惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

T
Tenable Blog
C
Cisco Blogs
T
Tor Project blog
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Spread Privacy
Spread Privacy
Attack and Defense Labs
Attack and Defense Labs
G
GRAHAM CLULEY
S
Security Archives - TechRepublic
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Recent Commits to openclaw:main
Recent Commits to openclaw:main
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
B
Blog RSS Feed
I
InfoQ
P
Proofpoint News Feed
A
Arctic Wolf
Simon Willison's Weblog
Simon Willison's Weblog
L
Lohrmann on Cybersecurity
K
Kaspersky official blog
Stack Overflow Blog
Stack Overflow Blog
The Register - Security
The Register - Security
Microsoft Azure Blog
Microsoft Azure Blog
云风的 BLOG
云风的 BLOG
U
Unit 42
Google Online Security Blog
Google Online Security Blog
P
Palo Alto Networks Blog
L
LINUX DO - 热门话题
The GitHub Blog
The GitHub Blog
V
V2EX - 技术
G
Google Developers Blog
H
Help Net Security
N
News and Events Feed by Topic
Blog — PlanetScale
Blog — PlanetScale
H
Hackread – Cybersecurity News, Data Breaches, AI and More
The Last Watchdog
The Last Watchdog
AI
AI
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
大猫的无限游戏
大猫的无限游戏
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Forbes - Security
Forbes - Security
宝玉的分享
宝玉的分享
Google DeepMind News
Google DeepMind News
月光博客
月光博客
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
博客园 - 叶小钗
F
Full Disclosure
Cloudbric
Cloudbric
Martin Fowler
Martin Fowler
Help Net Security
Help Net Security
H
Heimdal Security Blog
T
Troy Hunt's Blog

Hacker News - Newest: "AI"

AI can't read an investor deck AI as an attorney? Student uses ChatGPT, Gemini to sue UW over alleged racial discrimination Hacking MCP Servers in AI Systems – The Rug Pull: Tool Changes After Approval GitHub - MeepCastana/KubeezCut: Free Web based video editor GitHub - GenAI-Gurus/awesome-eu-ai-act: Curated tools, official sources, OSS, templates, and guides for EU AI Act compliance. Can AI judge journalism? A Thiel-backed startup says yes, even if it risks chilling whistleblowers Coming soon: 10 Things That Matter in AI Right Now DARPA built an AI to fact-check enemy weapons claims IatroBench: Pre-Registered Evidence of Iatrogenic Harm from AI Safety Measures What explains heterogeneity in AI adoption? When AI Meets Muscle: Context-Aware Electrical Stimulation Promises a New Way to Guide Human Movements - Department of Computer Science AI Changed How We Build. It Did Not Change What Matters. Linux rules on using AI-generated code - Copilot is OK, but humans must take 'full responsibility for the… Meta spins up AI version of Mark Zuckerberg to engage with employees Code Mode: Let Your AI Write Programs, Not Just Call Tools | TanStack Blog GitHub - Delavalom/graft: Go framework for building AI agents. Type-safe tools, multi-provider (OpenAI, Anthropic, Gemini, Bedrock), zero vendor SDKs. India's TCS tops estimates, says new AI models did not dent services demand Gen Z's fading AI hype Strong feeling: we are in a folded AI reality GitHub - machinarii/total-recall-catalog: A reference catalog of latest knowledge retrieval, memory & RAG systems GitHub - mensfeld/code-on-incus: Give each AI agent its own isolated machine with root, Docker, and systemd. Active defense detects and stops threats automatically.. Quantization, LoRA, and the 8% Problem: Benchmarking Local LLMs for Production AI Iran war: We spoke to the man making Lego-style AI videos that experts say are powerful propaganda Powell, Bessent discussed Anthropic's Mythos AI cyber threat with major U.S. banks GitHub - immartian/bellamem: Persistent belief-graph memory for AI agents. Retrieves decisive context by importance — not recency, not RAG, not /compact. recursive-mode: The Repo-Native Operating System for AI Engineering After the attack on Sam Altman's home, will AI CEO's go on the offensive? The biggest advance in AI since the LLM Opus 4.6 vs GPT 5.4 One Prompt Unity World Generation Test “AI polls” are fake polls Client Challenge Can AI be a 'child of God'? Inside Anthropic's meeting with Christian leaders How to Switch AI Chatbots and Why You Might Want To GitHub - MattMessinger1/agentic_refund_guardrail: Safe refund policy layer for AI agents — Python + TypeScript. Same behavior, shared tests. Adam/papers/emergent_values_whitepaper.md at master · strangeadvancedmarketing/Adam Ask HN: How do you stop playing 20 questions with your AI coding tools How far can automation and AI support psychotherapy? - @theU GitHub - stagas/rtdiff: realtime git diff gui and AI-assisted commits A Mac Studio for Local AI — 6 Months Later A History of the Early Years of AI at the University of Edinburgh Why AI Coding Tools Still Feel Stuck on Localhost MSN AI Datacenters Are Becoming Strategic Targets twitter.com Penn Researchers Use AI to Surface Unreported GLP-1 Side Effects in Reddit Posts Show HN: MoodSense AI (ML and FastAPI and Gradio, Deployed on Hugging Face) Moodsense Ai - a Hugging Face Space by aman179102 AI models are terrible at betting on soccer—especially xAI Grok GitHub - xialeistudio/echoic GitHub - HimashaHerath/github-dev-wrapped: AI-powered weekly GitHub activity reports deployed to GitHub Pages GitHub - alejandrobalderas/claude-code-from-source: Architecture, patterns & internals of Anthropic's AI coding agent — reverse-engineered from source maps AI and Tech brief: Ireland ascendant GitHub - Titovilal/context0: Context0 - Never Surrender Training for a Marathon with an AI Coach: What Worked and What Didn't Cyber Pulse: Agentic Intel - Apps on Google Play I Built an AI PR Reviewer That Catches Bugs by Not Looking for Bugs Gen Z workers are so fearful AI will take their job they’re intentionally sabotaging their company’s AI rollout | Fortune How AI Is Reimagining the Game of Golf–For Both Players and Courses GitHub - nattergabriel/reseed: A CLI tool for managing and distributing agent skills across projects Is SVG the final frontier? My AI workflow evolved from prompts to a near-autonomous workflow MLSharp Help - 3DGS Viewer & Generator I put my cognitive field based AI's runtime on GitHub Is Numble the first AI-proof game? A3: Kubernetes for autonomous AI agent fleets | Emergent Principles Deepali Vyas ("The Elite Recruiter") GitHub - msmarkgu/RelayFreeLLM: A restful API designed to route user prompts to various AI model providers. Unionized ProPublica staff are on strike over AI, layoffs, and wages Unleashing the Advantage of Quantum AI We're heading for an AI-fueled 'dementia crisis,' brain scientist warns The AI-Assisted Breach of Mexico's Government Infrastructure [pdf] GitHub - stef41/lmscan: 🔍 Detect AI-generated text and fingerprint which LLM wrote it. Open-source GPTZero alternative. Zero dependencies, works offline. MSN GitHub - visionscaper/collabmem: Enabling long-term collaboration with Agentic AI - building up episodic and world model memory over time with in-context awareness We gave an AI a 3 year retail lease in SF and asked it to make a profit | Andon Labs AI Code is Hollowing Out Open Source, and Maintainers are Looking the Other Way What leaked "SteamGPT" files could mean for the PC gaming platform's use of AI AI is the boss at this retail store. What could go wrong? GitHub - Wuzu11517/agentic-proxy: Local proxy meant to help reduce With Drones, Geophysics and ArtificiaI Intelligence, Researchers Prepare to Do Battle Against Land Mines A Single Operator, Two AI Platforms, Nine Government Agencies: The Full Technical Report 在 Steam 上购买 FriedrichAI: Offline AI 立省 10% GitHub - inevolin/resume-cli: Hit Claude usage limits? Resume any AI coding session elsewhere. Switch tools at zero friction. GitHub - atripati/ark: AI Runtime Kernel — a context operating system for AI agents. Eliminates tool bloat, loads only what’s needed, and gives LLMs their reasoning space back. How to Build a Secure AI PR Reviewer with Claude, GitHub Actions, and JavaScript This Startup Wants You to Pay Up to Talk With AI Versions of Human Experts Intel Arc Pro B70 Brings 32GB VRAM to Local AI for $949 WordPress 7.0: The Good, the AI, and the Still Missing AI on the couch: Anthropic gives Claude 20 hours of psychiatry AI Agents Know About Supabase. They Don't Always Use It Right. The history and future of AI at Google, with Sundar Pichai Inside an AI‑enabled device code phishing campaign How Meta Used AI to Map Tribal Knowledge in Large-Scale Data Pipelines AI for Systems: Using LLMs to Optimize Database Query Execution Forecasting the Economic Effects of AI Introducing Tinker: Play with AI, bring your ideas to life AI sheds light on an ancient gaming mystery People really hate AI but not as much as Iran—or Democrats | Fortune What is an AI Product Engineer? Phoebe Gates wants her $185 million AI startup to succeed with 'no ties to my privilege or my last name': 'I have a chip on my shoulder' | Fortune
Quick: An internal hosting platform for the AI era (2026) - Shopify
Daniel Beauchamp · 2026-06-14 · via Hacker News - Newest: "AI"

Shopify attracts people who love to tinker. Building has never been the bottleneck here. People are always making things: prototypes, dashboards, little tools for their teams. The hard part was getting those things in front of anyone else.

Our solution to this was Quick: an internal platform where you drop in a folder of HTML and assets and get back a secure URL that only Shopify employees can see. No frameworks, deploy pipelines, or config files. You just upload a folder and your site is live. If you need a database, AI, file storage, or websockets, those are just an API call away.

We launched Quick in July 2025, and the timing turned out to be perfect. AI had just gotten good enough that people across every discipline, not just us engineers, could generate a working website from a prompt. Quick gave them somewhere to put it. AI wasn't why we built it, but it's a big part of why it took off.

Today, Quick hosts more than 50,000 sites across Shopify. Over half the company has created at least one. Everything from dashboards that teams rely on daily to a multiplayer mountain-climbing game that nobody asked for but everybody plays.

This is how we got here.

Architecture

Quick started with the idea of finding the simplest way to put HTML files somewhere and serve them. And what's simpler than every "site" being just a folder of assets in a Google Cloud Storage bucket?

To serve them, we put a lightweight NGINX server in front, with a wildcard config so that mysite.quick.shopify.io maps straight to the mysite folder. But we didn't want NGINX to know anything about querying buckets. This is where gcsfuse came in: it mounts the bucket as if it were part of the local filesystem, so NGINX thinks it's just serving local files.

Authentication is just as simple. The whole server sits behind Identity-Aware Proxy (IAP), so every request is already a verified Shopify employee before it ever reaches a site.

The `quick deploy` command is nothing more than a small wrapper around gcloud’s rsync. It grabs the files from your local directory and pushes it up directly to the bucket. Feels like the good old days of FTP.

The next step: APIs

In this configuration, Quick could already accommodate many use cases. But what if your prototype or site needed just a little bit of functionality from a backend? Maybe it’s to store a bit of data, or upload a file, or call out to AI. Now suddenly you’re left having to spin up databases and infrastructure, which feels like overkill in many cases.

That’s when we thought to ourselves, “what if we had a single server that all sites on Quick could access and could provide basic backend services?” Give it a nice little client-side API and you’re all set.

Want your Quick site to save a blog post?

const posts = quick.db.collection('posts');
const created = await posts.create({
  title: 'Hello Quick DB',
  status: 'draft',
  created_at: new Date().toISOString()
});

Need realtime updates when something changes?

const unsubscribe = posts.subscribe({
  onCreate: (doc) => console.log('New:', doc),
  onUpdate: (doc) => console.log('Updated:', doc),
  onDelete: (id) => console.log('Deleted:', id),
});

The original Firebase was a big inspiration for us. It let you easily spin up a key value store exposed to the internet that you could just read / write to. You didn’t need schemas, or migrations, or anything. And best of all, anything you saved in it magically synced across all connected clients.

We initially played around with the idea of each Quick site having its own sqlite database, but that didn't play as well as we hoped with gcsfuse. It was much easier to spin up a single CloudSQL database with a nodejs server in front of it.

AI was the next feature we added, so that any Quick site could make client-side calls to the LLM of their choosing without needing to provide any API keys. The API keys are stored on the server and passed along to our Shopify AI proxy.

// Make LLM calls right from your browser
const res = await quick.ai.chat([{ role: 'user', content: 'Summarize my tasks' }]);
// Can also call image gen and any other frontier models

Then we kept going through the list of things that sites might need. We added file uploads, data warehouse support so sites could pull in data from Big Query, and Websocket support to make it possible to build collaborative apps.

Since the sites are behind IAP, we have all the user information needed for any request, which we can provide to the client. That way sites can instantly know who is using it, and that becomes part of a nice little Identity API with things like name, title, team, Slack handle, etc.

By the end of it we landed on this core group of features:

  • Database
  • File uploads
  • AI (LLM, image gen, etc...)
  • Data warehouse
  • Websockets
  • Identity

It's amazing how just with these few building blocks it feels like we can recreate the entire Internet

Exposing any of these services to the public internet without authentication would make an ops team lose sleep. But since Quick sites are only accessible within the trusted walls of Shopify, we have the luxury of being able to provide a zero-config client side API. All keys are stored on the server.

Agents + Quick

While there are docs for all the Quick APIs, I’m not sure if anyone has ever actually read them. That’s because Quick comes out of the box with all the skills your agent needs to use them. All you have to do is type `quick init`, launch your favourite agent, and you’re off to the races.

“Make me a site where my team can vote on lunch spots in real time.”

"Make me a site where we can run a live poll during the all-hands."

In less than a minute you have a site up and running, ready to be shared and used by all.

"Can I see multiplayer cursors for everyone on the site?”

Thanks to the websocket API, you sure can!

Adoption

Quick launched internally in July 2025. Those of us who were already vibe-coding HTML artifacts finally had somewhere secure to host them. Those struggling with app deployment complexity now had an easy path. And for everyone else, they didn't see what the big deal was….yet.

For the first bit, it felt just like Geocities. People were making personal homepages.

Out of pure nostalgia, someone made a webring and even a birthday site with a guestbook.

These days, if someone puts an open guestbook or comment field on the open web, it’s sure to get hacked or filled with spam. But in the Shopify trust bubble, that’s not a concern. We were reliving the joys of the early 2000’s web without any of the downsides. The big difference is that anyone could now author HTML thanks to AI.

Then in December 2025 things really popped off.

It’s now being used for everything from prototypes, dashboards, dev tools, and presentations.

Designers will just create custom tools for their teams to use. Like Artifact, an internal tool for sharing work.

It’s become second nature to reach for it. Want to share an idea for how themes are shown in the admin? Don’t share an image, share a Quick site.

Need a tool for customizing the interactive background on the latest Remix landing page? Build a Quick site.

Google Meet had a small outage last year, and within 15 minutes someone vibecoded a replacement that used WebRTC for communication.

It’s completely changed the culture of how we build and share. And while we are using it mostly for “serious” use cases, there’s still that underlying Geocities feel that invites people to tinker with weird and delightful things.

There’s a good amount of games that people are building, especially since the websocket API makes it so easy to add multiplayer functionality. Over 140 games were submitted at a recent game jam.

If you wanted to add a leaderboard to a public game on the internet, your first thought would be how to prevent hackers. Once again, Quick being internal removes all that. It takes “should we add a leaderboard” from a “maybe” to a “hell yes!” It’s a creative paradise.

An emergent ecosystem

One thing we didn’t anticipate when building Quick is how people would start embedding sites within other sites. Because it's just the web, one site can import code straight from another. So we noticed people started publishing shared JS libraries, and even making landing pages for them.

Quick is growing into its own internal ecosystem. You can find libraries for adding Figma-style comments to your site, for adding voice, analytics, achievements, and so much more.

The Quick philosophy: Keep it simple + embrace the constraints

You might be wondering how we implemented permissions, or how people manage their sites. Turns out there’s none of that. All Quick sites are open to all employees. There’s not even a concept of a “site owner.” Want to update your site? Overwrite it with new files. Want to take over a subdomain? Overwrite it!

It’s amazing how the complexities of the open web just disappear when something is an internal tool.

Every day we get new feature requests. Can we get custom backends? Can you add cron jobs? We've gotten really good at saying no, which is especially hard in an AI climate where you can vibecode a new feature in minutes. But the constraints are the whole point.

A small, fixed set of capabilities is what keeps Quick simple to use and maintain, and it's what makes people more creative, not less. When someone comes to us with feature request X, more often than not we can show them it's already possible. They just have to approach it differently, and they leave a little surprised at what the existing pieces can do.

Maintenance

As of now over 50,000 Quick sites have been created. More than 50% of Shopify employees have created at least one site. And all of this is running on a single VM that costs $200 a month to run.

Since so much of it is client side, the server is only in charge of serving assets and processing API requests. As for scale, we know how many employees we have so there’s never a danger of somehow 1,000x more people starting to use the platform all of a sudden.

That’s not to say there haven’t been hiccups along the way. We’ll sometimes find someone trying to do a batch process job on a loop and store massive amounts of data in the database. That’s led us to implement some rate limiting practices.

We’ve also over time migrated away from node to using Go, which helps a lot with memory management and parallelism.

A place to tinker

We started Quick because sharing things at Shopify was harder than building them. The fix turned out to be almost comically simple: a folder of files, a URL, and the trust that comes with everything being internal.

Because everything on Quick is visible to every teammate, each site teaches the next person what's possible. Tobi has a word for this kind of environment: Lehrwerkstatt, a learning workshop where knowledge spreads through proximity. We just gave it a domain name.