frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Turn off Apple Intelligence on macOS 27 and get its disk space back

https://github.com/omlahore/RemoveMacAI
121•privacyisntdead•1h ago

Comments

arialdomartini•1h ago
Stop the curl | bash insanity.

https://nocurlbash.com/#en

demibabs•59m ago
Good message but AI generated text is so grating to read.
shujito•59m ago
there's a homebrew alternative
stock_toaster•10m ago
Which installs via a random 3rd party tap, which honestly isn't much better than yolo curl|bash.
1over137•53m ago
“You wouldn't run a stranger's code without reading it.” Yes I would. We all do it all the time. macOS itself is closed source, and even if it weren't, there’s way too much code to read.
jtrueb•49m ago
Lol, thinking the exact same thing. No, we don’t read next to 0.0001% of the code we run.
jacquesm•26m ago
Code from trusted repositories is an entirely different thing compared to running 'wget some_github_repo_shell_script | sh' . That said, the likes of Tailscale are setting a bad example.
nvme0n1p1•5m ago
The script, and the code the script downloads, both come from the same repo and were written by the same developer.

If you've already decided you trust the author, what's the actual threat here?

jacquesm•2m ago
I would not trust the author just like that.

But then again, I'm a bit paranoid. At a minimum I would download the script and read it, and if it was too long or not written clearly enough then I would just drop it and find something better.

tmpz22•45m ago
Don’t be obtuse, the intended audience is developers with enterprise credentials sprinkled throughout their environment.

Its a different threat model. You should not curl bash.

benterix•14m ago
Developers with enterprise credentials sprinkled throughout their environment running anything from the Internet deserve what they get.

But I assumed the intended audience are home users with entry level macbooks/minis with 128 GB RAM where this patch actually helps them.

aaomidi•41m ago
This isn’t really that much of an issue when we have tls tbh.

Like I get why it’s bad, but also homebrew package installation is a more organized version of this.

Hashes are cool but also in a lot of systems you’re trusting the hash to be provided by the same website you don’t trust the binaries from…

packeted•40m ago
Great initiative. I recently got stung by an advert on reddit for "HBO Max for MacOS, 6 months free" from the official HBO user (don't get me started on how that slipped through). Front and center was a curl | bash copy to clipboard that obfuscated the payload source in base10. I knew better, but I think we've made this kind of thing way too acceptable. Of course it was malware and I realized the instant I pressed enter. Thankfully I didn't give it my password and immediately disconnected from the internet and killed the machine. I'm genuinely concerned these kind of attacks are going to become much more commonplace with AI, plus the ability to inject malicious code in to things that get run by trusted scripted installers.
swozey•37m ago
They all dump env and ship it off so check for any keys you might have had in there if anything was able to send at all.
andelink•22m ago
You curled and executed bash code allegedly from _HBO_?
hypeatei•39m ago
> If the project publishes a SHA-256 hash, use it. Non-negotiable on production machines.

They're pushing FUD around downloading a file but then suggest that we trust the same chain of complex things to display the right hash value? Integrity != authentication.

mogwire•39m ago
I bet this is the guy on the call who has to correct someone who calls them SSL certs.

Excuse me, they are TLS certs.

Thanks Arialdomartini, as I was saying… we need to renew the SSL Certs

maccard•38m ago
What’s your suggested installation method instead? Unless it’s “download and read the source before running it” this is no worse than npm install, or pip install, or clicking “trust” on a git repo in VSCode
mingus88•28m ago
It is actually worse than those examples. Pip and npm may be insecure, and that is a fault of those tools, but most user expect secure package managers and should demand it

Telling users it’s fine to raw dog arbitrary commands directly into their shell is dangerous and lowers the bar for all security. In fact by even making this comparison you are communicating that you are complacent with pip and npm’s issues and why shouldn’t you just execute arbitrary commands without even a second glance? Security doesn’t matter!

