late supreme leader Ayatollah Ali Khamenei, on a street in Tehran, Iran, earlier today.

    Six Saudi-flagged supertankers have changed course in the Gulf of Aden in recent days amid threats from the Iran-aligned Houthis, Reuters reports.

    Continue reading...
  • The Guardian - World theguardian.com guardian news uk world 2026-08-03 18:45

    ↗

    Joshua Bonehill-Paine, creator of satirical Crewkerne Gazette, has convictions including harassment of a Jewish MPA former neo-Nazi activist with convictions including for harassing a Jewish MP has been selected as a Conservative candidate for a local election in...

    Joshua Bonehill-Paine, creator of satirical Crewkerne Gazette, has convictions including harassment of a Jewish MP

    A former neo-Nazi activist with convictions including for harassing a Jewish MP has been selected as a Conservative candidate for a local election in Somerset.

    Joshua Bonehill-Paine, the creator of the viral Crewkerne Gazette series of AI clips, is due to stand for election to Somerset council next year in a new Crewkerne South district. He told the Guardian he was an executive member of the Tories’ Yeovil branch, working as an events organiser.

    Continue reading...
  • NPR - Top Stories npr.org headlines news npr public-broadcaster us us-news 2026-08-03 18:45

    ↗

    Wildfires in Spokane have destroyed hundreds of homes and led to evacuation orders for 60,000 people.

    Chris Mutton, left, whose house burned in a wildfire speaks with Shane Maggart on Aug. 2, 2026, in Spokane, Wash.

    Wildfires in Spokane have destroyed hundreds of homes and led to evacuation orders for 60,000 people.

    (Image credit: Young Kwak/AP)

  • The Hacker News thehackernews.com cybersecurity security tech-news technology 2026-08-03 18:43

    ↗

    Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking...

    Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments. One of the packages in question is "lib-mtop," an unscoped package with the same name as a private Alibaba package
  • DEV Community dev.to community dev-to software-dev technology 2026-08-03 18:43

    ↗

    After working on enterprise applications and distributed microservices, I have realized that the biggest challenges rarely come from writing business logic. They come from handling production traffic, failures, concurrency, and unexpected edge cases. Here are seven lessons...

    After working on enterprise applications and distributed microservices, I have realized that the biggest challenges rarely come from writing business logic. They come from handling production traffic, failures, concurrency, and unexpected edge cases.

    Here are seven lessons that every Spring Boot developer should know before calling themselves a senior engineer.

    1. Never Assume an API Will Be Called Only Once

    One of the most common mistakes is assuming a client sends exactly one request.

    In reality:

    • Users refresh the page.
    • Mobile apps retry automatically.
    • API gateways retry requests.
    • Kafka consumers may reprocess events.
    • Network failures cause duplicate submissions.

    If your endpoint creates an order, payment, or booking every time it receives a request, duplicates are almost guaranteed.

    Better Approach

    Design APIs to be idempotent.

    For example:

    • Use an Idempotency-Key.
    • Store processed request IDs.
    • Ignore duplicate requests safely.

    Production systems should always expect duplicate requests.

    2. Database Transactions Are Not Enough

    Many developers believe this solves everything:

    @Transactional
    public void createOrder() {
        ...
    }
    

    It doesn't.

    A transaction protects changes inside a single database.

    It does not protect:

    • Kafka publishing
    • Email sending
    • External REST APIs
    • Redis updates
    • File uploads

    If your database commits successfully but Kafka publishing fails, your system is already inconsistent.

    Better Approach

    Use patterns such as:

    • Transactional Outbox
    • Saga Pattern
    • Event-driven architecture
    • Retry with dead-letter queues

    3. Don't Trust External APIs

    Every external service will eventually fail.

    Your payment provider.

    Your authentication service.

    Your notification service.

    Even your own internal microservices.

    Never assume another service is always available.

    Add Protection

    • Timeouts
    • Retries
    • Circuit Breakers
    • Fallback logic
    • Monitoring

    Failing fast is usually better than waiting forever.

    4. Logging Is More Valuable Than You Think

    When production goes down, nobody asks:

    "Was the code clean?"

    Everyone asks:

    "What happened?"

    Poor logging turns a five-minute issue into a five-hour investigation.

    Good Logs Include

    • Correlation ID
    • Request ID
    • User ID (where appropriate)
    • Service name
    • Execution time
    • Error details

    Avoid logging entire request bodies or sensitive information.

