57 Matching Annotations
  1. Last 7 days
    1. The top four designers collectively consumed nearly all of TSMC's CoWoS wafer output, leaving little headroom for other customers.

      这个数据点表明AI芯片设计公司几乎垄断了TSMC的CoWoS晶圆产能,显示出供应链的极度紧张。这一比例接近100%,意味着其他客户几乎没有获得先进封装产能的空间,这反映了AI芯片供应链的严重瓶颈状态。

  2. May 2026
  3. Apr 2026
    1. Within eight days, the same campaign had cascaded from GitHub Actions to Docker Hub, npm, PyPI, and the VS Code extension marketplace. With just one token across five ecosystems, thousands of organizations were potentially impacted.

      大多数人认为软件供应链攻击通常是针对特定生态系统或缓慢扩散的,但作者展示了跨生态系统的快速级联攻击。这种攻击速度和范围远超传统认知,表明现代软件供应链的脆弱性被严重低估。

    2. The median JavaScript project on GitHub has 755 transitive dependencies

      这一数据点极具洞察力,指明了现代软件架构的根本性脆弱点:真正的防线不再是你的业务代码,而是你从未审查过的传递依赖网络。开发者往往只关注直接引入的包,却忽略了依赖树深处的暗箱,这正是供应链攻击能够“顺藤摸瓜”造成大面积杀伤的底层逻辑。

    3. We are building a world where machines write the code, machines choose the dependencies, and machines ship the updates. The AI agents are building the software. If we don't secure the supply chain they rely on, the AI agents are cooked.

      大多数人认为AI将提高软件开发的效率和安全性,但作者警告说,如果我们不保护AI代理所依赖的供应链,这些代理本身就会成为攻击目标。这挑战了AI发展必然带来安全提升的主流观点,提出了一个反直觉的警告。

    1. the initial access occurred after a Vercel employee's Google Workspace account was compromised via a breach at the AI platform Context.ai.

      大多数人认为大型云平台的漏洞主要来自外部直接攻击,但作者暗示这次安全事件实际上是通过第三方AI平台Context.ai的漏洞间接导致的,这挑战了人们对供应链安全风险的普遍认知。

    1. The action that matters most — building semiconductor-grade hydrogen bromide gas conversion capacity outside Israel — takes years.

      大多数人认为供应链中断可以通过市场机制快速调整,但作者指出建立替代产能需要数年时间,远快于市场自发调整的速度。这一反直觉观点强调了供应链韧性需要长期规划和政府干预,而非依赖市场力量。

    2. The structural failure is not the war: It is that the global memory supply chain has built itself around a conversion chokepoint with no redundancy and no fallback.

      大多数人认为供应链风险主要来自地缘政治冲突本身,但作者指出真正的结构性问题是全球内存供应链围绕一个没有冗余和备用方案的转换瓶颈构建。这一观点挑战了主流认知,将焦点从战争本身转向了供应链设计的根本缺陷。

    3. The story receiving almost no attention is bromine, and it is potentially the more dangerous one.

      大多数人认为中东地区的半导体供应链风险主要集中在氦气等资源上,但作者指出溴素才是更危险的隐形威胁。这一观点挑战了主流认知,因为它揭示了一个被广泛忽视的关键材料,其重要性远超当前媒体关注的焦点。

  4. Apr 2025
  5. Dec 2024
  6. May 2024
    1. the whole world is affected by it opium ferret from Afghan Fields produces nearly all of the heroines sold in Europe how will prices be impacted

      for - question - how will the Taliban's successful destruction of the poppy industry affect drug supplies in Europe?

      to - youtube - Vice - The new fentanyl killing drug users in Europe - https://hyp.is/MDez0BYcEe-rq0sJ-I6FRg/docdrop.org/video/JqqfI-bIvnI/

  7. Apr 2024
    1. Die EU hat nicht erreicht, dass Mittel aus dem Inflation Reduction Act auch zur Subventionierung des Kaufs von aus der EU gelieferten privaten E-Autos verwendet werden. Bei der Entscheidung der USA, die in der EU-Wirtschaft vielfach als protektionistisch bewertet wird, spielt die Herkunft von Mineralien eine große Rolle. Die Verhandlungen über das Critical Minerals Agreement (CMA) führten nicht zu einer Einigung. Der Handelsblatt-Artikel stellt den komplexen Hintergrund ausführlich dar und berichtet auch über weitere Verhandlungen.

      https://www.handelsblatt.com/politik/international/ira-deutsche-autobauer-gehen-amerikanischen-milliarden-subventionen-leer-aus/100030133.html

  8. Oct 2023
  9. Jul 2023
  10. Jun 2023
  11. Jan 2023
    1. Ziemkiewicz has a picture in his office of himself and Senator Joe Manchin, who has expressed support of his program. “Recycling provides a tremendous opportunity to avoid outsourcing the raw supply of critical minerals we need while creating new economic opportunities right here at home,” Manchin said, at a congressional hearing in the spring. Ziemkiewicz keeps his politics to himself. In the past, he has called himself “a Trotskyite,” but he believes that the success of his past three decades of work, reclaiming thousands of miles of rivers and streams in Appalachia, is based on sharing knowledge across a wide array of communities

      Wow, he got Manchin on board?

  12. Dec 2022
  13. Aug 2022
  14. Jun 2022
  15. Feb 2022
  16. Jan 2022
  17. notesfromasmallpress.substack.com notesfromasmallpress.substack.com
    1. If booksellers like to blame publishers for books not being available, publishers like to blame printers for being backed up. Who do printers blame? The paper mill, of course.

      The problem with capitalism is that in times of fecundity things can seem to magically work so incredibly well because so much of the system is hidden, yet when problems arise so much becomes much more obvious.

      Unseen during fecundity is the amount of waste and damage done to our environments and places we live. Unseen are the interconnections and the reliances we make on our environment and each other.

      There is certainly a longer essay hiding in this idea.

  18. Sep 2021
  19. Aug 2021
  20. May 2021
    1. blockchain-based system

      I see the point that blockchain helps make provenance tracing possible, but will need more details of how blockchain technology is leveraged here. Otherwise, I still feel stuck by questions like "Why it has to be blockchain?" and "Can't other technologies serve the same function?".

  21. Mar 2021
  22. Jan 2021
  23. Nov 2020
    1. According to the World Economic Forum’s Global Risks Report 2020, the interconnectedness of our global business supply chains has made the world more vulnerable to societal and economic disruption from local infectious-disease outbreaks.
  24. Aug 2020
  25. Jul 2020
  26. Jun 2020
  27. May 2020
  28. Apr 2020
    1. Newton, P. N., Bond, K. C., Adeyeye, M., Antignac, M., Ashenef, A., Awab, G. R., Babar, Z.-U.-D., Bannenberg, W. J., Bond, K. C., Bower, J., Breman, J., Brock, A., Caillet, C., Coyne, P., Day, N., Deats, M., Douidy, K., Doyle, K., Dujardin, C., … Zaman, M. (2020). COVID-19 and risks to the supply and quality of tests, drugs, and vaccines. The Lancet Global Health, S2214109X20301364. https://doi.org/10.1016/S2214-109X(20)30136-4

  29. Nov 2019
  30. Jun 2019