Run Qwen 3.8 Flash Next (125B) on consumer hardware (RTX 4090) at 100T/s
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
Run Qwen 3.8 Flash Next (125B) on consumer hardware (RTX 4090) at 100T/s
Unofficial Hacker News client; not affiliated with Y Combinator.
deadbunny · · focus · HN ↗
And I thought piping to bash was bad
snehesht · · focus · HN ↗
gchamonlive · · focus · HN ↗
Skunkleton · · focus · HN ↗
spiorf · · focus · HN ↗
sspiff · · focus · HN ↗
When I install something, and it asks for my root password later, I will be much more likely to think "hold up, this ain't right".
jeremyjh · · focus · HN ↗
serf · · focus · HN ↗
oh my zsh is a specific example.
chsh requires sudo on most installs.
minitech · · focus · HN ↗
nagaiaida · · focus · HN ↗
serf · · focus · HN ↗
what use is hashing every piece of software that goes thru the distros package manager just to throw caution to the wind at the layer above it?
w.r.t. "it's already from the same domain" , well most bash/z install scripts either invoke a package manager or they download and untar a package that has nothing to do with the host domain, anyway.
layer8 · · focus · HN ↗
Iolaum · · focus · HN ↗
layer8 · · focus · HN ↗
And everyone running a research agent on every download can’t be the solution. It’s much more effective to crowdsource a security database based on hashes. But for that, the downloads need to be self-contained.
parsimo2010 · · focus · HN ↗
thomastjeffery · · focus · HN ↗
[deleted] · · focus · HN ↗
[deleted]
ffsm8 · · focus · HN ↗
<a href="https://news.ycombinator.com/item?id=17636032">https://news.ycombinator.com/item?id=17636032
The original blog is no longer available though.
But I've not had that stop me from doing that myself, I am more towards the "I like easy" then the "I want to be secure" crowd
wsc981 · · focus · HN ↗
<a href="https://web.archive.org/web/20250109045029/https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/" rel="nofollow">https://web.archive.org/web/20250109045029/https://www.idont...
throooooo · · focus · HN ↗
minitech · · focus · HN ↗
(I picked this option for ease of comparison, getting a couple of major security wins with very low effort; I don’t recommend `npx`ing stuff in an otherwise unprotected environment either.)
* well, you can be somewhat more sure
athrowaway3z · · focus · HN ↗
`curl <a href="https://raw.githubusercontent.com/my/domain/setup.sh" rel="nofollow">https://raw.githubusercontent.com/my/domain/setup.sh | sh`
Note we dont even have a hash there - just a promise that a third party (github) has a log of whatever was hosted at that url.
nagaiaida · · focus · HN ↗
slowin · · focus · HN ↗
minitech · · focus · HN ↗
slowin · · focus · HN ↗
cpuguy83 · · focus · HN ↗
I'm not replying here to say one is better than than the other (npm has obviously had its share of problems) but rather to combat claims that curl|bash is somehow safer, it absolutely is not, in fact it's all the bad stuff about npm without the pretense of being potentially safe.
rlpb · · focus · HN ↗
bee_rider · · focus · HN ↗
majorchord · · focus · HN ↗
bee_rider · · focus · HN ↗
IshKebab · · focus · HN ↗
The technical excuses they come up with (e.g. that the server can detect it and send different content) are just post-hoc justifications for their instinct.
Just ignore them.
mrinterweb · · focus · HN ↗