站长制作的最新视频
一、序言 最近读完了一本讲解 MCP 实现原理的书:《这就是 MCP》,它帮助我更好地理解了 MCP,以下是一些笔记。 二、什么是 MCP MCP 的全称是 Model Context Protocol,之所以叫这个名字,是因为它可以成为大模型调用外部工具的协议,让大模型能够补充自己的上下文(即 Context)。 在没有 MCP 之前,每个大模型都在为自己扩展调用外部工具的能力,最常见的能力就是调用搜索引擎。但是这就会造成一个麻烦:每个大模型都需要自己开发一遍调用工具(重复造轮子),而且由于协议不开放,第三方开发者无法为大模型提供更多工具。 在有了 MCP 之后,整个开发流程变成了: 大模型都适配 MCP 协议 各种工具都适配 MCP 协议 这样,一个新的工具出来,立刻可以为所有大模型可用,而一个新的大模型也可以立刻调用市面上公开的 MCP(下图)。 有人把这个比作 “AI 时代的 HTTP 协议”,我是比较认同的。 三、MCP 的实现细节 3.1 角色 不同于 HTTP协议的浏览器 / 服务器(B/S)架构,MCP 的协议多了一个 “主机” 的角色,一共包含三个角色,分别是:主机,客户端,服务器。 主机:创建和管理多个客户端。负责鉴权相关工作。负责多个客户端内容的聚合, 客户端:一个客户端是一个进程,负责与对应的 MCP 服务器交互数据,管理会话的状态。 服务器:为客户端提供服务。可以部署成本地服务或远程服务。 3.2 协议 MCP 使用 JSON-RPC 作为客户端与服务器通信的基础。 当服务器部署在本地的时候,它允许客户端用 stdio 的方式来传输 JSON 编码的数据。 当服务器部署在远程的时候,它使用 HTTP 来传输 JSON。 鉴权方面, 基于 stdio 传输实现的服务器直接从环境变量中读取授权凭证,而基于 HTTP 协议的服务器,基于 OAuth 2.1 实现授权。 四、如何开发 MCP 开发 SDK:MCP 支持任意语言开发 MCP 服务器,我们可以使用官方提供的 SDK 快速生成代码框架。 调试工具:官方提供的调试工具名为 MCP Inspector,用它连接对应 MCP 之后就可以在面板中调试功能。 发布 MCP:我们可以把开发好的服务发布到 MCP 市场上面供开发者检索到。 MCP 市场。市面上比较有名的市场包括: Anthropic 官方的 MCP Servers 仓库 Smithery Glama 五、MCP 的问题 MCP 发布才一年时间,所以还有很多细节未来需要完善,包括: 协议对多模态内容支持不够友好 鉴权机制不完善,很多 MCP 服务还未支持 25 年 3 月引入的 OAuth 鉴权协议 安全防护能力弱。攻击者可以构造恶意的 MCP 服务来诱导用户执行恶意命令,从而实现信息窃取,执行恶意命令等攻击。 以上。
Amazon (Reddit, Hacker News, 2, 3): We are investigating increased error rates and latencies for multiple AWS services in the US-EAST-1 Region. I like how, unlike Apple’s status page, you can see a history of outages and updates. Jess Weatherbed: A major Amazon Web Services (AWS) outage took down multiple online services for several hours […]
Norbert Heger: Back in our pilot Deletion Impossible, you learned about a bug in macOS 15.3 where dragging an app to the Trash did not reliably uninstall its system extension. Despite macOS promising to “remove the associated system extension,” the extension often stayed behind. With macOS 26 Tahoe, this problem has reappeared. Once again, moving […]
Michael Simon (via Ric Ford): If you use Firefox on a Mac or PC, Apple offers a handy browser extension that puts your iCloud passwords right at your fingertips without needing to open a separate app. However, a new warning might make you think twice before you use it next time.As reported by The Hacker […]
Ben Lovejoy: A former Meta product manager has claimed that the social network circumvented Apple’s privacy protections, as well as cheating advertisers, and fired him when he repeatedly raised the issue internally.[…]It was quickly alleged that Meta was using workarounds to continue to track users who had denied permission, alongside other privacy violations. A class […]
Tana是一款强大的笔记应用,能够高效辅助用户记录和整理工作。通过在Daily notes中记录,利用AI功能生成周报效果显著。然而,Tana的学习曲线较陡,用户需要耐心练习与思考,并参考官方资料与他人分享,才能掌握其深层逻辑与功能。
Johannes Weiss and Mitchell Allison (forum): Swift Profile Recorder, an in-process sampling profiler for Swift services, is now available as an open source project.[…]Swift Profile Recorder enables you to:Adopt profiling without extra privileges or system dependencies, allowing you to add profiling across a variety of compute environments with constrained permissions.Collect samples using curl, allowing you […]
SE-0491 (via Becca Royal-Gordon): We propose that Swift’s grammar be extended so that, wherever an identifier is written in source code to reference a declaration, it can be prefixed by ModuleName:: to disambiguate which module the declaration is expected to come from. This syntax will provide a way to resolve several types of name ambiguities […]
Fight to Repair: A coalition of businesses, nonprofits, and elected officials (including Fight To Repair’s parent organization, the Secure Resilient Future Foundation) has formally petitioned Microsoft to extend Windows 10 support, which is currently slated to end on October 14th. With more than a billion Windows 10 devices operating globally, it is estimated that hundreds […]
Adam Engst (Hacker News): Apple’s new Liquid Glass interface design brings transparency and blur effects to all Apple operating systems, but many users find it distracting or difficult to read. Here’s how to control its effects and make your interface more usable. Although the relevant Accessibility settings are quite similar across macOS, iOS, watchOS, and […]
Raluca Budiu (Hacker News): One of the oldest findings in usability is that anything placed on top of something else becomes harder to see. Yet here we are, in 2025, with Apple proudly obscuring text, icons, and controls by making them transparent and placing them on top of busy backgrounds.[…]And then comes Apple’s boldest (or […]
Adam Engst: Here’s where I take exception to Liquid Glass, and to Apple’s positioning of content as the most important aspect of our digital devices, and thus of our digital lives. Yes, many people are largely passive consumers of content, whether we’re talking about Web pages, podcasts, or streaming videos. For those people, there is […]
Mario Guzmán: I can’t stop laughing at how comically large the corner radii are on #macOSTahoe windows. Clownish. Dominik Wagner: Preview? These are white, A4 PDF pages, they don’t have round corners. We are not on battlestar galactica. I need my pdf preview to show me my paper as it is, not with different rounded […]
