Hacker Newsnew | past | comments | ask | show | jobs | submit | ateles's commentslogin


ServeTheHome already reported on CLX memory expansion controllers back in December: https://www.servethehome.com/hyper-scalers-are-using-cxl-to-...


> Luckily for most packages this is reasonably doable, IFF you trust the upstream sources they fetch from.

Don't forgot to also check the applied patch files. Many AUR builds include custom patches to make something work, making this a convenient way add something malicious into the build. An extreme example for patches is ventoy's 1355 line long PKGFILE [0] sourcing lots of patches both from external domains as well from the git server on aur.archlinux.org itself.

[0]: https://aur.archlinux.org/cgit/aur.git/tree/PKGBUILD?h=vento...


For completeness another trick to deceive people can be to have (git/http) sources from places other then just the official repo, like in the example you linked. When changed they will just show up as a a "hash" change... which is fine for the original upstream source (if trusted) but not for anything else.

But in general I would think 4 times about installing any AUR package no longer reasonable reviewable in the parts not either in official packages or the upstream source (including patches, dependencies, etc.).

Sometimes throwing something into an untrusted OCI image you run in a VM (instead of lightweight containers) is just the better option... sadly, also often still painful to setup.


> Worse: it's a conversation killer. There's nothing to respond to. Your wall of text suppresses dialogue. They can't reply, can't push back, can't clarify. It's a weapon disguised as helpfulness.

Also my main problem with many chat bots. Too many different aspects brought up at once. Short answers would be more eco-friendly too.


I find this to be my current number 1 challenge when working on a terminal and seeking explanations for why a problem was approached in that way. the terminal only holds so many lines at once. Let's not talk about current scrolling in terminals.

It's interesting that the LLM will oblige my succinctness requests for one or two replies then back to 7 paragraph answers that I can't reply to point by point in a TUI.


I think this varies by expectation. If you use voice, their response will be shorter and more human. If you write, you will get a whole article in response. This lets you get to what matters to you faster, as long as you're able to skim documents.

If I write and want a short response I preface it with "be brief." Sadly it doesn't work 100% of the time


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: