Me and 99% of users won't check the code for malicious behaviour so I might as well run a binary from the web.
Me and 99% of users won't check the code for malicious behaviour so I might as well run a binary from the web.
When (not if, when) binaries get trojanned, this causes blame to be directed at the original author, and takes a lot of work to explain that they are not at fault - this has happened in many supposedly reputable download sites including SourceForge, TUCOwS, Download.com and many others (yes, I haven’t used windows in 20 years or so, no idea what the hip new places are)
Say “thank you”, and spend 10 more minutes yourself to set it up (even if compilation takes 5 hours, it’s usually 10 mins to get it started). And then offer it for others, and handle the ricochets when it gets trojanned with no wrong done by you.
If just 20 people adopted such a process, there would be 98% less complaints of this kind.
Genuinely curious.
Anyone not technical enough to compile a binary has to give up trying to use it or risk some unnoficially distributed executable .
Not to mention that the md5 checksum is a very poor choice for this purpose because of the ease of creating md5 collisions.
That's the whole point of using a cryptographic signature backed by a web of trust instead of a mere hash.
Okay so if 20 people did the same work over and over it would reduce 98% of the complaints.
Contrast that to if the author did the work once, it would reduce 100% of the complaints!
Do they owe you anything?
I am not a python dev and testing AI stuff in Python made me hate python ecosystem (not the language ) a lot. All this new AI projects are made by enthusiaste, they depend on a specific CUDA version, a specific A,B,D python lib versions. Very often shit does not work anymore and you need to google and hope other person was unlucky before you and posted some commit version of the stuff that still works.
My advice for people that test AI stuff, after you get it working do not update, try if possible to install the new version side by side and see if it works, it saves you the pain to roll back to a good version.
All of these, along with those package managers have had malware posted to them.
If you're going to use something that needs a bit of technical skill to operate correctly, you're going to need at least enough skill to get it running.
Roads would be far safer if every car had some facility by which you had to remove and refit some random engine or braking system component correctly before it would start.