Nick Heer (Mastodon): I do not think all these effects necessarily help legibility, which is as poor as it has ever been in translucent areas. The degree to which this is noticeable is dependent on the platform. In iOS 26, I find it less distracting, I think largely because it exists in the context of […]
Jason Kottke: I’m usually pretty go-with-the-flow as far as OS updates go, but iOS 26 / Liquid Glass is terrible: incoherent, ugly, and difficult to use. Obviously a massive design effort, but they missed the mark IMO. Juli Clover: It’s been two days since iOS 26 was released, and Apple’s new Liquid Glass design is […]
博客和博客 小红书时常给我推送「博客」相关内容,点开却发现多是「播客」。 试探的问了一个贴主,对方回复:输入法 […]
深圳益田假日广场的苹果店,人非常多,但是没有iPhone 17 Pro可以买。
Apple (Hacker News, MacRumors, Slashdot): With M5, the 14-inch MacBook Pro gets even faster, more capable, and delivers a huge leap in AI performance. […] Additionally, it offers phenomenal battery life of up to 24 hours, so users can take their pro workflows anywhere. With the latest storage technology, the new 14-inch MacBook Pro with […]
Apple (Hacker News, MacRumors, MacStories): M5 unlocks the most advanced iPad experience ever, packing an incredible amount of power and AI performance into the ultraportable design of iPad Pro. […] N1, the new Apple-designed wireless networking chip, enables the latest generation of wireless technologies with support for Wi-Fi 7 on iPad Pro. The C1X modem […]
Apple (Hacker News, MacStories): Apple today introduced Apple Vision Pro with the powerful M5 chip that delivers a leap forward in performance, improved display rendering, faster AI-powered workflows, and extended battery life. The upgraded Vision Pro also comes with the soft, cushioned Dual Knit Band to help users achieve an even more comfortable fit, and […]
Apple (Hacker News, MacRumors): Built using third-generation 3-nanometer technology, M5 introduces a next-generation 10-core GPU architecture with a Neural Accelerator in each core, enabling GPU-based AI workloads to run dramatically faster, with over 4x the peak GPU compute performance compared to M4. The GPU also offers enhanced graphics capabilities and third-generation ray tracing that combined […]
站长在西班牙拍摄的相片的第一部分
最新消息称,Tana免费用户可以获得500点AI点数。我还没测试这500点能做多少事情,但认为这是一个不错的策略。这能让免费用户更多体验AI功能,从而可能转化为付费用户。即使平时不常用AI的用户,也能免费使用。这在产品上取得了平衡,为免费用户提供更多价值,并提高了他们因AI升级而转化的可能性。
Eric Böhnisch-Volkmann: Here’s Neo Network Utility 2.0 with a refreshed yet familiar design for macOS Tahoe, including menu icons, pill-shaped buttons, and a modern tab view. It actually looks good in Liquid Glass.Of course we didn’t just touch it up a bit. The new version lets you open multiple windows and run commands in all […]