    Logs should help you debug—not create new security problems.

    5. Performance Problems Usually Start in the Database

    Most slow APIs aren't caused by Java.

    They're caused by:

    • Missing indexes
    • N+1 queries
    • Loading unnecessary data
    • Multiple database calls inside loops

    Before optimizing Java code:

    • Check SQL execution plans.
    • Measure database latency.
    • Cache frequently used data.
    • Fetch only what you need.

    Always measure before optimizing.

    6. Handle Concurrency Explicitly

    Concurrency bugs are among the hardest to reproduce.

    Imagine two requests arriving at exactly the same time:

    Request A
    Request B
    
    Both check:
    Balance = ₹100
    
    Both withdraw ₹100
    
    Final Balance = -₹100
    

    Everything worked correctly from each request's perspective.

    Together, they corrupted the data.

    Solutions

    • Optimistic Locking
    • Pessimistic Locking
    • Distributed Locks
    • Atomic database updates
    • Idempotent operations

    Concurrency isn't a rare edge case.

    It's a daily production reality.

    7. Monitoring Is Part of the Application

    If you can't observe your application, you can't operate it.

    Every production service should expose:

    • Health checks
    • Metrics
    • Request latency
    • Error rates
    • JVM metrics
    • Database latency
    • Kafka consumer lag

    Modern observability tools include:

    • Micrometer
    • Prometheus
    • Grafana
    • OpenTelemetry
    • ELK Stack

    The best production incidents are the ones users never notice because your monitoring detected them first.

    Final Thoughts

    Being a senior Spring Boot developer isn't about memorizing annotations or frameworks.

    It's about designing systems that continue to work when networks fail, traffic spikes, duplicate requests arrive, and dependencies become unavailable.

    Production engineering is less about writing more code and more about building software that remains reliable under real world conditions.

    If you're just starting your backend journey, focus on these concepts early. They'll have a much bigger impact on your career than learning another framework.

    Java #SpringBoot #Microservices #Backend #SoftwareEngineering #SystemDesign #DistributedSystems #Kafka #Programming #DevOps

  • TechCrunch techcrunch.com startups tech-news techcrunch technology 2026-08-03 18:43

    ↗

    Apple’s long-awaited AI overhaul finally makes Siri the assistant it was always supposed to be. But after years of delays, the launch lands in an AI landscape where chatbots have evolved into agents that can code, reason, create media, and complete complex tasks. Siri AI is...

    Apple’s long-awaited AI overhaul finally makes Siri the assistant it was always supposed to be. But after years of delays, the launch lands in an AI landscape where chatbots have evolved into agents that can code, reason, create media, and complete complex tasks. Siri AI is genuinely useful, yet it arrives at a moment when simply being a capable AI assistant no longer feels revolutionary.
  • Phys.org phys.org phys-org physics research-news science 2026-08-03 18:40

    ↗

    When a hurricane roars toward land, forecasters try to predict how high sea levels will rise to help coastal communities prepare for the worst impacts.

    When a hurricane roars toward land, forecasters try to predict how high sea levels will rise to help coastal communities prepare for the worst impacts.
  • Phys.org phys.org phys-org physics research-news science 2026-08-03 18:40

    ↗

    Students who open a personal social media account earlier in adolescence appear to perform worse on later standardized tests, according to a study in Nature Human Behaviour based on 5,227 Italian students. The authors speculate that these differences may be attributable to...

    Students who open a personal social media account earlier in adolescence appear to perform worse on later standardized tests, according to a study in Nature Human Behaviour based on 5,227 Italian students. The authors speculate that these differences may be attributable to excessive social media engagement and disruptions to students' attention.
  • Kotaku kotaku.com culture gaming kotaku reviews 2026-08-03 18:40

    ↗

    I swear I'll be more organized this time

    I swear I'll be more organized this time
  • Design Milk design-milk.com art design design-milk fashion interiors tech 2026-08-03 18:39

    ↗

    After debuting at Burning Man, Jen Lewin’s towering bear sculptures now anchor Brooklyn’s Gowanus waterfront

    Jen Lewin’s Monumental ‘Ursas’ Find a Permanent Home Along the Gowanus Canal

    For many public artworks, permanence is the exception rather than the rule. Jen Lewin’s The Ursas, however, has made the uncommon leap from the ephemeral landscape of Burning Man to a permanent installation along Brooklyn’s evolving Gowanus waterfront, where the monumental sculptures now anchor a newly accessible stretch of the canal.

    A metallic sculpture, Jen Lewin The Ursas, is being installed on a bridge over a canal in a city, with modern high-rise buildings and construction cranes in the background.

    ‘The Ursas’ were installed at their new home along the Gowanus Canal on Aug. 1. Photography by Diane Bondareff/AP Content Services for Charney Companies and Tavros.

    Installed at Nevins Landing on Aug. 1, the paired sculptures occupy a prominent position between the residential towers and the canal. The development, designed by Fogarty Finger with waterfront landscape architecture by Field Operations, is part of the larger Gowanus Wharf campus. The project adds a new public landmark to a neighborhood undergoing dramatic physical and cultural transformation, as former industrial sites are increasingly giving way to housing, parks, and civic spaces.

    Workers on a lift install Jen Lewin’s The Ursas, a striking geometric animal sculpture, in an urban setting surrounded by high-rise buildings and construction scaffolding.

    Photography by Diane Bondareff/AP Content Services for Charney Companies and Tavros

    Inspired by the Ursa Major and Ursa Minor constellations, The Ursas explores ideas of navigation, orientation, and environmental stewardship. The larger of the two works, Ursa Major, rises 30 feet and is constructed from reclaimed ocean plastic originally sourced from Lewin’s 2022 installation The Last Ocean. Visitors can step inside the sculpture, where an infinity-mirrored chamber contains hand-drawn illustrations of species listed as extinct or presumed extinct on the IUCN Red List. Beside it, the 13-foot-tall Ursa Minor is clad in infinity mirrors and programmable LED lighting that creates an ever-shifting sense of depth and reflection.

    Construction workers install two large geometric bear sculptures from Jen Lewin’s The Ursas outdoors in an urban area, with modern buildings and a forklift visible in the background.

    Photography by Diane Bondareff/AP Content Services for Charney Companies and Tavros

    “The Ursas grew out of my research into the melting Ross Ice Shelf while developing The Last Ocean,” Lewin says. “What began as scientific inquiry became a personal reckoning with the scale and speed of environmental change.”

    Lewin describes Ursa Minor as “a beacon” seeking the North Star, while Ursa Major carries illustrations honoring recently extinct species. “Together, the works hold two realities at once: grief and responsibility, but also direction,” she explains. “They ask us not only to reflect, but to decide how we move forward.”

    Workers in safety vests install Jen Lewin’s The Ursas, a large geometric animal sculpture, next to a wrapped sculpture on a city waterfront construction site.

    Photography by Diane Bondareff/AP Content Services for Charney Companies and Tavros

    The installation also marks a notable moment for Gowanus, where public art is increasingly being positioned as part of broader neighborhood redevelopment rather than an afterthought. The Ursas become one of the first permanent artworks to define the identity of the four-building Gowanus Wharf campus, which will ultimately introduce more than 2,200 residential units alongside publicly accessible waterfront space.

    Before arriving at their new home, the sculptures made a dramatic journey across the Verrazzano-Narrows Bridge before being hoisted over Brooklyn’s Union Street Bridge and lowered into place along the canal. What began as a temporary installation in the Nevada desert in 2023 is now part of the everyday fabric of the city.

    Editorial Transparency: This article was developed with the assistance of AI tools, which may have been used for research, outlining, editing, or copy refinement. Reporting, fact-checking, and editorial decisions were made by the Design Milk editorial team.

  • Reason reason.com news politics us-news us-politics 2026-08-03 18:39

    ↗

    The article is here; the Abstract: This paper examines how the European Court of Human Rights' (ECt­HR or Court) hate… The post Journal of Free Speech Law: "Positive Obligations, Hate Speech, and the Reconfiguration of Free Expression at the European Court of Human Rights,"...

    The article is here; the Abstract:

    This paper examines how the European Court of Human Rights' (ECt­HR or Court) hate speech jurisprudence has been structurally reoriented by the Court's response to an increasing number of applications brought by victims of hate speech. Whereas earlier case law predominantly assessed hate speech under Article 10 of the European Convention on Human Rights, focusing on the permissibility of restrictions on expression, recent victim-initiated claims have directed the ECtHR's analysis towards Articles 8 and 14 and thus towards the question of State responsibility for pro­tec­tion against harm caused by third-party speech.

    Through a reading of the ECtHR's case law, this paper shows how the Court's response to this applicant-driven expansion has recalibrated the balance between dignity, equality, and freedom of expression. The paper argues that the resulting framework risks limiting the doctrinal safeguards traditionally associated with Article 10 analysis.

    In addition, there has been an increasingly expansive understanding of who qualifies as a "victim" of hate speech, extending this qualification beyond direct targets who are in protected groups to include individuals who are merely associated with such groups. The paper argues that the Court's expanding expectation of positive obligations owed by States to their citizens in relation to the exercise of their rights may incentivize over-intervention by domestic authorities and chill legitimate public debate.

    The post Journal of Free Speech Law: "Positive Obligations, Hate Speech, and the Reconfiguration of Free Expression at the European Court of Human Rights," by Natalie Alkiviadou appeared first on Reason.com.

  • The Guardian - World theguardian.com guardian news uk world 2026-08-03 18:37

    ↗

    Restore leader has countered charges he’s splitting the right while showing his party is a very real obstacle for ReformEven by the standards of their rivalry, the speed at which Rupert Lowe’s olive branch to Nigel Farage morphed into fresh recriminations between the two was...

    Restore leader has countered charges he’s splitting the right while showing his party is a very real obstacle for Reform

    Even by the standards of their rivalry, the speed at which Rupert Lowe’s olive branch to Nigel Farage morphed into fresh recriminations between the two was swift.

    It began with a softly lit 12-minute video posted on Sunday by the Restore Britain leader, looking straight to camera and referring to “Nigel” as he suggested his party could be willing to cast aside its differences with Reform UK and work together.

    Continue reading...
  • DEV Community dev.to community dev-to software-dev technology 2026-08-03 18:35

    ↗

    Una discusión sobre un archivo digital casi nunca se pierde por lo que el archivo dice. Se pierde una pregunta antes: ¿Cómo sabemos que ese es el archivo que usted recibió, y no el que editó anoche? Si la respuesta es "confíe en mí", ya perdiste. Y da igual cuánta razón...

    Una discusión sobre un archivo digital casi nunca se pierde por lo que el archivo
    dice. Se pierde una pregunta antes:

    ¿Cómo sabemos que ese es el archivo que usted recibió, y no el que editó anoche?

    Si la respuesta es "confíe en mí", ya perdiste. Y da igual cuánta razón tengas en
    el fondo.

    Este problema no es exclusivo de un juzgado. Lo tiene el auditor que recibe un
    volcado de logs, el equipo que documenta un incidente, quien conserva la copia de
    un contrato firmado por correo. En todos los casos hace falta lo mismo: poder
    demostrar que un conjunto de bytes no cambió desde un momento determinado, y que
    lo demuestre alguien que no seas tú.

    Para eso escribí Tunjo: una
    herramienta en Rust que recorre un material en solo lectura, calcula su huella y
    firma un acta verificable por cualquiera.

    Por qué un árbol y no un hash

    Lo obvio sería concatenar todo y sacar un SHA-256. Funciona, y es inútil en la
    práctica.

    Cuando alguien discute un archivo —un correo concreto entre cuatro mil— con
    un hash único solo puedes ofrecer dos cosas: o entregas el conjunto completo para
    que se recalcule, o pides que te crean. La primera opción expone material que no
    tiene por qué exponerse; la segunda no es una prueba.

    Un árbol de Merkle resuelve exactamente eso. Cada archivo es una hoja, cada par
    de nodos se combina hacia arriba y queda una raíz. Para demostrar que una hoja
    pertenece a esa raíz basta con exhibir esa hoja y el camino de hashes hasta
    arriba: unos pocos kilobytes. El resto del conjunto no se toca.

    Dos detalles del árbol que no son opcionales:

    // Separación de dominio: una hoja nunca puede hacerse pasar por nodo interno.
    h.update([0x00]);          // hoja
    h.update([0x01]);          // nodo interno
    
    // Y la raíz ata el número de hojas.
    h.update([0x02]);
    h.update(n.to_be_bytes());
    

    Sin lo primero, un hash de hoja podría presentarse como si fuera un nodo del
    árbol. Sin lo segundo aparece la ambigüedad clásica de los árboles con número
    impar de hojas: dos conjuntos distintos pueden producir la misma raíz. Es un
    error viejo y conocido, y sigue apareciendo en implementaciones nuevas.

    La huella cubre el estado, no solo el contenido

    La hoja no es el hash del archivo: es el hash del elemento completo —ruta,
    tamaño, fecha, estado y hash del contenido—.

    La diferencia importa. Si la huella fuera solo del contenido, mover un archivo de
    carpeta, renombrarlo o sustituirlo por un enlace que apunta al mismo contenido
    dejaría la raíz intacta. Y esos tres movimientos cambian lo que el conjunto
    significa: dónde estaba un documento es parte del hecho que se documenta, no un
    detalle de presentación.

    Firmar para dentro de diez años

    El acta se firma con la firma triple-híbrida de
    Quipu: Ed25519 + ML-DSA-87 (FIPS 204)

    • SLH-DSA-SHA2-256s (FIPS 205), y las tres deben validar.

    No es coleccionismo de algoritmos. Es que la vida útil de esto no se mide en
    meses: un expediente puede tardar años en resolverse, y la firma tiene que seguir
    verificándose al final. Las tres piezas fallan por motivos distintos —Ed25519
    frente a un ordenador cuántico; ML-DSA por ser reciente y basada en retículos;
    SLH-DSA solo si se rompe la función hash— y hacen falta las tres a la vez para
    que el sello valga. Que caiga una no tumba el acta.

    El coste es honesto: la firma pesa unos 34 KB. Para sellar un conjunto de
    archivos, es ruido.

    Verificar la firma no basta

    Este es el error que más fácil se comete al implementar algo así. La firma cubre
    el JSON completo del acta, incluida la raíz de integridad. Si al verificar te
    limitas a comprobar la firma, das por buena una raíz que nadie recalculó: alguien
    con la clave podría firmar un acta cuya raíz no corresponde a los elementos que
    lista, y pasaría el control.

    Por eso la verificación recalcula el árbol siempre, y solo después mira la firma.
    Hay una prueba dedicada a ese caso exacto: firma auténtica sobre raíz mentirosa
    debe fallar.

    $ tunjo verificar acta.json --origen ./evidencia
    SELLO VÁLIDO
      contenido:  4 elementos, 3 con contenido verificable
      raíz:       d9f6f68f591c6af087838dc27049a4194ab70525c350b79ec22446f9c12f9e33
    
    1 DISCREPANCIA(S) contra evidencia:
    
    ALTERADO   adjuntos/c.pdf
               acta: 3fdbaf9c795e22f14e16974c37b62ed381b9c8c4ac7bcbe1a01f13d08ec46643
               disco: 9af5d94042eafbf2c335aa874085b263ff0201aee5e5033fd4c432e92de0093d
    

    Ante la ausencia de un dato, ruido

    Una herramienta de integridad que disimula sus fallos es peor que no tenerla,
    porque produce confianza sin respaldo. Tres decisiones al respecto:

    Un archivo ilegible detiene el sellado. No se salta en silencio. Si de verdad
    es ilegible, hay que pedirlo explícitamente y entonces el acta lo registra como
    error: de ese elemento consta que existía y que la lectura falló, y nada más.

    Del reloj se dice la verdad. El acta pide declarar cómo se contrastó con una
    fuente externa. Si no se declara, escribe "NO VERIFICADO" en lugar de callarlo.
    Sin sello de tiempo de un tercero, esto prueba orden relativo, no fecha cierta —y
    también lo dice.

    Los enlaces simbólicos no se siguen. Se registra a dónde apuntan. Seguirlos
    sacaría la adquisición del material que se recibió.

    Lo que deliberadamente no hace

    No detecta intrusiones, no atribuye autoría y no concluye nada. Podría añadirle
    heurísticas que dijeran "aquí hubo un ataque", y sería un error: quien firma un
    informe tiene que poder defender cada afirmación línea por línea, y nadie defiende
    una heurística que no escribió. Cuando esa afirmación se cae, arrastra al resto
    del informe.

    Tampoco prueba el pasado. Acredita desde el instante de la adquisición: si el
    material ya venía alterado, el sello certifica fielmente material alterado. Está
    escrito en el acta que genera, no en la letra pequeña.

    El verificador es público, y no por generosidad

    Si el único que puede comprobar un sello es quien lo emitió, no es una prueba: es
    una afirmación con formato técnico. Por eso el verificador es software libre y su
    código está publicado.

    Lo comprobé de la única forma que vale: cloné el repositorio público en una
    máquina limpia, lo compilé desde cero y con ese binario verifiqué un acta
    sellada por otro. Válida. Después alteré un byte de un adjunto y el mismo binario
    señaló ese archivo y solo ese.

    git clone https://github.com/isazajuancarlos/tunjo
    cd tunjo && cargo build --release
    ./target/release/tunjo verificar acta.json --origen ./evidencia
    

    Rust, AGPL-3.0, y las pruebas incluyen una simulación de 240 contrastes: se altera
    un byte de cada uno de 120 archivos y se exige que señale ese y solo ese, y que al
    restaurarlo no queden falsos positivos. Detectar es fácil; discriminar es el
    trabajo.

  • Engadget engadget.com engadget gadgets reviews tech technology 2026-08-03 18:30

    ↗

    Before you go spend money on new headphones, try these adjustments. You can probably improve the sound on the ones you have.

    Before you go spend money on new headphones, try these adjustments. You can probably improve the sound on the ones you have.

  • The Guardian - World theguardian.com guardian news uk world 2026-08-03 18:27

    ↗

    US president reduced to bemoaning Tehran’s ‘unbelievable duplicity’ as he struggles to find solid negotiating groundMiddle East crisis live – latest updatesThe Donald Trump doctrine has always contained a tenuous relationship with the truth. It was his mentor, the infamous...

    US president reduced to bemoaning Tehran’s ‘unbelievable duplicity’ as he struggles to find solid negotiating ground

    • Middle East crisis live – latest updates

    The Donald Trump doctrine has always contained a tenuous relationship with the truth. It was his mentor, the infamous New York lawyer Roy Cohn, who taught the young real estate mogul always to claim victory and never to admit defeat. Unfortunately for Trump, in Iran the US president has found a counterpart just as stubborn as himself.

    As Trump claims new negotiations are to begin with Tehran this week, Iran has shown it can also reignite the conflict by lobbing ballistic missiles at US bases in the region and maintaining a stranglehold on the strait of Hormuz, effectively taking initiative in the stalled peace process. And time is of the essence for Trump as the clock ticks toward a global energy crisis and a painful midterm elections for him and his Republican party.

    Continue reading...
  • Polygon polygon.com gaming polygon reviews voxel-media 2026-08-03 18:27

    ↗

    A new security measure meant to thwart bots might mean that TCG products like the UPC won't be purchased primarily by scalpers

    Trading card game fans have spent the last few weeks feeling anxious, as The Pokémon Center slowly doles out new waves of 30th anniversary pre-orders. So far, the prevalence of bots programmed to make lightning-fast purchases while collectors wait for hours has made every drop a miserable affair. Much of the time, scalpers clean out the best products before most people can even load the page. But now, The Pokémon Company might finally be putting an end to that nightmare.

  • DEV Community dev.to community dev-to software-dev technology 2026-08-03 18:27

    ↗

    Canonical URL: https://blog.1001020.xyz/ Suggested cover image: use a recent image from https://blog.1001020.xyz/gallery I have been building a small publishing system called 1001020, a serverless blog and AI gallery running on Cloudflare Workers. The live site is here:...

    Canonical URL: https://blog.1001020.xyz/

    Suggested cover image: use a recent image from https://blog.1001020.xyz/gallery

    I have been building a small publishing system called 1001020, a serverless blog and AI gallery running on Cloudflare Workers.

    The live site is here: 1001020 — AI Gallery & Cloudflare Experiments

    The goal was not to build another static blog generator. I wanted something that could publish articles, serve an image gallery, manage uploaded assets, expose structured sitemaps, and stay operational without a traditional server.

    The basic architecture

    The whole public site runs on Cloudflare Workers. Articles, settings, comments, gallery metadata, and telemetry live in Cloudflare KV. Managed images are stored in R2 and served through a dedicated image domain.

    The main pieces are:

    • Cloudflare Workers for request routing and rendering
    • Cloudflare KV for article and site metadata
    • Cloudflare R2 for managed image uploads
    • A theme system for different frontend layouts
    • XML sitemap and image sitemap generation
    • A small local AI drafting tool for preparing and publishing content

    The gallery is a first-class part of the site, not just a media folder. You can browse it here: AI Gallery on 1001020

    Why Workers instead of a conventional backend?

    For this project, Workers are a good fit because the workload is mostly request routing, HTML generation, metadata reads, and small API writes. A conventional server would work, but it would add deployment and maintenance overhead that I did not need.

    Cloudflare Workers also make it easy to keep the app close to the edge while still handling dynamic behavior. The blog can render pages server-side, expose APIs, and support admin operations without a separate Node or container deployment.

    KV as the content store

    The project stores persistent content in KV using explicit keys for articles, gallery records, settings, telemetry, comments, newsletter subscribers, and other small datasets.

    This shape works well for a personal publishing system because the access pattern is simple:

    • read the article index
    • read individual article records
    • write admin updates
    • render HTML or markdown responses
    • regenerate sitemap output from current content

    The main tradeoff is that KV is not a relational database. I keep data models small and explicit, and avoid pretending it can do arbitrary query workloads.

    R2 for images

    Images are uploaded as managed assets and served from R2. Article content can reference those managed image URLs, and the system tracks image references so unused assets can be identified and cleaned up.

    That part matters because image-heavy blogs tend to accumulate stale files quickly. Treating image references as part of the content model keeps the gallery and article system easier to maintain.

    SEO basics that are built in

    The site now ships with the boring but important search plumbing:

    • sitemap.xml
    • image-sitemap.xml
    • robots.txt
    • server-rendered article content
    • image dimensions for layout stability
    • canonical article URLs
    • Google Search Console verification token injection through the admin settings page

    One article that explains part of the agent workflow direction is here: Agent Harness Loop and Graph Engineering

    What I learned

    The biggest lesson is that a serverless blog should not be treated as a toy static page. Once publishing, images, metadata, admin operations, analytics, and sitemaps enter the picture, the system starts to look like a small CMS.

    Cloudflare Workers can handle that shape well, but only if the storage model stays simple and the routes remain deliberate.

    For 1001020, the result is a compact publishing stack that can run globally without a traditional backend server:

    • live site: https://blog.1001020.xyz/
    • AI gallery: https://blog.1001020.xyz/gallery
    • example article: https://blog.1001020.xyz/article/agent-harness-loop-graph-engineering

    I am still iterating on the publishing workflow, but the core system is now stable enough to share.

  • The Guardian - US News theguardian.com guardian news uk us 2026-08-03 18:23

    ↗

    Hundreds of structures damaged as firefighters battle to contain 15 major wildfires amid extreme heat and droughtFirefighters in Washington state are battling wildfires that have forced 60,000 people to flee and destroyed hundreds of buildings as drought and extreme heat fuel...

    Hundreds of structures damaged as firefighters battle to contain 15 major wildfires amid extreme heat and drought

    Firefighters in Washington state are battling wildfires that have forced 60,000 people to flee and destroyed hundreds of buildings as drought and extreme heat fuel an “extraordinary” fire season in the Pacific north-west.

    Fifteen major blazes are raging across the state, David Upthegrove, the head of Washington’s department of natural resources, told reporters over the weekend.

    Continue reading...
  • The Guardian - World theguardian.com guardian news uk world 2026-08-03 18:23

    ↗

    Hundreds of structures damaged as firefighters battle to contain 15 major wildfires amid extreme heat and droughtFirefighters in Washington state are battling wildfires that have forced 60,000 people to flee and destroyed hundreds of buildings as drought and extreme heat fuel...

    Hundreds of structures damaged as firefighters battle to contain 15 major wildfires amid extreme heat and drought

    Firefighters in Washington state are battling wildfires that have forced 60,000 people to flee and destroyed hundreds of buildings as drought and extreme heat fuel an “extraordinary” fire season in the Pacific north-west.

    Fifteen major blazes are raging across the state, David Upthegrove, the head of Washington’s department of natural resources, told reporters over the weekend.

    Continue reading...
  • The Guardian - US theguardian.com guardian headlines news us-news 2026-08-03 18:23

    ↗

    Hundreds of structures damaged as firefighters battle to contain 15 major wildfires amid extreme heat and droughtFirefighters in Washington state are battling wildfires that have forced 60,000 people to flee and destroyed hundreds of buildings as drought and extreme heat fuel...

    Hundreds of structures damaged as firefighters battle to contain 15 major wildfires amid extreme heat and drought

    Firefighters in Washington state are battling wildfires that have forced 60,000 people to flee and destroyed hundreds of buildings as drought and extreme heat fuel an “extraordinary” fire season in the Pacific north-west.

    Fifteen major blazes are raging across the state, David Upthegrove, the head of Washington’s department of natural resources, told reporters over the weekend.

    Continue reading...
  • Loading more…
Maibook — your private personalized AI community
  • rcanand.com
  • mlaillc.com
  • @rcanand (X)
  • LinkedIn
  • Feedback
  • Credits