04-29 07:58 · 开源,文件传输,隐私,跨平台,本地通信
Localsend: An open-source cross-platform alternative to AirDrop
Homepage • Discord • GitHub • Codeberg
English (Default) • Español • فارسی • Filipino • Français • Indonesia • Italiano • 日本語 • ភាសាខ្មែរ • 한국어 • Polski • Português Brasil • Русский • ภาษาไทย • Türkçe • Українська • Tiếng Việt • 中文
LocalSend is a free, open-source app that allows you to securely share files and messages with nearby devices over your local network without needing an internet connection.
- About
- Sponsors
- Screenshots
- Download
- How It Works
- Getting Started
- Contributing
- Troubleshooting
- Building
LocalSend is a cross-platform app that enables secure communication between devices using a REST API and HTTPS encryption. Unlike other messaging apps that rely on external servers, LocalSend doesn't require an internet connection or third-party servers, making it a fast and reliable solution for local communication.
Browser testing via
It is recommended to download the app either from an app store or from a package manager because the app does not have an auto-update.
Read more about distribution channels.
Caution
Unofficial MSIX preview: you can try builds from the latest commits at localsend.ob-buff.dev. Stability is not guaranteed and all custom code tweaks are listed on that site.
Compatibility
In most cases, LocalSend should work out of the box. However, if you are having trouble sending or receiving files, you may need to configure your firewall to allow LocalSend to communicate over your local network.
Also make sure to disable AP isolation on your router. It should be usually disabled by default but some routers may have it enabled (especially guest networks). See troubleshooting for more information.
Portable Mode
(Introduced in v1.13.0)
Create a file named settings.json
located in the same directory as the executable.
This file can be empty.
The app will use this file to store settings instead of the default location.
Start hidden
(Updated in v1.15.0)
To start the app hidden (only in tray), use the --hidden
flag (example: localsend_app.exe --hidden
).
On v1.14.0 and earlier, the app starts hidden if autostart
flag is set, and the hidden setting is enabled.
LocalSend uses a secure communication protocol that allows devices to communicate with each other using a REST API. All data is sent securely over HTTPS, and the TLS/SSL certificate is generated on the fly on each device, ensuring maximum security.
For more information on the LocalSend Protocol, see the documentation.
To compile LocalSend from the source code, follow these steps:
- Install Flutter directly or using fvm (see version required)
- Install Rust
- Clone the
LocalSend
repository - Run
cd app
to enter the app directory - Run
flutter pub get
to download dependencies - Run
flutter run
to start the app
Note
LocalSend currently requires an older Flutter version (specified in .fvmrc)
and thus build issues may be caused by a mismatch between the required and the (system-wide) installed Flutter version.
To make development more consistent, LocalSend uses fvm to manage the project Flutter version.
After installing fvm
, run fvm flutter
instead of flutter
.
We welcome contributions from anyone interested in helping improve LocalSend. If you'd like to contribute, there are a few ways to get involved:
You can help translate LocalSend into other languages. We use the Weblate platform to manage translations.
Alternatively, you can also contribute by forking this repository and adding translations manually.
The translations are located in the app/assets/i18n directory. Edit the _missing_translations_<locale>.json
or strings_<locale>.i18n.json
file to add or update translations.
Take note: Fields decorated with @
are not meant to be translated; they are not used in the app in any way, being merely informative text about the file or to give context to the translator.
- Bug Fixes: If you find a bug, please create a pull request with a clear description of the issue and how to fix it.
- Improvements: Have an idea for how to improve LocalSend? Please create an issue first to discuss why the improvement is needed.
For more information, see the contributing guide.
These commands are intended for maintainers only. Make sure to run them from the app
directory.
Traditional APK
flutter build apk
AppBundle for Google Play
flutter build appbundle
flutter build ipa
flutter build macos
Traditional
flutter build windows
Local MSIX App
flutter pub run msix:create
Store ready
flutter pub run msix:create --store
Traditional
flutter build linux
AppImage
appimage-builder --recipe AppImageBuilder.yml
Snap
Instructions in localsend/snap/README.md
▸ 展开全文
04-29 07:57 · 类脑计算,神经科学,AI架构,学术前沿,基础研究
Behavioral timescale synaptic plasticity rewires the brain after an experience
Introduction
Every experience we have changes our brain, the way a ceramicist reshapes a slab of clay. Every corner we turn, every conversation we have, every shudder we feel causes cascading effects: Chemicals are released, electricity surges, the connections between brain cells tighten, and our mental models update.
The brain is “incredibly plastic, and it stays that way throughout the lifespan of a human,” said Christine Grienberger, a neuroscientist at Brandeis University. This plasticity, the quality of being easily reshaped, makes the brain really good at learning — a quintessential process that allows us to remember the plotline of a novel, navigate a new city, pick up a new language, and avoid touching a hot stove. But neuroscientists are still uncovering fundamental rules that describe how neuroplasticity reshapes brain connections.
