Hacker Newsnew | past | comments | ask | show | jobs | submit | dbgobrrr's commentslogin

Good move! I was there before, and the worst part was... I was using a @gmail.com address. Bad mistake on my part. So actually tracking what I used the address with, that was my real pain. Now everything is on my custom domain, so if I need to move on from my current provider, it will be painless. In the process I did manage to delete a whole bunch of accounts I didn't use anymore.

Incidentally, I also moved to fastmail, and it is just boringly fantastic. It works. It has features I actually need and enjoy (masked emails!) and I recommend it to anyone who asks.


>I was using a @gmail.com address. Bad mistake on my part. So actually tracking what I used the address with, that was my real pain.

This is thankfully mostly solved now by AI. I recently had a do a migration that I had been putting off for years and it was relatively painless.


> This is thankfully mostly solved now by AI.

How did you solve this with AI?


They said “mostly”. AI solves 90% and then you solve the other 90%.


Lol. On almost every post someone comes in to say that $problem was easily solved by AI. Usually out of the whole context of the thread.

Snake oil level comments.


What is the 90%?


I had it read all of the emails find which accounts were associated with the old email and then go switch them to the new email. I only had to manually intervene for 2 accounts out of 36ish.


Lemonade-server works pretty well (most of the time). It wraps llama.cpp and other runtimes - it downloads the official binaries as far as I could see, and you can set alternative versions if needed. Works nicely with Strix Halo for a while now.

https://lemonade-server.ai


> users being warned multiple times that it's vital to review anything before you install it, compared to the official repositories.

I think this stance should be re-evaluated. Arch Linux developers are doing a fantastic job and I am personally thankful to them - this is not in any way critical of them. And while I don't see an easy solution here, I just feel that the time of "warning users" is long gone with how much supply-chain attacks are ramping up these days.

Some other controls could at least alleviate the problem. Perhaps some form of peer-review and grace period before publishing could help here?


Idk. Arch does have official repositories that are actively maintained and vetted. AUR is for the vast amounts of random software that isn’t popular or important enough to be officially maintained.

I’m not sure how to find a balance. One reason to use Arch is to always have the latest software, especially if you’re gaming. (Need to run very recent kernels, GPU drivers, and DEs to support new graphics cards.) So that’s very different from other stable LTS distros which carefully pick the package updates they incorporate.

Anyways, I do agree package cooldowns and such make a lot of sense. Package managers should be pulling out the stops on all the free controls they can implement. I can understand why anything requiring compute or maintainer time is a non-starter. (Sidebar: I don’t feel the same way about npm. Microsoft can afford to run malware scanners and analysis tools on npm packages.)

https://wiki.archlinux.org/title/Official_repositories


There's some big stuff in AUR like the binary VS Code and Chrome, fwiw.


I wouldn't those programs. You have the corresponding FOSS versions (code-oss and chromium) in the main repository. Chrome is basically spyware.


I'm on Kubuntu and I install VS Code using Microsoft's repo and Chrome using Google's repo. Also I do Wine and Docker using their own repos. I can't imagine VS Code or even Chrome being put into the mainstream Kubuntu/Ubuntu repos nor why such a burden should ever be shifted to Canonical.


That’s because you’re using something those companies officially support. Is your argument everyone running Linux needs to be on a Debian-based or Fedora-based distribution?

Btw the official “vscode on Linux” instructions literally point to the community maintained AUR (same for nix).

The truth of the matter is the AUR is poorly maintained structurally, regardless of what companies officially support. Things like letting arbitrary people unilaterally take over orphaned packages is horrendously stupid.


Stupid or rather low-friction on purpose?


Stupidly low friction. Consistently failing to learn from the mistakes of package managers is bad enough. Failing to learn from your own is another level.

“Learning from your mistakes is good. Learning from the mistakes of others is better”.

For all its flaws, at least Cargo attempts to do that. AUR does not. No other package manager this regularly has hijacking problems.


Both. And that's an even worse combo, making stupidity frictionless.


Since you are using the official repos thats not an issue. The issue is when the package creator is some rando on the internet.


It's definitely a sign that popular packages should be moved from AUR to the official repository. I've got some stuff from AUR simply because it's something I need and that's where it is, and I never really verify it's safe; I just trust it blindly. Clearly a bad idea. I guess I should learn to avoid AUR and when I do use something from it, we more aware it's an exception and I need to check it more thoroughly. That's something I normally only do only for stuff that's neither from AUR nor the official repo.


How much work is created (and for who) when a package is moved to the official repository?


A package maintainer has to be interested and willing to support it. Sometimes packages get dropped from the official repositories into AUR when the maintainer loses interest, and noone else wants to pick up the slack.


> Some other controls could at least alleviate the problem

The biggest one I'd suggest they change immediately is remove the ability for anyone to just take over an orphaned package. That's a crazy policy, to me.

It should require you to fork it & resubmit, not take over the original.

Then they can go through and do purges of orphaned packages that are beyond a certain age.


How would this help against someone submitting an actual, non-compromised version bump, then adding malware once it's accepted?


Personally, what you suggest would defeat the purpose of the AUR, and what you describe is already applied to the official packages. If you want only the safe and stable stuff, don't use random packages from AUR :)


Have the same router (Flint 2), and had a similar issue in the past. After I configured SSIDs with different names on the radios (i.e. the SSID is either configured on radio0 or radio1, not both), I didn't encounter this anymore. YMMV, but this helped me - perhaps it'll prove useful to you as well.

And besides this issue, overall it works great. I recommend this to anyone who asks me about it.


I regularly follow Jeff Geerling's blog and I value his opinion (usually), and I understand his points - he does make very good points in this article. However, the conclusion really irked me:

> As I mention in my video, the Framework 12 isn't a bad laptop, it's just a bad value, especially in comparison to the Neo.

Saying it is bad *value* is off the mark completely. There is, unless you are willing to use MacOS (which is a knock-out criteria for me: I love Apple hardware, but I cannot stand the OS and its artificial restrictions it imposes on the user).

I own a FW12 and for me the main driver was a light laptop with good battery life[1], that I can install my own Linux on it, and the drivers all work from day one on a new laptop. The last bit is not taken for granted, I have been bitten many times by this (as I'm sure many of you did). On top of that, I decided I will not have any more android devices if I can choose otherwise[2] - and the FW12 is a good tablet replacement. It's great to watch videos with (tent mode).

So for me, personally, it is great value, and the Neo would just become a secondary device I would very rarely use. Low utility means for me low value, YMMV.

[1] The battery itself is great. I get real 10-12 hours of work on it regularly! But obviously intel CPU cannot rival Apple on power consumption, as you can see in the benchmarks in the article. [2] Android or iPhone are unfortunately a requirement for modern life. That's just so sad and I wish it would be legislated that apps that are needed (banking, civil services, etc.) *must* work on an alternate OS without the user hostility (I'd mention here: https://keepandroidopen.org/)


What you’re saying is valid, but it doesn’t take away from the “bad value” statement. Jeff was speaking value for money, you’re talking subjective utility value. Reviews cannot, and should not even try, to include that in their assessment. Sure, mention the limitation (and he did), but to assign a value to it for comparison is called “personal bias” and it’s no different than saying “it’s twice the hardware for half the price, but gloss black is a boring color, so 1 star.” Reviewers should always state value as “dollars per pound” and $1 for 10lbs is a better value than $1 for 5lbs; that you personally can’t fit 10lbs in your vault doesn’t change the assessment.

The real problem is that “value” is an ambiguous word, so everyone is right and wrong while talking about the same thing entirely differently. Yeesh.


It's a terrible take and he absolutely exposed himself as an apple shill.


> It might keep up with Sonnet 4.5 with some tinkering.

I would love to see that. I've been using Qwen3.6 35B and the dense 27B, and they are both too slow with not such great results for agentic coding tasks. It's ok, but not impressive. I had better luck with the BF16 and Q8 than the Q4 from unsloth (really love what unsloth is doing in this space). Another problem I had with Qwen, which I did not ever encounter with Sonnet - even the BF16 gets stuck and needs a "continue task" prompt from time to time, the lower quants are even worse in that regard.

If you get some interesting results, I would love to read about it!


You don't mention runtime, hardware and harness which are critical. The 35B A3B model should be pretty fast, you do need a decent setup but nothing too fancy. I'm using Q8_XL from unslouth with llama.cpp and opencode and it's pretty awesome. I find that opencode drives the model best, it very rarely gets stuck even with a ton of tool calls. I agree it's comparable to Sonnet 4.5 for most tasks. You may also try the Gamma 4 models which are faster but not as good for coding.


With GNU/Linux, yes. With Android/Linux, not so much. [1]

(I used to dislike this "GNU/Linux" term, it seemed unimportant - Android showed me why the GNU part of it is)

[1] https://keepandroidopen.org/


I don't think anybody implied or thought of Android in this subthread, just because it nominally runs the Linux kernel. I for sure understood it as just "Linux = whole OS-level distros of the laptop/PC bound type" not "anything with a Linux kernel even if it's a proprietary mobile phone OS".


Only if you have the closed-source Google Play Services... Just like desktop, there are plenty of Android distros like LineageOS


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: