Run Qwen 3.8 Flash Next (125B) on consumer hardware (RTX 4090) at 100T/s
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
Run Qwen 3.8 Flash Next (125B) on consumer hardware (RTX 4090) at 100T/s
Unofficial Hacker News client; not affiliated with Y Combinator.
deadbunny · · focus · HN ↗
And I thought piping to bash was bad
Skunkleton · · focus · HN ↗
minitech · · focus · HN ↗
(I picked this option for ease of comparison, getting a couple of major security wins with very low effort; I don’t recommend `npx`ing stuff in an otherwise unprotected environment either.)
* well, you can be somewhat more sure
athrowaway3z · · focus · HN ↗
`curl <a href="https://raw.githubusercontent.com/my/domain/setup.sh" rel="nofollow">https://raw.githubusercontent.com/my/domain/setup.sh | sh`
Note we dont even have a hash there - just a promise that a third party (github) has a log of whatever was hosted at that url.
nagaiaida · · focus · HN ↗
slowin · · focus · HN ↗
minitech · · focus · HN ↗
slowin · · focus · HN ↗
cpuguy83 · · focus · HN ↗
I'm not replying here to say one is better than than the other (npm has obviously had its share of problems) but rather to combat claims that curl|bash is somehow safer, it absolutely is not, in fact it's all the bad stuff about npm without the pretense of being potentially safe.