‹ BackHN Continuity

Thread

Run Qwen 3.8 Flash Next (125B) on consumer hardware (RTX 4090) at 100T/s

741 points · 330 comments · snehesht

  1. deadbunny · · focus · HN ↗
    &gt; Set up Strata on this PC for me: <a href="https:&#x2F;&#x2F;github.com&#x2F;Niko1221&#x2F;Strata" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;Niko1221&#x2F;Strata - follow docs&#x2F;AI_SETUP.md in that repository.

    And I thought piping to bash was bad

    1. Skunkleton · · focus · HN ↗
      I&#x27;ve never understood the security argument people are making when they complain about `curl foo | bash`. I get that these scripts sometimes mess up your bashrc or whatever, but from a security perspective I see no issue. You are already installing software from the same domain. If they were going to do something nasty, they could do it with any of the software you are using from them. It doesn&#x27;t have to be the setup script.
      1. layer8 · · focus · HN ↗
        I push binaries from untrusted sources through VirusTotal before running them. Piping a Bash script from curl bypasses that. Furthermore, such Bash scripts, when they aren’t self-contained, make security checks more difficult than a self-contained archive, installer, or binary, even when downloading the script without immediate execution.
        1. Iolaum · · focus · HN ↗
          Nothing is stopping anyone from pointing their agent to that script to review and audit it before running it.
          1. layer8 · · focus · HN ↗
            I don’t believe an agent can do that effectively without a sandbox to run the script in, if the script isn’t self-contained.

            And everyone running a research agent on every download can’t be the solution. It’s much more effective to crowdsource a security database based on hashes. But for that, the downloads need to be self-contained.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.