‹ BackHN Continuity

Thread

Run Qwen 3.8 Flash Next (125B) on consumer hardware (RTX 4090) at 100T/s

790 points · 352 comments · snehesht

  1. deadbunny · · focus · HN ↗
    &gt; Set up Strata on this PC for me: <a href="https:&#x2F;&#x2F;github.com&#x2F;Niko1221&#x2F;Strata" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;Niko1221&#x2F;Strata - follow docs&#x2F;AI_SETUP.md in that repository.

    And I thought piping to bash was bad

    1. Skunkleton · · focus · HN ↗
      I&#x27;ve never understood the security argument people are making when they complain about `curl foo | bash`. I get that these scripts sometimes mess up your bashrc or whatever, but from a security perspective I see no issue. You are already installing software from the same domain. If they were going to do something nasty, they could do it with any of the software you are using from them. It doesn&#x27;t have to be the setup script.
      1. ffsm8 · · focus · HN ↗
        You can detect the use of curl|bash server side, hence it&#x27;s an essentially undetectable attack vector. People have shown poc attacks of that kind all the way back in the 2010s

        <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=17636032">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=17636032

        The original blog is no longer available though.

        But I&#x27;ve not had that stop me from doing that myself, I am more towards the &quot;I like easy&quot; then the &quot;I want to be secure&quot; crowd

        1. wsc981 · · focus · HN ↗
          There’s a snapshot on web archive:

          <a href="https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20250109045029&#x2F;https:&#x2F;&#x2F;www.idontplaydarts.com&#x2F;2016&#x2F;04&#x2F;detecting-curl-pipe-bash-server-side&#x2F;" rel="nofollow">https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20250109045029&#x2F;https:&#x2F;&#x2F;www.idont...

        2. throooooo · · focus · HN ↗
          How would you do that? Just rely on the user agent? I use curl quite a lot, but don&#x27;t pipe to a shell.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.