7 ms·
Why is never a binary provided? Me and 99% of users won't check the code for malicious behaviour so I might as well run a binary from the web.
by EmilyHughes 3y ago
Why is never a binary provided?
Me and 99% of users won't check the code for malicious behaviour so I might as well run a binary from the web.
- frenchman99 3y agoEncouraging users to run some random binary from GitHub is a really good way to spread all kinds of viruses. People should only run binaries from trusted sources.
- marginalia_nu 3y agoCompiling and running random git projects isn't that big of a step up.
- frenchman99 3y agoYou're totally right, it's just as bad, maybe even worse because build tools sometimes ask for admin permissions. People should ideally really on some kind of reputation system or get software from trusted vendors.
- zamnos 3y agoYou probably don't run curl | sudo bash either but other people have different threat models.
- frenchman99 3y agoI do sometimes, when the source is trustworthy.
- input_sh 3y agoLinked somewhere in the middle of the README file: https://backgroundremoverai.com/?lang=en https://backgroundremoverai.com/?lang=en
- beagle3 3y agoThis is more than entitled behavior, it’s downright harmful. When (not if, when) binaries get trojanned, this causes blame to be directed at the original author, and takes a lot of work to explain that they are not at fault - this has happened in many supposedly reputable download sites including SourceForge, TUCOwS, Download.com and many others (yes, I haven’t used windows in 20 years or so, no idea what the hip new places are) Say “thank you”, and spend 10 more minutes yourself to set it up (even if compilation takes 5 hours, it’s usually 10 mins to get it started). And then offer it for others, and handle the ricochets when it gets trojanned with no wrong done by you. If just 20 people adopted such a process, there would be 98% less complaints of this kind.
- nwoli 3y agoGitHub will take it down if it contains blatant malware so it’s not that big of a deal
- VWWHFSfQ 3y agoSomebody would have to report that to them first though
- jdthedisciple 3y agoHow can a binary I provided possibly be trojanned by someone else? Genuinely curious.
- VWWHFSfQ 3y agoTrojaned installers by download.com were rampant back in the day. They would take your program and wrap it up in a nice little installer wizard and then also stuff a bunch of adware and spyware in there with it
- luizcdc 3y agoI don't understand what's the harm of having a releases page with a binary and its md5 hash, or how that keeps anyone from just compiling an unofficial binary themselves and adding malware to it. Anyone not technical enough to compile a binary has to give up trying to use it or risk some unnoficially distributed executable .
- IshKebab 3y agoBecause it's a Python project (like most AI code) and distributing Python code in easily usable form is an absolute nightmare.
- martsa1 3y agoI've not tried it with AI projects, but pyinstaller does a usually pretty solid job of packing up most python projects, and it's pretty simple to get started with.
- Cyphase 3y agoI've packaged various AI/ML/PyTorch/TensorFlow things with PyInstaller in the past. It took some hours of initial work, but the result was good. Things might be easier now.
- simion314 3y agoWill that package all the dependencies in? I am not a python dev and testing AI stuff in Python made me hate python ecosystem (not the language ) a lot. All this new AI projects are made by enthusiaste, they depend on a specific CUDA version, a specific A,B,D python lib versions. Very often shit does not work anymore and you need to google and hope other person was unlucky before you and posted some commit version of the stuff that still works. My advice for people that test AI stuff, after you get it working do not update, try if possible to install the new version side by side and see if it works, it saves you the pain to roll back to a good version.
- whitemary 3y agoBetter yet make a Dockerfile
- nadermx 3y agoHad not thought to make a binary for this project. I will look into this
- Gordonjcp 3y agoDeliberate barrier to entry. If you're going to use something that needs a bit of technical skill to operate correctly, you're going to need at least enough skill to get it running. Roads would be far safer if every car had some facility by which you had to remove and refit some random engine or braking system component correctly before it would start.
- zamnos 3y agoWould roads be safer, or would there be more mechanics? They seem like different skills.
- CapstanRoller 3y agoEveryone would be too busy wrenching on their cars to drive them
- Gordonjcp 3y agoRoads would be safer, because people would understand more about their car that "PUSH BUTAN GO FAST"
- Tao3300 3y agoRoads would be more dangerous. I put the work into my car, I'll drive how I want.
- weinzierl 3y agoBesides what beagle3 wrote: Providing binaries for various platforms is more work than you might think and the people who like to do development work are rarely the same people that like packaging and distribution. That's why developer and maintainer are separate persons more often than not.
- deleted 3y ago[deleted]
- Hard_Space 3y agoMy problem is the assumption by authors that the project being installed is the only one on the machine, and the fact that projects get so tied to particular versions of libraries. Therefore installing the PyTorch specified in this version is likely to be injurious to other existing installations, unless you handle it all in a Conda wrapper.