Ric Ford (PDF): Researchers at Graz University of Technology discovered severe, unpatched vulnerabilities in iPhones, Android phones and other devices that facilitate attacks and data theft via malicious USB chargers. Previously known and addressed as “juice jacking,” the effective new technique has been titled “ChoiceJacking.” Adam Engst: This vulnerability exists because USB ports can simultaneously […]
Eric Slivka: Buried in its announcement about “F1: The Movie” making its streaming debut on December 12, Apple has also announced that Apple TV+ is being rebranded as simply Apple TV.[…]Apple of course offers its set-top box hardware under the Apple TV name while also offering the Apple TV app across various platforms as a […]
Max Seelemann (on his new blog): So how do you tell if a task supports cancellation? That’s tricky to answer per-se because cancellation is voluntary behavior and needs to be represented in the task’s value or error type. If you’re lucky, cancellation support (or lack thereof) is documented.[…]The designated way to check for cancellation is […]
深圳益田假日广场的苹果店,人非常多,但是没有iPhone 17 Pro可以买。
长江、黄河我国的两大母亲河,孕育了中华民族的的伟大文明,共同发源于中华水塔的青藏高原,从一股涓涓细流开始,敞开胸怀,容纳来自祖国大地的大部分江河,滚滚东去,一南一北各自奔向自己的归宿。由于生活在内地,享受着母亲河的恩惠,但是却未能见识其发祥与归宿地,心中一直还有一个执念,有生之年要尽量去看看。高原的海拔和偏僻的交通,对发祥地的向往只能成为奢望,然而归宿地周边的大平原则成为可行的选择。国庆长假终于有机会实现多年的梦想。 长假还没有开始,为了减少拥挤提前出发,到达青岛后再驾车前往黄河入海口,各种导航软件都指向东营,没有精确的到达地点,就朝着这个方向奔袭。大平原上的高速公路双向六车道,几个小时就感到入海口的气息,由于是黄河泥沙冲积而成的,越是往深处走,地上的植物生长状况也在改变,先还可以看见高大的乔木树,大块的田土相连,逐渐的变成低矮的灌木丛,田土也变得零散,再后来就没有了可以种庄稼的田土了,剩下零星的水坑,旁边生长的则是贴地的植被,没有水的地面则泛出白色的盐碱。 一望无垠的平原上,开始是稀稀拉拉的几台“磕头机”慢悠悠的上下起伏,随着“磕头机”的密度增加,我感到已经离我想去的目的地不远啦。虽然知道“磕头机”是抽油的设施,但是从来没有近距离的观察过,好奇心的驱使停下车来,仔细地看看,其实每一台“磕头机”都不完全一样的,还有的是两台并排的一起工作,仿佛就是一个小孩站在一个巨人旁边干着同一件事情。 此时,我国的石油盛产地之一就在脚下,胜利油田,我来啦。 经历过贫油时代的我们,曾经记得一句口号:宁愿少活二十年,拼命也要拿下大油田。煤炭是工业的粮食,石油是工业的血液,没有了煤炭和石油工业将无从谈起。铁人王进喜的故事牢牢的扎根在我们的心里,童年的时候就知道我们有一个大庆油田,后来逐渐知道了我们还有好几个大油田,胜利油田就是其中之一。然而胜利油田在哪里确实没有去仔细想过,今天无意把胜利油田踩在了脚下。每一台“磕头机”抽出来的油量不会很多,旁边就有管道送走,好多条小管汇合成一条大管,几条大管再汇合成更大的管,怀抱粗的大管就顺着公路流向不知道去到了哪里。一望无边的天际边,数不清的“磕头机”,把地下的液体黄金送到它该去的地方。 徘徊数分钟后继续向天际边出发,此时零零星星的车也汇聚成了车流,还算的通畅,慢慢的看见天和地融为了一体,天边就是水,水上就是天,最终变成一条线,车也多了起来,不再那么通畅,走走停停,来到了路的尽头,转弯爬上了大堤。 孤东大堤到了。查资料后才知道,为保证油田勘探开发的顺利进行,自70年代起,胜利油田开始建设海堤工程,孤东海堤所在地原为浅海漫滩潮汐带,涨潮时一片汪洋,退潮后一片泥滩,并经常受到黄河洪水、凌汛的威胁。把海水赶往更深的大海,修建堤坝围出了80多平方公里的海滩,直到90年代才彻底完工,让更多的的“磕头机”矗立在了原来的海中央。举目四望,除了背后是是一片“磕头机”,正前方是天水相连的一条线,左右则是望不到头的一百多公里堤坝,凭我这肉身凡体永远也看不到头的。 十多米宽的坝顶可供双车并行,看见有车停在路边,好奇的驱使停下了脚步。站在堤坝之上,感觉自己好渺小,虽然有禁止翻越下海的警示牌,仍然挡不住赶海人的激情。不仅是孩童的乐园,而是所有人的天堂。为防止海水对堤坝的侵蚀,无数的水泥浇筑的工字型水泥墩放在靠海的一侧,有的完全淹没于水中,有的则在岸边,有的一半在水里,呈现出一块石墩两种颜色,要想到达水边,需穿过比人还高的石墩缝手脚并用方能实现,明明看见露出的石墩,一脚站上去的时候,海浪正好涌来,保证让你的双脚洗个扎扎实实的海水浴。 还没有到大堤之前,路边好多卖渔具的摊位,鱼竿、地笼、鱼饵,还有鸡肉,此时才明白原来这里除了钓鱼,多数的人是来钓螃蟹的,傻傻的螃蟹可能是饿得太久,只要双鳌夹住诱饵是绝不放手的,哪怕你把它提出水面,还需用手将其拔掉。真的是印证了————宁做他人盘中餐,也要做个饱死鬼。由于没有准备钓蟹的装备,只能看别人的表演。 地笼的捕捞效果更加给力,一个小小的地笼,里面放上诱饵,丢在水里,数分钟后提起来,笼里就是好几只,大小都有,有的还挂在笼外双鳌则死死的抓着笼里的诱饵,起笼的那一刻所有人都欢呼雀跃,兴奋的呼叫声此起彼伏。大概幸福的顶峰不过如此了,然而幸福的时光却是那么的短暂,大半天的时间转瞬即过,错过了午餐的时间也没有感觉到,天色也逐渐暗淡下来。 回程的路上在网上寻找可以吃饭的地方,没想到跳出来的满满的都是黄河口大闸蟹,路边也有人不停的招呼,有新鲜的大闸蟹,各种招牌也是满满的大闸蟹。出于对短斤少两的恐惧,仍然选择网上寻找提前联系的源头供货的卖家就餐。导航的指引来到养蟹兼帮加工的农家院落,忙碌的老板电话不断的响起,都是要求送货的,稍有空闲才与我们交谈。在我的脑海里,大闸蟹不是阳澄湖的吗,怎么会出现在这里,聊天后才知道,好多的阳澄湖大闸蟹都是从这里出发,到了阳澄湖里洗个澡,再发往全国各地,地理品牌从此由黄河口变成了阳澄湖。 老板全家动员,选蟹、绑蟹、装箱,有条不紊的忙碌,接待我们的小哥热情而不懈怠,一边介绍他们的养蟹过程,一边帮我们选蟹,大小都有,2.5两母蟹30元一只,3.5两公蟹35一只。按照每人4只的量选好加工,老板还给了我们意外的惊喜。卖给我们打折的残蟹,原来捕捞的过程中,出现了缺胳膊少腿,没有了很好的卖相,就称之为残蟹论斤卖,再来上一大盆。 黄河口大闸蟹的加工方法也特别的简单,放在蒸锅上,一只蟹背一片生姜,静静的等待一刻钟,热气腾腾的大闸蟹就可以入口了,天然的蟹香无需任何调料,让人垂涎欲滴,滚烫的拿在手上左右交替,实在受不了还回盆里,稍歇片刻便大块朵颐。此时此刻此生终于实现了大闸蟹自由啦,午餐和晚餐同时靠蟹完成,双手满嘴都是蟹油。 吃饱喝足已经是月上三竿之时,抓紧时间休息,明天还将赶往下个打卡点。
湾区下雨了。没有雷声和闪光,也没有低飞蜻蜓,也没有黑黑的乌云,只是单纯的,特别大的雨。从 AP 停车场开出
过去两三年,我曾为多家公司的资深开发人员开展 Agent 开发培训;最近一个月,我也一直在为毕业生设计和培训 AI Agent。直到本周,
如果说这个时代最伟大的变革是什么? 那一定是:人工智能。 2023年2月,我对大火的ChatGPT写了一篇简短...
那個 macOS app 也已經下架好幾年了,現在可以來聊聊當時的趣事。 十年前,我還在一家國產線上音樂串流服務打工。那年 Geohot 來台灣參加駭客年會,年會結束後,公司同事也爭取讓 Geohot 來公司演講。 全公司前後端工程師聚集在公司最大的那一間會議室,座位不夠,會議室角落也都坐滿了人,等待大神蒞臨。活動從早上十一點四十五分開始,預計進行四十五分鐘,十二點半之後,會安排與主辦活動的那幾位同事共進午餐。 他在前十分鐘內,首先做了一個謙遜的自我介紹,並且謙稱資安啊、入侵啊、破解啊…也沒什麼,絕大多數時刻,入侵者用的,往往也是些固定的手法,做資安其實也就是幾個大原則,像是能在線上管控的服務,就不要讓其他人可以在本機上使用,而想要防止入侵,就是自己也要有入侵者的思維,才會知道其他人可能會怎樣入侵,就這些。 — 他最近常收到邀請,像是昨天去了另外一家 T 社,今天來我們公司,他都不知道該講些什麼。 我跟旁邊的同事交頭接耳,說,今天他來我們這邊講 T 社的事情,大概過柳天,他也會在其他地方,講我們的事情吧。 既然能講的有限,那不如實戰演練,接下來的時間,讓大家看看我們的服務可能有哪些漏洞。他把 MacBook 接上了投影機,瀏覽公司首頁,首頁上最醒目的內容,就是「立刻下載 App」的按鈕,除了手機版本外,還有 Windows、macOS 兩套桌面版本。 他又重複了一次,像這種線上串流服務,如果只做線上版本,會遠遠比桌面版本安全,為什麼不只做線上版本就好呢?我們回覆,沒辦法,商業上,就是得要有離線聽歌的需求。雖然日後桌面上的方案,也逐漸往純網頁技術、以及網頁中的 DRM 方案發展,但已經是五六年後的事了。 喔,得離線啊。你們真的得知道這樣有多危險耶。 投影畫面中,就看到 Geohot 下載了一套 macOS 版本的 App,畢竟他現在用的是 macBook,有位同事幫忙設定帳號,其他同事則是先發出一陣騷動,視線全都投向了我這邊 — 畢竟 macOS 版本,還有其他蘋果平台上的版本,是由我負責的。 我聳聳肩。 … Continue reading →
最近更新了一篇关于Apple几十年前的吉祥物的文章,发布于少数派会员内容,地址如下: https://sspai.com/prime/story/dogcow-a-history
Eric Slivka: Apple has essentially discontinued Clips, its video-editing app designed to allow users to combine video clips, images, and photos with voice-based titles, music, filters, and graphics to create enhanced videos that can be shared on social media sites.The app has been removed from the App Store, and a support document on Apple’s site […]
Lorenzo Franceschi-Bicchierai (via Hacker News): NSO spokesperson Oded Hershowitz told TechCrunch on Friday that “an American investment group has invested tens of millions of dollars in the company and has acquired controlling ownership.” Confirmation of the deal came soon after Israeli tech news website Calcalist reported Friday that a group led by Hollywood producer Robert […]
Juli Clover: Google today said that Gemini AI is being integrated into the Chrome browser for the Mac and PC. Chrome users in the U.S. will get the functionality first, with Gemini able to clarify complex information on any webpage. There will be a small Gemini symbol in the upper right side of the browser […]
Kaushik Gopal (via Hacker News): You have a drawer full of USB cables. Half are junk that barely charge your phone. The other half transfer data at full speed. But which is which? […] The script parses macOS’s system_profiler SPUSBHostDataType command, which produces a dense, hard-to-scan raw output[…] […] The first version was a bash […]
阅读人数: 9
一个外卖小哥。
小球飞鱼大量发生中:
任何人,都无法真正抵抗身体的衰老,正如时间无法倒流。 在即将满39岁之际,我越来越感觉到,人到中年,身体健康会...
看了未麻的部屋重映,印象比较深的是切场景的的时候总有台词,而台词在前一个场景和后一个场景都是成立的,
Apple (Wired, MacRumors): We’re doubling our top award to $2 million for exploit chains that can achieve similar goals as sophisticated mercenary spyware attacks. This is an unprecedented amount in the industry and the largest payout offered by any bounty program we’re aware of — and our bonus system, providing additional rewards for Lockdown Mode […]
Pablo Manríquez: Apple has quietly removed DeICER, a civic-reporting app used to log immigration enforcement activity, from its App Store after a law enforcement complaint — invoking a rule normally reserved for protecting marginalized groups from hate speech. […] Apple told developer Rafael Concepcion that the app violated Guideline 1.1.1, which prohibits “defamatory, discriminatory, or […]
Qualcomm (Hacker News): Qualcomm Technologies, Inc. today announced its agreement to acquire Arduino, a premier open-source hardware and software company. The transaction accelerates Qualcomm Technologies’ strategy to empower developers by facilitating access to its unmatched portfolio of edge technologies and products.[…]By combining Qualcomm Technologies’ leading‑edge processing, graphics, computer vision, and AI with Arduino’s simplicity, affordability, […]
Hilbert Hagedoorn (via Hacker News): Synology has backtracked on one of its most unpopular decisions in years. After seeing NAS sales plummet in 2025, the company has decided to lift restrictions that forced users to buy its own Synology hard drives. The policy, introduced earlier this year, made third-party HDDs from brands like Seagate and […]