Hacker Newsnew | past | comments | ask | show | jobs | submit | rescbr's commentslogin

I'm using maki (https://maki.sh), it has 1, 2 and 3.

I just wish it wouldn't ask me to pipe an install script directly to shell to install.

Yes, I can probably inspect that but I do think installing through package managers is the best practice.

It looks better than pi with XDG and not being JS but that is it's own red flag for me.


I personally also don't like this, so use cargo to install it, it's in the readme. Takes a reasonable time to build on my X220, but on a modern computer it is plenty fast.

  cargo install --locked --git https://github.com/tontinton/maki.git maki

Is there a meaningful security difference between curl-pipe-bash and cargo install --git? Couldn't the cargo install include a buildscript that jumps right into a shell?

Sure, but you can review the git repo's content/commits in plain text, while curl-pipe-bash would require you to reverse engineer the binary that's downloaded.

If somebody hacks the project's home page and switches the download location to a hacked binary, you'd be none the wiser. Of course, somebody could hack the repo and add a deliberate vulnerability as well, but at least you would have a trail of it.


You can review the contents of the git repo before building it.

For curl | bash, you cannot. “But you can pipe to a fil—“ nope: https://tferdinand.net/en/why-curl-bash-is-a-dangerous-bad-h...


Me too, maki in --yolo mode within an incus NixOS container, giving maki rootless (nested) podman and nix flakes powers (so it can install and run whatever tools it needs), with 100% ds4-flash it's extremely powerful and super cheap.

This is definitely not my experience with GLM-5.2. It is writing pretty good ARM SIMD code.

It also is an excellent radare2/rizin/ghidra driver as well. Maybe it's because its ~cyber~ capabilities (pretty much linked with assembly-level knowledge) aren't guardrailed off?


> questions about the modern Chinese history, to which a Chinese LLM will not answer

This has been debunked here on HN so many times. The Chinese open models do answer the hairy Chinese political questions, and the raw APIs pass-through the response. Now, the answer might be blocked by the agent who's calling the API, specially if you are using a Chinese endpoint instead of the RoW (i.e. Singapore) endpoint.

That's the reason why you should always prefer a open agent/harness as well instead of using the provider's.


I'm Brazilian and I had never connected "insha'Allah" to "oxalá". Wow, TIL.

At least we were taught in school that if a word starts with "al" then there is a big chance it has roots in Arabic.


Still, somebody heavily funded this thing for too long, and I very much doubt that we don't have the surveillance apparatus in place today for these things to get unchecked.

Stuff is known but not acted upon for various reasons.


That's why you don't run the model at low quantization

I also make nerdy jokes/puns, and I had similar experiences with beneficial model steering that such puns create.

It's interesting how more loose/informal prompting achieves good results, there is some cultural understanding in the models from training. Once I asked the clanker to remove the gambiarras and puxadinhos that it wrote as part of an experiment, and it promptly fixed those.


They claimed the model was PhD-level, but they never mentioned the university the model graduated from... :)


I currently have a free trial AI Pro subscription that will run out next month.

If it weren't for the $10 GCP credit, I'd straight away cancel it. I don't see enough value in Gemini to justify the $20 subscription.


Similar here. I saw an email wanting the 20 bucks to continue and I outright laughed. There’s no planet on which that plan offers equivalent value to the OpenAI or Anthropic equivalents.

They might have success if they tried maybe a 12-15 dollar tier.


I feel the same. I feel Anthropics' raw models are excellent, but Claude Code's bloat make them lose some potential.

This and I very much miss reading the chain of thought. At least I have it on GLM-5.2.


I've tried GLM a few times but each time it ends up getting stuck in a loop and burning tons of tokens before I eventually kill it and restart. Has anyone had the same issue / know how to avoid it? I've been using Qwen 3.6 instead


Where are you sourcing the API from?

I have zero quality issues on Z.ai Coding Plan and maki.sh as the coding agent, but I've seen many reports on 3rd party providers that they host heavily quantized versions of GLM models.


Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: