5 ms·
I suppose it's a good time to encourage people trying out pi[1] with any cheap model from the openrouter rankings page[1]. [1] https://pi.dev/ https://pi.dev/
by yanis_t 3mo ago
I suppose it's a good time to encourage people trying out pi[1] with any cheap model from the openrouter rankings page[1].
[1] https://pi.dev/ https://pi.dev/
[2] https://openrouter.ai/rankings https://openrouter.ai/rankings
- aftergibson 3mo agohttps://pi.dev/models https://pi.dev/models is throwing an internal server error for me.
- jwr 3mo ago"curl -fsSL https://pi.dev/install.sh https://pi.dev/install.sh | sh" — seriously? That tells me a lot about the whole project, unfortunately.
- lo0pback 3mo ago[dead]
- tuvix 3mo agoboth the Julia and Rust programming languages use curl -> sh to install
- tovej 3mo agoBoth of them provide that option. I've never installed rust without a package manager. Why would I?
- qarl2 3mo ago> Why would I? Because then you can install it without depending on a package manager?
- tovej 3mo agoYeah, from source in that case. Or using a verified binary if I absolutely had to.
- qarl2 3mo agoYes, if you want to, you can do that. Understand that 99% are comfortable trusting downloads. They know that it's just as easy to sneak backdoors into source code as it is to sneak backdoors into executables. See also: XZ hack.
- tovej 3mo ago99% of developers are most definitely not comfortable piping a script into the shell. I would never runa script without reviewing it. I would install a package from a distros repository without reviewing the contents, however, because I can trust that a distro maintainer has reviewed it, that anyone else in the community can review it, and that that the bytes I'm downloading are the specific bytes I'm supposed to be downloading. If you run a script off the open internet, you're being massively irresponsible. There are so many attack vectors that could be used here, and they are much easier to implement than something like the massive social engineering attack that was XZ.
- HDBaseT 3mo agoDepending on a package manager has its benefits. I personally try and use my operating systems package manager for all applications (in this instance, dnf on Fedora). The moment you start adding a million repos, third party package managers, Flatpaks, Snaps, random curl install scripts, etc, it becomes extremely unmaintainable. What happens if the curl application depends on openssl, maybe with a legacy or specific cryptographic function? I assume the curl script will either install the required version, or include the relevant libraries right? Now that is outside of the system package managers scope, meaning updating openSSL to avoid some vuln now requires extra work. What happens when you go from Fedora 44 to 45? You should be checking all your applications are supported on whatever version or operating system you are running. There is a decently high chance you run into dependency issues when some lib version is updated. Package Managers are (generally) more secure and simple to use for an end user (they are using the OS to begin with). Curl scrips are easier for the software developers.
- throwaway2027 3mo agoClaude Code does it the same way (which doesn't excuse it obviously) but still. curl -fsSL https://claude.ai/install.sh https://claude.ai/install.sh | bash https://code.claude.com/docs/en/quickstart https://code.claude.com/docs/en/quickstart
- ardacinar 3mo agoYep, that's not an excuse. Claude goes down all the time, should pi also go down? Oh wait (from another comment under this article): > https://pi.dev/models https://pi.dev/models is throwing an internal server error for me.
- mik3y 3mo agoI am genuinely curious what it tells you, as "curl https//.. | sh" has long been an enormously popular approach to distribution in the open source world. Homebrew, to name just one example, advertises a similar method. (pi.sh also documents other install methods, like `npm`, on their homepage) If trust and security is the issue, unfortunately "better" ideas like hashpipe [1] never achieved critical mass [1] https://news.ycombinator.com/item?id=9318286
- tovej 3mo agoWhat about better ideas like installing from source, or using a package manager? Or even flatpaks.
- mik3y 3mo agoThe ideas aren't mutually exclusive, and I've never seen an open source project support "curl | sh" without also supporting those methods. Indeed, plenty of these scripts often act as a "what OS and packager do we have" mux. Just look at the source of this one, for example. When you support an open source project at scale and/or with less savvy users, you come to see the benefit of "here, just f'ing slam this into your shell and we'll figure it out" installers. I know I have.
- ithkuil 3mo agoThere are many ways of implementing a curl | sh installer, some of them robust, some of them not. However they all look the same to the end user. That's a feature and also a potential source of problems since users cannot tell if that particular application they want to install Is implementing the installer correctly or not. The outcome is that most users just trust that application (possibly because it's popular and trusted) and that's fine but it also trains the public that this installation method is ok and that gives a positive feedback for other applications to also offer their software using that installer pattern until at least one of such packages is implemented very badly or sneakily malicious. If only a curl had a flag where you pass the sha256 of the file and it first checks it against the buffered file before outputting it to stdout. That would singlehandedly resolve this whole kerfuffle. The install instructions will be a slightly longer one liner and that's fine because people copy paste it anyway
- Arubis 3mo agoI get this, and would recently have had a similar reaction. But I have to ask: do you typically run your agent harness in yolo mode?
- plagiarist 3mo agoIn general I agree with you, but on the other hand it is an agentic coding agent you should have isolated in a container or VM anyway
- efficax 3mo agoit tells you they're just like basically every other CLI targeting project for the last 15 years? I mean is it a big security hole we all accept, yes, it is. But it's not really indicative of much. That's also how I install rust.
- croes 3mo agoWe also accepted the security risks of npm and such and we get one supply chain attack after another. Maybe security should be at a higher position on our priority list. The careless days are ultimately over but we still don’t act like that.
- horsawlarway 3mo agoYeah, totally reasonable comment given the utter security that must come from anthropic with their installer, amiright? oh wait... "curl -fsSL https://claude.ai/install.sh https://claude.ai/install.sh | bash" (right from https://claude.com/product/claude-code https://claude.com/product/claude-code) Further - what the flicking fuck do you think an installer is going to do on your system? Not run any commands? Because I've written installers for every platform... they ALL can run commands. So what exactly is the complaint in this comment? If you want to go read the install script - knock yourself out (or hell, point your agent at it...).
- kordlessagain 3mo agoAnd you can simply look at the installer by pulling it up in the browser.
- qarl2 3mo agoYou can simply look at the installer by leaving off the "| bash".
- qarl2 3mo agoMy dude - if you're going to trust them then you're going to trust them. You think it's hard to obfuscate shell calls from inside a built executable? What it tells us is that you're probably searching for reasons to grouse about AI.
- sippeangelo 3mo agoSeriously, what is the threat model here?
- arbll 3mo agoNah bro package manager where you copy and paste their custom repo and key from the same website that hosts the `.sh` is definitely safer, trust me /s
- InsideOutSanta 3mo agoThere is no threat model that doesn't also apply to pretty much every other distribution method. It's just people who have internalized "don't paste commands from the Internet into your terminal" and aren't thinking about exactly what makes pasting commands from the Internet into your terminal dangerous, and how that applies to this specific case.
- Ferret7446 3mo agoCompromised web server, since they don't tend be as secure. Signed packages are safer as signing keys are generally more secured than web servers.
- kordlessagain 3mo agoI just did a build in Nemesis8 (containerized agents) and Pi appears to be working fine. Opencode is a good choice too if you're interested in checking out GLM 5.2 from z.ai. https://github.com/deepbluedynamics/nemesis8 https://github.com/deepbluedynamics/nemesis8
- MrOxiMoron 3mo agoExcept I was having connection issue and errors through open router too
- cromka 3mo agoIs pi better than opencode?
- kordlessagain 3mo agoI like it. One caveat is that it doesn't do MCP tools, but can wire them up with bash (or use CLIs if those are available).
- zipy124 3mo agoThey are different models. OpenCode is trying to be a claude code/codex replacement, where-as pi is something you build yourself, kind of trying to be an emacs type thing compared to vs-code. As in emacs it is more common to write your own extensions, where as in vs-code most people just download them.
- agentdev001 3mo agoI keep butting into the question of; why opencode, when you've got codex available? Codex is open source as well, and i can't seem to picture a situation where one would want Opencode over Codex. As far as I can tell, they tick the same boxes- but one has the support of a big boy model provider.
- Carrok 3mo agoIf you care about privacy at all, you can route your Opencode requests through an inference provider that does not retain any logs or data. It is also much cheaper. So if your boxes include `Privacy` and `Affordability`, then no, they don't tick the same boxes.
- cromka 3mo agoI think they meant using Codex with non-openai providers?
- agentdev001 3mo agoYou can use the Codex harness with non-openai providers if you want.
- sergiotapia 3mo agoI can vouch for ohmypi, it's quite good out of the box and works great with your codex subscription or openrouter or fireworks etc. Very good harness. https://omp.sh/ https://omp.sh/
- bflesch 3mo agowebsite is super laggy and has low FPS
- agentcooper 3mo agoWith Agent Client Protocol (ACP) you can keep the same UI and switch not models, but entire agents, that means using tools/prompts/compaction/etc that are tailored for the model. Try Zed[1] for GUI and pool[2] for TUI. [1] https://zed.dev/ https://zed.dev/ [2] https://github.com/poolsideai/pool https://github.com/poolsideai/pool
- CBLT 3mo agoLinked your own project with an "All rights reserved" license? The only thing my company will allow me to do with that software is have AI steal it </s>
- agentcooper 3mo agoWe don't have any client-side telemetry. Conversations with Poolside models are stored, but you can use any ACP agent with pool. And we have plans to open-source it eventually.
- Ferret7446 3mo agoI tried ACP but the UI for agents is so minimal I don't see much of a point. They're all just text boxes now.
- deleted 3mo ago[deleted]
- thejazzman 3mo agoI retried Pi yesterday with GLM5.2 and Deepseek I asked a simple question about my codebase. Pi: >60s and 100k tokens, I cancelled and gave up Claude (pointed at the same deepseek model): 17s 15k tokens I burned my $5 GLM budget in 15 minutes. So idk what the Pi hype is about cuz this is my 3rd disappointing try
- bel8 3mo agoGLM 5.2 is priced at 1/3 of Opus. Depending on who you ask for a napkin math. Not worth it in my opinion. You'll get 10x more value by using MiMo 2.5 or DeepSeek Flash which is what I use for most code.