Recently, neuroscientists described a new form of neuroplasticity that might be helping the brain learn across a timescale of several seconds — long enough to capture the behavioral process of learning from a single experience. In two recent reviews, published in The Journal of Neuroscience and Nature Neuroscience, they describe “behavioral timescale synaptic plasticity,” or BTSP. This type of learning in the hippocampus, the brain’s memory hub, is caused by an electrical change that affects multiple neurons at once and unfolds across several seconds. Researchers suspect that it may help the brain learn in a single attempt.
“It’s pretty clear that [BTSP is] a strong, powerful mechanism that can lead to immediate memory formation,” said Daniel Dombeck, a neuroscientist at Northwestern University who was not involved with the theory’s development. “It’s something that has been missing in the field for a long time.”
By uncovering BTSP, neuroscientists have unraveled more of the story of how the brain changes with experience, bringing us closer to understanding how learning happens. “Neuroplasticity is … one of the last frontiers of the brain,” said Attila Losonczy, a neuroscientist at the University of Texas Southwestern Medical Center who studies BTSP. “If we understand this, I think we take a major step towards understanding how the brain works.”
A Plastic Brain
Today, neuroplasticity is taken as fact, but for much of the 150-year history of neuroscience, the adult brain was thought to be static. “The idea that the adult brain can change wasn’t actually widely accepted until very late [in] the history of modern neuroscience,” said Moheb Costandi, a trained neuroscientist and author of Neuroplasticity, a primer from MIT Press. “It was taken for granted that the adult human brain can’t change.” In 1928, Santiago Ramón y Cajal, the oft-cited founder of modern neuroscience, wrote that “in adult centers the nerve paths are something fixed, ended, immutable.” This idea would prevail well into the middle of the 20th century.
Santiago Ramón y Cajal/Public Domain
We now know that the brain is constantly remolding itself, both functionally and structurally, across many scales — from the molecules that flow between neurons to the connections that stretch across the brain and beyond.
The power of neuroplasticity is perhaps best demonstrated by case studies. One patient born without an olfactory bulb could smell because other parts of her brain remolded to serve as substitutes. Another patient had the entire left side of her brain removed as a baby; after her right side reorganized to take on the left’s former roles, today she has a functional life. When a stroke or an accident damages the brain, other neurons fill in to recover patients’ everyday functions such as speaking and walking.
Neuroplasticity also drives everyday learning. This process is mainly thought to result from synaptic plasticity, or changes to the trillions of connections between neurons. And although the brain learns in various ways, one particular idea has dominated for more than 70 years.
In 1949, Donald Hebb, a Canadian psychologist, articulated a theory of learning now known as Hebbian plasticity. According to this model, when neurons are activated within milliseconds of each other, the connection between them is physically strengthened, so that in the future they are more likely to fire together. Over time, they form a network that represents a concept or an experience. In other words, the more the networks in the brain are used, the stronger they get, an idea often summarized as “neurons that fire together, wire together.”
UBC Archives Photograph Collection; University Archives, University of British Columbia Library. UBC 41.1/2039-1
But neuroscientists “always had a sneaking suspicion that Hebbian plasticity wasn’t quite right,” said Jeffrey Magee, a neuroscientist at Baylor College of Medicine. Or at least, it wasn’t the full story. It required an experience to be repeated multiple times to imprint the lesson on the brain — a framework that may explain how we learn a new city or language, but not how we le
▸ 展开全文
04-29 07:57 · 大模型发布,云服务合作,AI基础设施,模型集成,市场竞争
OpenAI models coming to Amazon Bedrock: Interview with OpenAI and AWS CEOs
Good morning,
As I noted yesterday, today’s Stratechery Interview is early in terms of my timing — Tuesday instead of Thursday — and late in terms of delivery — 1pm Eastern instead of 6am — because the topic was embargoed. That embargo created a bit of a weird situation for me over the last several days:
- Last Friday I conducted the following interview with OpenAI CEO Sam Altman and AWS CEO Matt Garman about Bedrock Managed Agents, powered by OpenAI; naturally, one of my questions was about how this fit in with OpenAI’s deal with Microsoft giving Azure exclusive access to OpenAI models.
- Late Sunday I heard through the grapevine that Microsoft would announce something Monday morning; I wondered if it might be a preemptive lawsuit!
- On Monday Microsoft and OpenAI announced they had amended their agreement, allowing OpenAI to serve its products on other cloud providers, including AWS.
So here we are.
I think the Microsoft-OpenAI deal makes a lot of sense for both sides. Here are the bullet points of the new arrangement from Microsoft’s post:
- Microsoft remains OpenAI’s primary cloud partner, and OpenAI products will ship first on Azure, unless Microsoft cannot and chooses not to support the necessary capabilities. OpenAI can now serve all its products to customers across any cloud provider.
- Microsoft will continue to have a license to OpenAI IP for models and products through 2032. Microsoft’s license will now be non-exclusive.
- Microsoft will no longer pay a revenue share to OpenAI.
- Revenue share payments from OpenAI to Microsoft continue through 2030, independent of OpenAI’s technology progress, at the same percentage but subject to a total cap.
- Microsoft continues to participate directly in OpenAI’s growth as a major shareholder.
I think the most important point is the last one. Azure had a real competitive advantage thanks to being the only hyperscaler able to offer OpenAI models, but this also hindered OpenAI, particularly once it became clear that many enterprises cared first and foremost about accessing models on their current cloud of choice; I’ve been noting for a while that this was a real competitive advantage for Anthropic. In other words, Azure’s exclusivity was actively damaging Microsoft’s investment in OpenAI, and given Anthropic’s rapid growth this year, Microsoft needed to tend to their investment, even if it diminished Azure’s differentiation.
OpenAI, meanwhile, clearly sees AWS as a massive opportunity — so much so that they are forgoing Azure-related revenue for the next few years (which, per the previous point, will help Azure management feel better about losing their exclusivity; their PnL is going to look a lot better without paying a revenue share to OpenAI). OpenAI is also releasing Microsoft from the AGI clause; now the agreement between the two companies will run through 2032 no matter what.
What does seem clear is that OpenAI’s focus is going to be on AWS, and the greatest evidence in that regard is the topic of this interview: Bedrock Managed Agents, powered by OpenAI. The easiest way to think about this offering is Codex in AWS; a lot of what makes Codex work is the fact that it is local, which gives you a lot of complexity, particularly in terms of security, for free. It’s another thing entirely to figure out how to make agents work across an organization, and the goal of this offering is to make these workflows much more accessible for organizations who already have most of their data in AWS.
To that end, in this interview, we discuss how AWS created the entire cloud category, and the impact it had on startups, and how AI is both similar and different to that previous paradigm shift. Then we discuss Bedrock Managed Agents, what it is, and how it differs from Amazon’s existing AgentCore offering. We also touch on Trainium and why chips won’t matter to most AI users, and why partnering makes sense relative to Google’s focus on full integration.
As a reminder, all Stratechery content, including interviews, is available as a podcast; click the link at the top of this email to add Stratechery to your podcast player.
On to the Interview:
An Interview with OpenAI CEO Sam Altman and AWS CEO Matt Garman About Bedrock Managed Agents
This interview is lightly edited for clarity.
Topics:
AWS and Startups | Bedrock Managed Agents | Local vs. Cloud | AgentCore vs. Managed Agents | Trainium | Customer Demand | Building the AI StackAWS and Startups
Matt Garman and Sam Altman — well Matt, welcome to Stratechery — and Sam, welcome back [I previously interviewed Altman in October 2025, March 2025, and February 2023].
Sam Altman: Thank you.
Matt Garman: Thank you, thanks for having me.
So Matt, this is your first time on Stratechery. Alas, I think that Sam’s presence is going to preclude the usual getting to know you section. Besides, he doesn’t want to hear us reminisce about our times at Kellogg Business School, but it is good to have a fellow alumnus on the podcast.
MG: Yeah, I’m ha
▸ 展开全文
04-29 07:56 · 服务中断,代码托管,DevOps,基础设施,可用性
An update on GitHub availability
I wanted to give an update on GitHub’s availability in light of two recent incidents. Both of those incidents are not acceptable, and we are sorry for the impact they had on you. I wanted to share some details on them, as well as explain what we’ve done and what we’re doing to improve our reliability.
We started executing our plan to increase GitHub’s capacity by 10X in October 2025 with a goal of substantially improving reliability and failover. By February 2026, it was clear that we needed to design for a future that requires 30X today’s scale.
The main driver is a rapid change in how software is being built. Since the second half of December 2025, agentic development workflows have accelerated sharply. By nearly every measure, the direction is already clear: repository creation, pull request activity, API usage, automation, and large-repository workloads are all growing quickly.
This exponential growth does not stress one system at a time. A pull request can touch Git storage, mergeability checks, branch protection, GitHub Actions, search, notifications, permissions, webhooks, APIs, background jobs, caches, and databases. At high scale, small inefficiencies compound: queues deepen, cache misses become database load, indexes fall behind, retries amplify traffic, and one slow dependency can affect several product experiences.
Our priorities are clear: availability first, then capacity, then new features. We are reducing unnecessary work, improving caching, isolating critical services, removing single points of failure, and moving performance-sensitive paths into systems designed for these workloads. This is distributed systems work: reducing hidden coupling, limiting blast radius, and making GitHub degrade gracefully when one subsystem is under pressure. We’re making progress quickly, but these incidents are examples of where there’s still work to do.
What we’re doing
Short term, we had to resolve a variety of bottlenecks that appeared faster than expected from moving webhooks to a different backend (out of MySQL), redesigning user session cache to redoing authentication and authorization flows to substantially reduce database load. We also leveraged our migration to Azure to stand up a lot more compute.
Next we focused on isolating critical services like git and GitHub Actions from other workloads and minimizing the blast radius by minimizing single points of failure. This work started with careful analysis of dependencies and different tiers of traffic to understand what needs to be pulled apart and how we can minimize impact on legitimate traffic from various attacks. Then we addressed those in order of risk. Similarly, we accelerated parts of migrating performance or scale sensitive code out of Ruby monolith into Go.
While we were already in progress of migrating out of our smaller custom data centers into public cloud, we started working on path to multi cloud. This longer-term measure is necessary to achieve the level of resilience, low latency, and flexibility that will be needed in the future.
The number of repositories on GitHub is growing faster than ever, but a much harder scaling challenge is the rise of large monorepos. For the last three months, we’ve been investing heavily in response to this trend both within git system and in the pull request experience.
We will have a separate blog post soon describing extensive work we’ve done and the new upcoming API design for greater efficiency and scale. As part of this work, we have invested in optimizing merge queue operations, since that is key for repos that have many thousands of pull requests a day.
Recent incidents
The two recent incidents were different in cause and impact, but both reflect why we are increasing our focus on availability, isolation, and blast-radius reduction.
April 23 merge queue incident
On April 23, pull requests experienced a regression affecting merge queue operations.
Pull requests merged through merge queue using the squash merge method produced incorrect merge commits when a merge group contained more than one pull request. In affected cases, changes from previously merged pull requests and prior commits were inadvertently reverted by subsequent merges.
During the impact window, 658 repositories and 2,092 pull requests were affected. We initially shared slightly higher numbers because our first assessment was intentionally conservative. The issue did not affect pull requests merged outside merge queue, nor did it affect merge queue groups using merge or rebase methods.
There was no data loss: all commits remained stored in Git. However, the state of affected default branches was incorrect, and we could not safely repair every repository automatically. More details are available in the incident root cause analysis.
This incident exposed multiple process failures, and we are changing those processes to prevent this class of issue from recurring.
April 27 search-related incident
On April 27, an incident affected our Elas
▸ 展开全文
04-29 07:56 · 开源,语音AI,技术发布,AI内容工厂,嵌入式
VibeVoice: Open-source frontier voice AI
2026-03-06: 🚀 VibeVoice ASR is now part of a Transformers release! You can now use our speech recognition model directly through the Hugging Face Transformers library for seamless integration into your projects.
2026-01-21: 📣 We open-sourced VibeVoice-ASR, a unified speech-to-text model designed to handle 60-minute long-form audio in a single pass, generating structured transcriptions containing Who (Speaker), When (Timestamps), and What (Content), with support for User-Customized Context. Try it in Playground.
- ⭐️ VibeVoice-ASR is natively multilingual, supporting over 50 languages — check the supported languages for details.
- 🔥 The VibeVoice-ASR finetuning code is now available!
- ⚡️ vLLM inference is now supported for faster inference; see vllm-asr for more details.
- 📑 VibeVoice-ASR Technique Report is available.
2025-12-16: 📣 We added experimental speakers to VibeVoice‑Realtime‑0.5B for exploration, including multilingual voices in nine languages (DE, FR, IT, JP, KR, NL, PL, PT, ES) and 11 distinct English style voices. Try it. More speaker types will be added over time.
2025-12-03: 📣 We open-sourced VibeVoice‑Realtime‑0.5B, a real‑time text‑to‑speech model that supports streaming text input and robust long-form speech generation. Try it on Colab.
2025-09-05: VibeVoice is an open-source research framework intended to advance collaboration in the speech synthesis community. After release, we discovered instances where the tool was used in ways inconsistent with the stated intent. Since responsible use of AI is one of Microsoft’s guiding principles, we have removed the VibeVoice-TTS code from this repository.
2025-08-25: 📣 We open-sourced VibeVoice-TTS, a long-form multi-speaker text-to-speech model that can synthesize speech up to 90 minutes long with up to 4 distinct speakers. — accepted as an Oral at ICLR 2026! 🔥
VibeVoice is a family of open-source frontier voice AI models that includes both Text-to-Speech (TTS) and Automatic Speech Recognition (ASR) models.
A core innovation of VibeVoice is its use of continuous speech tokenizers (Acoustic and Semantic) operating at an ultra-low frame rate of 7.5 Hz. These tokenizers efficiently preserve audio fidelity while significantly boosting computational efficiency for processing long sequences. VibeVoice employs a next-token diffusion framework, leveraging a Large Language Model (LLM) to understand textual context and dialogue flow, and a diffusion head to generate high-fidelity acoustic details.
For more information, demos, and examples, please visit our Project Page.
VibeVoice-ASR is a unified speech-to-text model designed to handle 60-minute long-form audio in a single pass, generating structured transcriptions containing Who (Speaker), When (Timestamps), and What (Content), with support for Customized Hotwords.
-
🕒 60-minute Single-Pass Processing: Unlike conventional ASR models that slice audio into short chunks (often losing global context), VibeVoice ASR accepts up to 60 minutes of continuous audio input within 64K token length. This ensures consistent speaker tracking and semantic coherence across the entire hour.
-
👤 Customized Hotwords: Users can provide customized hotwords (e.g., specific names, technical terms, or background info) to guide the recognition process, significantly improving accuracy on domain-specific content.
-
📝 Rich Transcription (Who, When, What): The model jointly performs ASR, diarization, and timestamping, producing a structured output that indicates who said what and when.
📖 Documentation | 🤗 Hugging Face | 🎮 Playground | 🛠️ Finetuning | 📊 Paper
small.mp4
Best for: Long-form conversational audio, podcasts, multi-speaker dialogues
-
⏱️ 90-minute Long-form Generation: Synthesizes conversational/single-speaker speech up to 90 minutes in a single pass, maintaining speaker consistency and semantic coherence throughout.
-
👥 Multi-speaker Support: Supports up to 4 distinct speakers in a single conversation, with natural turn-taking and speaker consistency across long dialogues.
-
🎭 Expressive Speech: Generates expressive, natural-sounding speech that captures conversational dynamics and emotional nuances.
-
🌐 Multi-lingual Support: Supports English, Chinese and other languages.
📖 Documentation | 🤗 Hugging Face | 📊 Paper
English
ES_._3.mp4
Chinese
default.mp4
Cross-Lingual
1p_EN2CH.mp4
Spontaneous Singing
2p_see_u_again.mp4
Long Conversation with 4 people
4p_climate_45min.mp4
VibeVoice-Realtime is a lightweight real‑time text-to-speech model supporting streaming text input and robust long-form speech generation.
- Parameter size: 0.5B (deployment-friendly)
- Real-time TTS (~300 milliseconds first audible latency)
- Streaming text input
- Robust long-form speech generation (~10 minutes)
📖 Documentation | 🤗 Hugging Face | 🚀 Colab
VibeVoice_Realtime.mp4
Please see CONTRIBUTING.md for detailed contribution guidelines.
While efforts have been made to optimize it through various techniques, it may still produce outputs that are unexpect
▸ 展开全文
04-28 07:59 · AI政策,并购受阻,监管,外资限制,自主可控
China blocks Meta's acquisition of AI startup Manus
China's state planner on Monday called for Meta to unwind its $2 billion acquisition of Manus, a Singaporean artificial intelligence startup with Chinese roots.
The decision to prohibit foreign investment in Manus was made in accordance with laws and regulations, the National Development and Reform Commission said in a brief statement. It added that it has asked the parties involved to withdraw the acquisition transaction.
CNBC has contacted Meta for comment. Its stock was up slightly in morning trading.
The deal had attracted scrutiny from both China and Washington, as lawmakers in the U.S. have prohibited American investors from backing Chinese AI companies directly. Meanwhile, Beijing has increased efforts to discourage Chinese AI founders from moving business offshore.
The Chinese government's intervention in the transaction drew alarm among tech founders and venture capitalists in the country who were hoping to take advantage of the so-called Singapore-washing model, where companies relocate from China to the city-state to avoid scrutiny from Beijing and Washington.
Manus was founded in China before relocating to Singapore. The company develops general purpose AI agents and launched its first general AI agent in March last year, which can execute complex tasks such as market research, coding and data analysis. The release saw the startup lauded as the next DeepSeek.
Manus said it had passed $100 million in annual recurring revenue, or ARR, in December, eight months on from launching a product, which it claimed made it the fastest startup in the world at the time to hit the milestone from $0.
The company raised $75 million in a round led by U.S. VC Benchmark in April last year.
When Meta announced the deal late last year, the tech giant said it would look to accelerate artificial intelligence innovation for businesses and integrate advanced automation into its consumer and enterprise products, including its Meta AI assistant.
But in January, China's Ministry of Commerce said it would conduct an assessment and investigation into how the acquisition complied with laws and regulations concerning export controls, technology import and export, and overseas investment.
A Meta spokesperson told CNBC that the transaction "complied fully with applicable law," and that it anticipated "an appropriate resolution to the inquiry."
When asked about China's move to block Meta's Manus acquisition, APEC Senior Officials Meeting Chairman Chen Xu told reporters that it is "important that all parties act in a spirit of mutual benefit."
While Chen said he did not know the specifics of the issue, he said that "if such an issue can be handled properly, it can help facilitate more substantive discussions in APEC." That's according to an official English translation.
— CNBC's Anniek Bao and Dylan Butts contributed to this story.
▸ 展开全文
04-28 07:59 · 大模型访问限制,AI成本,模型供应链,API策略,AI应用影响
Claude Pro: Opus model will only be available if extra usage is enabled
This guide shows you three ways to change which Claude model you're using with Claude Code: the quick /model
command for instant changes, the --model
flag for one-time session changes, and environment variables to set your preferred model as the permanent default.
Easiest method: Use /model command
The simplest way to change models is to use the /model command directly within Claude Code. This works immediately without restarting your terminal.
Start Claude Code:
claude
Type
/model
and choose your desired model from the interactive menu.Your model change takes effect immediately.
Supported models
Opus 4.7,
claude-opus-4-7
Sonnet 4.6,
claude-sonnet-4-6
Opus 4.6,
claude-opus-4-6
Opus 4.5,
claude-opus-4-5-20251101
Haiku 4.5,
claude-haiku-4-5-20251001
Sonnet 4.5,
claude-sonnet-4-5-20250929
Change model for current session only
Use the --model
flag when starting Claude Code.
Start a fresh Terminal session.
Enter the following commands (depending on the model you’d like to use for that session):
For Opus 4.7:
claude --model claude-opus-4-7
For Sonnet 4.6:
claude --model claude-sonnet-4-6
For Opus 4.6:
claude --model claude-opus-4-6
For Opus 4.5:
claude --model claude-opus-4-5-20251101
For Haiku 4.5:
claude --model claude-haiku-4-5-20251001
For Sonnet 4.5:
claude --model claude-sonnet-4-5-20250929
Change default model for all future sessions
Step 1) Check your shell type by running: echo $SHELL
/bin/zsh
→ You're using zsh (macOS default)/bin/bash
→ You're using bash (Linux default)
Step 2) Add model setting to your shell config:
For ZSH users (macOS)
Opus 4.7:
echo 'export ANTHROPIC_MODEL="claude-opus-4-7"' >> ~/.zshrc
Sonnet 4.6:
echo 'export ANTHROPIC_MODEL="claude-sonnet-4-6"' >> ~/.zshrc
Opus 4.6:
echo 'export ANTHROPIC_MODEL="claude-opus-4-6"' >> ~/.zshrc
Opus 4.5:
echo 'export ANTHROPIC_MODEL="claude-opus-4-5-20251101"' >> ~/.zshrc
Haiku 4.5:
echo 'export ANTHROPIC_MODEL="claude-haiku-4-5-20251001"' >> ~/.zshrc
Sonnet 4.5:
echo 'export ANTHROPIC_MODEL="claude-sonnet-4-5-20250929"' >> ~/.zshrc
For BASH users (Linux)
Opus 4.7:
echo 'export ANTHROPIC_MODEL="claude-opus-4-7"' >> ~/.bashrc
Sonnet 4.6:
echo 'export ANTHROPIC_MODEL="claude-sonnet-4-6"' >> ~/.bashrc
Opus 4.6:
echo 'export ANTHROPIC_MODEL="claude-opus-4-6"' >> ~/.bashrc
Opus 4.5:
echo 'export ANTHROPIC_MODEL="claude-opus-4-5-20251101"' >> ~/.bashrc
Haiku 4.5:
echo 'export ANTHROPIC_MODEL="claude-haiku-4-5-20251001"' >> ~/.bashrc
Sonnet 4.5:
echo 'export ANTHROPIC_MODEL="claude-sonnet-4-5-20250929"' >> ~/.bashrc
Step 3) Apply the changes:
For ZSH:
source ~/.zshrc
For BASH:
source ~/.bashrc
Step 4) Close Terminal completely, then reopen it.
Step 5) Start Claude Code in a fresh Terminal session: claude
.
Now your chosen model will be the default for all future Claude Code sessions.
▸ 展开全文
04-28 07:59 · 数据泄露,AI安全,供应链风险,语音数据,合规审查
4TB of voice samples just stolen from 40k AI contractors at Mercor
4TB of voice samples were just stolen from 40,000 AI contractors. Here is how to verify if yours is being weaponized.
On April 4, 2026, the extortion group Lapsus$ posted Mercor on its leak site. The dump is reported at roughly four terabytes and bundles a payload that breach analysts have been warning about for two years: voice biometrics paired with the same person's government-issued identity document. According to the leaked sample index, the archive covers more than 40,000 contractors who signed up to label data, record reading passages, and run through verification calls for AI training.
Why this breach is different
Most voice leaks in the last decade fell into one of two buckets. Either a call center got popped and recordings were stolen with no easy way to map them back to identity. Or an ID-document broker leaked driver's licenses and selfies without any audio attached. Mercor merged both columns. The contractor onboarding pipeline asked for a passport or driver's license scan, then a webcam selfie, then a sit-down voice recording reading scripted prompts in a quiet room. That sequence, in one row of one database, is exactly what a synthetic voice cloning service needs as input.
The Wall Street Journal reported in February 2026 that high-quality voice cloning now requires roughly fifteen seconds of clean reference audio for tools available off the shelf. The Mercor recordings are reported to average two to five minutes of studio-clean speech per contractor. That is far past the threshold. Pair it with a verified ID document and the attacker has both the clone and the credential needed to put the clone to work.
What attackers can now do with stolen voice data
The threat models below are not speculative. Each is a documented technique already used in the wild before this breach.
- Bank verification bypass. Several US and UK banks still treat voiceprint matching as one of two factors. A clone of the account holder reading a challenge phrase clears the audio gate, leaving only a knowledge question that often comes from the same leaked dataset.
- Vishing the victim's employer. Calling HR or finance pretending to be the employee to redirect payroll, request a wire, or unlock a workstation. The Krebs on Security archive lists more than two dozen confirmed cases since 2023.
- Deepfake video calls in the Hong Kong Arup template. In 2024 a finance worker at Arup wired roughly 25 million dollars after a multi-person deepfake video call. The voices and faces had been built from public footage. Mercor leaked something better than public footage: studio audio plus a verified ID.
- Insurance claim fraud. Pindrop reported a 475 percent year-over-year increase in synthetic voice attacks against insurance call centers across 2025. Auto, life, and disability claims are the prime targets because they are settled by phone.
- Romance and grandparent scams targeting family members. The FBI Internet Crime Complaint Center logged 2.3 billion dollars in losses for victims aged 60 and over in calendar year 2026. The single fastest-growing category was emergency impersonation calls, where the synthetic voice claims to be a relative in trouble.
How to check if your voice is being misused
If you ever uploaded a voice sample to Mercor, or to any of the other AI training brokers that operated through 2025, treat your voice the way you would treat a leaked password. You cannot rotate it, but you can change what it unlocks. Here is the short list.
- Self-audit your public audio footprint. Search YouTube, podcast directories, and old Zoom recordings for samples of your voice that are publicly indexable. Take down what you can. The less reference audio is in the open, the less robust an attacker's clone.
- Set up a verbal codeword with family and finance contacts. Pick a phrase that has never been spoken on a recording and never typed in chat. Brief the people who handle money on your behalf. If a call ever asks for a transfer, the codeword is mandatory.
- Rotate where voiceprints are still in use. Google Voice Match, Amazon Alexa Voice ID, Apple personal voice, and any banking voiceprint enrollment can be deleted and replaced. Do that now, ideally from a new recording in a different acoustic environment than the leaked sample.
- Tell your bank to disable voiceprint as a verification factor. Ask in writing for multi-factor authentication that combines an app token or hardware key with a knowledge factor. Many banks let you opt out of voice as a primary factor; few of them advertise it.
- Run suspicious recordings through a forensic scanner. If you receive an audio file or voicemail that claims to be from someone you know and asks for money, access, or urgency, run it through a deepfake detector before acting. ORAVYS offers a free check for the first three samples submitted by breach victims (see the offer below).
The forensic checklist that experts use
When a sample lands on a forensic analyst's desk, the following artifacts are the
▸ 展开全文
04-28 07:57 · 开源停止维护,数据库备份,供应链风险,运维工具,PostgreSQL
Pgbackrest is no longer being maintained
TL;DR: pgBackRest is no longer being maintained. If you fork pgBackRest, please select a new name for your project.
After a lot of thought, I have decided to stop working on pgBackRest. I did not come to this decision lightly. pgBackRest has been my passion project for the last thirteen years, and I was fortunate to have corporate sponsorship for much of this time, but there were also many late nights and weekends as I worked to make pgBackRest the project it is today, aided by numerous contributors. Every open-source developer knows exactly what I mean and how much of your life gets devoted to a special project.
Since Crunchy Data was sold, I have been maintaining pgBackRest and looking for a position that would allow me to continue the work, but so far I have not been successful. Likewise, my efforts to secure sponsorship have also fallen far short of what I need to make the project viable.
Like everyone else, I need to make a living, and the range of pgBackRest-related roles is very limited. I can now consider a wider variety of opportunities, but those will not leave me time to work on pgBackRest, which requires a fair amount of time for maintenance, bug fixes, PR reviews, answering issues, etc. That does not even include time to write new features, which is what I really love to do. Rather than do the work poorly and/or sporadically, I think it makes more sense to have a hard stop.
I imagine at some point pgBackRest will be forked, but that will be a new project with new maintainers, and they will need to build trust the same way we did.
Again, many thanks to all the pgBackRest contributors over the years. It was a pleasure working with you!
pgBackRest is a reliable backup and restore solution for PostgreSQL that seamlessly scales up to the largest databases and workloads.
pgBackRest v2.58.0 is the current stable release. Release notes are on the Releases page.
Compression is usually the bottleneck during backup operations so pgBackRest solves this problem with parallel processing and more efficient compression algorithms such as lz4 and zstd.
A custom protocol allows pgBackRest to backup, restore, and archive locally or remotely via TLS/SSH with minimal configuration. An interface to query PostgreSQL is also provided via the protocol layer so that remote access to PostgreSQL is never required, which enhances security.
Multiple repositories allow, for example, a local repository with minimal retention for fast restores and a remote repository with a longer retention for redundancy and access across the enterprise.
Full, differential, and incremental backups are supported. pgBackRest is not susceptible to the time resolution issues of rsync, making differential and incremental backups safe without the requirement to checksum each file. Block-level backups save space by only copying the parts of files that have changed.
Retention polices can be set for full and differential backups to create coverage for any time frame. The WAL archive can be maintained for all backups or strictly for the most recent backups. In the latter case WAL required to make older backups consistent will be maintained in the archive.
Checksums are calculated for every file in the backup and rechecked during a restore or verify. After a backup finishes copying files, it waits until every WAL segment required to make the backup consistent reaches the repository.
Backups in the repository may be stored in the same format as a standard PostgreSQL cluster (including tablespaces). If compression is disabled and hard links are enabled it is possible to snapshot a backup in the repository and bring up a PostgreSQL cluster directly on the snapshot. This is advantageous for terabyte-scale databases that are time consuming to restore in the traditional way.
All operations utilize file and directory level fsync to ensure durability.
If page checksums are enabled pgBackRest will validate the checksums for every file that is copied during a backup. All page checksums are validated during a full backup and checksums in files that have changed are validated during differential and incremental backups.
Validation failures do not stop the backup process, but warnings with details of exactly which pages have failed validation are output to the console and file log.
This feature allows page-level corruption to be detected early, before backups that contain valid copies of the data have expired.
An interrupted backup can be resumed from the point where it was stopped. Files that were already copied are compared with the checksums in the manifest to ensure integrity. Since this operation can take place entirely on the repository host, it reduces load on the PostgreSQL host and saves time since checksum calculation is faster than compressing and retransmitting data.
Compression and checksum calculations are performed in stream while files are being copied to the repository, whether the repository is located locally or remotely.
If the repository is on a
▸ 展开全文
04-28 07:56 · 历史趣闻,非技术内容,无关联
Magic by return of post: How mail order delivered the occult
What allowed occultism to blossom in the United States at the turn of the 20th century? Linotype machines, cheap pulp paper, and newly improved postal networks. Allan Johnson investigates the forgotten history and (still living) world of mail-order magic.
April 22, 2026
In the early twentieth century, after the rationalising forces of the Enlightenment had supposedly recast spiritual life through reason, curious advertisements began to appear in popular periodicals ranging from Popular Mechanics to Weird Tales, offering arcane occult knowledge sent directly to the reader’s door. Typical of their genre, a 1902 notice in the Chicago Tribune introduced the De Laurence Institute of Hypnotism, which promised to “[unfold] the mysterious law of all personal magnetism, occult force, and influence”, while, elsewhere, the Occult Digest announced the services of the Los Angeles–based Brotherhood of Light, who had on offer “correspondence courses in all branches of occult science” by return of post.1 Sending away for the secrets of the ages was, it seemed, disarmingly simple, part and parcel of the colossal mail-order industry that had emerged during the Second Industrial Revolution of the late-nineteenth and early twentieth centuries.
The rise of mail-order magic was, in many ways, both an upshot and a parody of modernity. America’s long nineteenth century had already seen its fair share of religious transformation, with movements like Mormonism, Seventh-day Adventism, Christian Science, and the Shakers, among others, emerging from the spiritual fervour of the Second Great Awakening, each grappling in their own way with the relationship between the individual and society at large. In 1917, German sociologist Max Weber famously argued that “the fate of our times is characterized by rationalization and intellectualization and, above all, by the ‘disenchantment of the world’”.2 To Weber’s mind, the progress of the modern world had eradicated the need for spiritual practice, with the purposes it had once held now being carried by the cold logics of bureaucracy, science, and instrumental reason. From the vantage point of hindsight, however, Weber’s Entzauberung thesis seems less terminal than he had imagined.
In a time increasingly shaped by Taylorist factories and scientific materialism, Weber ultimately misread modernity, and his account of disenchantment confused modernity’s growing spiritual liberalism with large-scale secularisation. That is, Weber believed that the declining adherence to Christianity (which was unmistakable) signalled that the numinous had faded from modern life (which couldn’t have been further from the truth). Modernity and scientific materialism didn’t really get rid of spiritual practice as much as abstract it from an inherited, communal framework. What modernity had in fact created was a radical redistribution of belief, in which the rationalist currents presumed to have extinguished faith in powers and presences beyond oneself became the very means by which one could learn about these otherworldly forces from the privacy of one’s own home.
The new material conditions of postal exchange — linotype machines, cheap pulp paper, and rapidly improving and expanding delivery networks — made the recondite world of the occult ultra-targeted and at a scale never before seen. The consumer now got to choose if they wanted to practice meditation, astrology, tarot, Mesmerism, Kabbalah, Rosicrucianism, something even more arcane, or a unique combination of them all. There was no fixed template for how the instruction unfolded, but most would-be adherents began their affiliation by responding to the offer of a free sample lesson or catalogue from a magazine ad. From there, they could subscribe to courses whose scale, duration, and cost varied greatly. To give just a single example, lessons from Psychiana, one of the largest esoteric correspondence schools of the 1930s by subscriber numbers, cost around $1 each (about $20 in today’s currency) and were purchased in groups of ten or twenty lessons, with one lesson posted weekly. For students of Psychiana, as well as those who sent away to the many other smaller providers, completion of these introductory sequences usually then opened onto further tiers of instruction or advanced courses, with payment typically remitted in cash, sometimes in instalments or in arrears.
One of mail-order magic’s early innovators was Sydney Flower, the shadowy Chicago-based publisher behind The Hypnotic Magazine, The Yogi, and New Thought (the latter co-edited with William Walker Atkinson, best known as the presumed author of 1908’s Kybalion), as well as a startling range of orderable courses, through his Psychic Research Company and Magnetic Publishing Company, with titles such as A Course of Instruction in Magnetic Healing in Five Parts and A Course of Instruction in the Development of Power through Clairvoyance.
Flower emerges with almost no trace of a past, but by the time he arr
▸ 展开全文