HNHacker News
TopNewBestAskShowJobs

cpuguy83

1,989 karma · joined October 9, 2013

[ my public key: https://keybase.io/cpuguy83; my proof: https://keybase.io/cpuguy83/sigs/MuEz1UU_zSo4UKnd094MCmzz00ECpwuyAEYaDzBwZQY ]
submissionscomments
cpuguy83··on Run Qwen 3.8 Flash Next (125B) on consumer hardware (RTX 4090) at 100T/s
With curl|bash you are literally getting anything that happens to be in that script. These are frequently poorly constructed, so not check hashes or pin dependencies they install. Even security companies (see trivy supply chain attack) get these badly wrong.

I'm not replying here to say one is better than than the other (npm has obviously had its share of problems) but rather to combat claims that curl|bash is somehow safer, it absolutely is not, in fact it's all the bad stuff about npm without the pretense of being potentially safe.

cpuguy83··on OpenAI Discloses Six New Incidents of ‘Concerning’ A.I. Behavior
Training AI on the stories we created about AI taking over causing AI to have that idea. Ouroboros.
cpuguy83··on Tether: iMessage, SMS, etc. on Linux
It doesn't do messages or notifications. "Just" things like file copy and clipboard.
cpuguy83··on Tether: iMessage, SMS, etc. on Linux
kdeconnect has an iOS client.
cpuguy83··on Tether: iMessage, SMS, etc. on Linux
"Easy" is subjective, but tether seems like it would do this? There is also kdeconnect (don't let the "KDE" fool you).
cpuguy83··on Tailcat – Like netcat, but over Tailscale’s data plane
Also created memcached, livejournal... Brad has a long list of impressive work.
cpuguy83··on Tailcat – Like netcat, but over Tailscale’s data plane
Interesting. I thought about doing this immediately after reading their old blog[1] post on punching through NAT some time ago.

Just a combo of never getting around to it and friends talking me out of it b/c of existing alternatives such as wormhole[2].

[1] https://tailscale.com/blog/how-nat-traversal-works

[2] https://github.com/magic-wormhole/magic-wormhole

cpuguy83··on New Mac mini, featuring M6 and M5 Pro
Larger model -> more memory

It depends on what model(s) you want to run.

cpuguy83··on Malicious Rust crate Arrayref runs a build-time payload
Sure, but I don't expect build to execute arbitrary code. That's a big difference.

It's like if `git clone` ran random stuff from the cloned repo.

cpuguy83··on Malicious Rust crate Arrayref runs a build-time payload
The problem isn't the language here, it's cargo executing build.rs from dependencies which necessarily allows arbitrary code execution.
cpuguy83··on Universal health coverage could save $1T and 114k lives a year: study
The US is not much different. We don't have a wealth of specialists available to see people right away.

I've flat out been rejected from a specialist because they had no availability at all. I actually tried again and got to be seen, but an appointment is months out, always.

cpuguy83··on Docker Sandboxes – Disposable, isolated sandboxes for AI agents
I'm fairly certain that docker sandbox is based on https://github.com/containerd/nerdbox which you can run on Linux.
cpuguy83··on I stopped trusting USB-C cable labels and started testing them
USB-C is literally just the name of the connector. USB-A can also have varying speeds across it... and B. These are all connectors, not speed ratings.

There is usb 1, 2, 3, and 4 that are more of a statement on the performance capability.

cpuguy83··on Go 1.27 Interactive Tour
I'm pretty sure the issue is not "higher order abstractions". It is using multiple single letter references with no real grounding or relationship that the reader has to track.

For example, looping over a map with "k" and "v" vars is not that bad because the reader understands k=key and v=value, and that makes since for a map. If you do this same thing with different single letter vars, e.g. "a" and "b", it instantly becomes more difficult to read.

When writing a generic function and using these single character type references it can make sense, especially because the function/method doesn't care what those references are, however to someone trying to understand what's going on it can be extremely difficult simply because of the names.

Sure, if all you are going to do is call that method or function those type references go away and the call site may be relatively clean, but you still have to read the thing to understand what it is and how to use it.

cpuguy83··on Elevators
Enjoyed the read, thanks!

Beyond the content, the font, style, etc made it a pleasant experience for me.

cpuguy83··on Cruller: Bun's Zig Runtime, Continued on Zig 0.16
Bug is uncovered. Where was it first introduced? Why was the code changed? What did it do before the bug was introduced?
cpuguy83··on Show HN: Davit, a Apple Containers UI
This is focused on builds, so running either buildkitd or dockerd in an Apple containerization container. No port forwarding or host volume stuff (really its focused on running buildkit on mac) BUT complete integration with docker CLI and buildx.

https://github.com/cpuguy83/crucible

cpuguy83··on Why Vancouver is always a stand-in for San Francisco in movies and TV shows (2021)
Thanks for this. Just started another rewatch and were of course in awe of the house.
cpuguy83··on Vulnerability reports are not special anymore
Plenty of people offended by closing a PR or issue unresolved.
cpuguy83··on Vulnerability reports are not special anymore
In an ideal universe yes. But we live in a world where vulnerability scanners reign supreme.
cpuguy83··on Vulnerability reports are not special anymore
It's not (just) more of them, it's the same ones reported by multiple people.

I think the point is those issues are now easily discoverable and are nearly public because of it.

cpuguy83··on The AirPods Effect
I'm reminded of the old-timey picture of a bunch of people on a train staring at their newspapers. Nothing new here.
cpuguy83··on macOS Container Machines
Not a full docker env, I aimed this as doing builds though you can run dockerd as an option, https://github.com/cpuguy83/crucible uses the containerization framework to run either build kitd or dockerd and wire it up to docker/buildx cli (or whatever client tooling you want to use).

The Containerization framework is a library that sits as a layer on top of the virtualization framework. So each container is its own VM.

Machine is tooling above the containerization framework to run multiple things in a container in a vm.

cpuguy83··on Codex just found a "workaround" of not having sudo on my PC
Hold onto your butts.
cpuguy83··on Codex just found a "workaround" of not having sudo on my PC
No, docker access means root. You can use "rootless" mode, in this case it means root in a user namespace (that is not the "host" user namespace).
cpuguy83··on Killed by Apple
Apple did recently approve drivers for both nvidia and amd, but not for gaming purposes.

Apple supported OpenGL plenty, just that the world moved. Apple created metal, shortly after Vulkan was created.

"They could support it if they wanted to" is almost a tautology. Of course they could. But then they have to support another thing. They are on the hook when something goes wrong.

cpuguy83··on Apple Cuts More Mac Studio and Mac Mini RAM Options as Memory Shortage Worsens
Does it free up fab space to make the newer ram?
cpuguy83··on Docker 29 has changed its default image store for new installs
The whole entire reason is compression is not deterministic across tooling.
cpuguy83··on Docker 29 has changed its default image store for new installs
containerd 2.3 has support for erofs which does a direct import of the layer. It can even convert the tar based layers to erofs, faster than extracting the tar normally.

Also looking at block-based content store so that blocks can be deduped across images.

cpuguy83··on Docker 29 has changed its default image store for new installs
That is not correct. You would have to use the same compression tool (and likely version) for this to match.

Old docker discarded the compressed bits but kept some metadata about the the so it can at least recreate the tar.

It also recreated the manifest o push.

Page 1 of 32Next →