And for the record, even with pip and npm being the way that they are, they are still better than a curl pipe because they are versioned. In the case I get a compromised deployment I understand immediately if I got hit by the affected package, and the entire repo can then be audited. Not the case when I’m just curling whatever the internet wants to send into my process space

zakki•18m ago
Fed the source to LLM for analysis?
stock_toaster•12m ago
Why is this even an app? It looks like it just generates a mobileconfig profile on the fly. Instead, seems like they could be offering a download of a pre-generated mobileconfig, which seems like it would be much safer than installing some app via curl|bash .... but then I guess there wouldn't be a chance to have an "app", get github stars, and do whatever else.
porridgeraisin•27m ago
> Bash starts before the download finishes ... Drop the connection mid-transfer and you get partial execution: a command like rm -r /usr/share/program can truncate to rm -r /usr. Commands ran, cleanup didn’t.

curl | bash scripts all define a function and then call it on the last line. This is a non issue in the real world.

> The server knows you’re piping — and can lie

This `sleep` based trick is always a cool demo to show freinds yes, but the server can also sneak in malware in a multitude of other ways given you're downloading code and binaries from them.

> You trust DNS, TLS, the CDN, and the origin simultaneously. A compromised CDN or BGP hijack delivers malware silently.

Well yes, that's how the internet works. If TLS of the server is really compromised, then the attacker will replace the checksum as well as the signing key. In real scenarios, you are going to be reading the signing key and checksum from the same domain. [1]

> You can’t reproduce what ran

`| tee inspect.sh | bash`

> Add sudo and it’s game over

Most credentials and important files live in the home directory, root is a red herring. If you're running it on shared server, then well... don't add sudo.

[1] Yes of course there are legitimate usecases for signing software. Common example: linux distros which are mirrored at many domains, but the checksum and signature are hosted on the canonical domain. But if I am curlbashing uv's install.sh from `astral.sh`, then doing signature verification using the public key hosted on the same astral.sh isn't adding much.

hnfong•10m ago
> curl | bash scripts all define a function and then call it on the last line. This is a non issue in the real world.

Please take a look at this before making any assertions... https://github.com/omlahore/RemoveMacAI/blob/main/install.sh

Terr_•9m ago
I think that's missing the forest for trees. The problem with these curl-to-bash approaches isn't that you literally can't intercept and inspect them given effort and planning.

The problem is that there's no verified "standard" artifact, which means my copy being checked safe doesn't say anything about whether your copy is safe too.

In contrast, release_1.2.3.zip is expected to be identical in size/hash/bytes for all people, and if it isn't then that sets off alarm bells.

> curl | bash scripts all define a function and then call it on the last line. This is a non issue in the real world.

Why would a convention often followed by good/careful actors bind what malicious/careless people create?

bigyabai•1h ago
Something horrible must have happened, if macOS users are curling shell scripts from the internet to make their desktops more like Linux.
nomel•48m ago
Nope. The only people who notice or care about any of this are those who can't accommodate the storage. Outside that, it all just works better now (especially Siri).
behnamoh•46m ago
Saying that Siri "works" is peak Apple fanboism.
trollbridge•36m ago
People with 256GB laptops care when the 27 AI stuff burns up 10-20% of their storage.
GeekyBear•32m ago
So don't install Chrome.
trollbridge•22m ago
Most people want Chrome for the inevitable site that doesn’t work in Safari.

The problem is Apple intelligence is decent, but not worth 20% of your storage decent.

swozey•41m ago
behnamoh•57m ago
Oh, things are about to get worse with the new macOS "privacy/security" measures. They are going to curb agentic workflows even more. I don't know how Apple just finds new ways to annoy developers, but we're in a minority after all. Of 200 million Mac users, probably just up to 1 million are developers, and the rest are normies who can't tell when they should authorize or cancel the pop-up.
doawoo•53m ago
I'd argue that a lot of developers can't determine if an LLM generated command is actually safe or not.
wartywhoa23•52m ago
Ah, if only that meant that there'll be less slop in the macOS code itself..
NamlchakKhandro•47m ago
Apple hates developers
pjmlp•34m ago
They love the ones that buy Apple hardware to develop apps for iDevices, pay the dev subscription and store fees for apps, or simply because they wanted a shiny UNIX and don't consider BSD/Linux OEMs worth their money.
ultrarunner•28m ago
With LLMs, everyone's a developer now. Welcome to the mainstream.
hypfer•38m ago
This is stuff on the level of O&O ShutUp10. Which is a good tool, but also, a Windows tool for very (back in the day) Windows-specific nonsense.

What's going on at Apple product strategy?

userbinator•23m ago
It's interesting to see more customisation tools appearing for macOS, as just a few years ago I was looking for ways to strip down the OS (CI related), and while such info was widely available in the Windows world, to the point that customised "distros" are available, it was nearly nonexistent for macOS; only the Hackintosh community had some useful articles on how things worked.

Could the rise of LLMs and vibe-coding have motivated people who otherwise wouldn't bother?

gumby•13m ago
It’s hard to strip it down these days as the OS image and its core, immutable filesystem cannot be edited. Admittedly this helps keep idiots from destroying their filesystem and also blocks many malware attacks on the system, but, for example. I don’t believe you can delete the chess program.
the_arun•16m ago
How do we believe this tool? Is it secure?
pyaamb•15m ago
Is there a way to do this manually?
nailer•6m ago
> Every release is built from its tag by GitHub Actions and carries a build provenance attestation.

Huh cool. They're doing curl | bash properly.

neuroelectron•6m ago
Not a lot of good reasons to upgrade to 27. They removed Rosetta and you have to reinstall that if you want it. So is MacOS turning into something that more regular people are going to have to maintain in the future or end up with something like Windows 11?

I switched to MacOS 3 years ago because of Microsoft and the writing on the wall seems to say I got another year left before I'm forced into Linux. Because if I have to maintain my own OS then I might as well install Linux and do it once.

halJordan•3m ago
If a temporary tool being retired is the reason you switch, then wait until you find out how many LOC are being deleted from the linux kernel this year and next
pietz•4m ago
This should have been a prompt.
I'm sick of juggling disk space on my 1tb laptop AND I don't want an llm attack vector anywhere near my machine, this things getting nuked from orbit or i'm not updating to golden gate, ever.
trollbridge•36m ago
curl|bash is now standard way to install packages on both macOS and Linux. It’s maddening, but it is now.
pjmlp•33m ago
Meanwhile on Windows we mostly use the store or winget, funny times.
trollbridge•23m ago
Yeah. I think of Windows as basically “homebrew comes preinstalled”.
drnick1•34m ago
Uncomfortable, but true.

GNOME has reached maturity and hasn't changed significantly in years, while Apple is busy destroying macOS.

dijit•22m ago
Really? GNOME is not what I would recommend to people.

I should applaud their efforts, and I get that much of it is voluntary, but their bugs are numerous, notable and the way they interact with the rest of the universe (both people with accessibility needs, and the wider developer ecosystem on linux) can most accurately be described as arrogant and hostile.

KDE is the bastion of maturity here, and I would agree that it is mature.

I’m not sure how the love for GNOME continues when KDE (while not my personal choice) has clearly been running circles around it since GNOME3 and the gap has only widened since that change too.

bigyabai•3m ago
Both desktops are pretty mature. I've run both of their Wayland stacks, and Mutter/KWin both perform great these days. It really comes down to personal preference for most use-cases.
fmajid•26m ago
It’s not about privacy, it’s about kneecapping competitors, just like when they blocked the advertising ID but exempted themselves from this because “Apple is not a third-party, we’re a second-party”.

Apple is an advertising company and thus inherently untrustworthy.

Run Qwen 3.8 Flash Next (125B) on consumer hardware (RTX 4090) at 100T/s

https://github.com/Niko1221/Strata
483•snehesht•8h ago•249 comments

Turn off Apple Intelligence on macOS 27 and get its disk space back

https://github.com/omlahore/RemoveMacAI
121•privacyisntdead•1h ago•54 comments

A map of every lighthouse

https://mapped.earth/lighthouses/world
130•karakoram•2d ago•62 comments

Improper redaction reveals Google Data Center water and electricity usage

https://www.1011now.com/2026/09/30/more-questions-than-answers-about-lincolns-google-data-center-...
91•sensanaty•1h ago•95 comments

'Neanderthals Among Us' review

https://www.historytoday.com/archive/review/neanderthals-among-us-peter-sahlins-review
40•pepys•1d ago•30 comments

Homa: The end of TCP for AI clusters [video]

https://www.youtube.com/watch?v=eZ8WWZzoaR0
16•signa11•1h ago•2 comments

Results from the ASIC puzzle

https://blog.janestreet.com/asic-puzzle-results/
53•eru•2d ago•17 comments

I asked Claude build a physically accurate O'Neill cylinder you can walk around

https://island-three.gruberbuilds.workers.dev/
14•bilsbie•1h ago•11 comments

Show HN: Build with Python – a beginner course where your code draws

https://scimigo.com/en/learn/build-with-python/01-draw-with-python
10•davidwshao•2h ago•2 comments

Show HN: Glashütte Trash Clock – A 30-minute pendulum clock made from trash

https://niklasroy.com/gtc/
143•r0r0•2d ago•18 comments

A man who listens to whales

https://blue-continuum.com/the-man-who-listens-to-whales
7•dnetesn•2d ago•0 comments

Tell HN: Bob Cringely has died

767•paveworld•20h ago•162 comments

Declaring a bird extinct: The median wait is 36 years after the last sighting

https://birdshistory.com/how-long-to-declare-a-bird-extinct/
10•Heidi_70•22h ago•4 comments

Show HN: AI search for every photo and every frame of video on macOS

https://github.com/allenv0/SCM
122•allenleee•11h ago•59 comments

The evolution of effective altruism

https://www.economist.com/international/2026/10/01/how-effective-altruism-conquered-the-world
39•bazzmt•7h ago•45 comments

Page Table Memory Consumption

https://frn.sh/pagetables/
14•shellpipe•3d ago•0 comments

A Minsky machine in ncurses terminfo

https://seriot.ch/computation/terminfo/
27•beefburger•2d ago•8 comments

Incentives in Academic Research

https://www.msoos.org/2026/10/incentives-in-academic-research/
12•zero_k•3h ago•4 comments

How to scale intent, quality, and artistry with AI [video]

https://www.youtube.com/watch?v=GLvFTMtw4Jk
21•simonjgreen•12h ago•8 comments

Why don't more developers “use the platform”?

https://nolanlawson.com/2026/10/03/why-dont-more-developers-use-the-platform/
261•vinhnx•17h ago•268 comments

Automating my 35mm film scanning pipeline

https://shannadige.com/blog/darkroom/
44•shannadige•1d ago•32 comments

Bill Draper has died

https://www.nytimes.com/2026/09/30/technology/william-draper-dead.html
39•bookofjoe•8h ago•12 comments

The work by Valve's Timur Kristóf on improving old AMD GPUs on Linux

https://www.phoronix.com/news/XDC-2026-Valve-Timur-AMDGPU
443•speckx•1d ago•86 comments

What is going on with ceiling fans

https://mcmansionhell.com/post/829127919552151552/what-is-going-on-with-ceiling-fans
144•colinprince•3d ago•119 comments

Fog-Bank: Archiving the oldest webcam feed

https://fog-bank.org/net
9•rdmuser•16h ago•1 comments

cp: -r or -R?

https://movq.de/blog/postings/2026-09-30/0/POSTING-en.html
67•zdw•4d ago•82 comments

Agents don't need memory, they need documentation

https://liao.gg/blog/agents-dont-need-memory
326•kmeh•1d ago•201 comments

Surely you have ultra-wideband radios on your bins too?

https://sjg.io/writing/binrange-have-you-actually-put-the-bins-out/
121•simonjgreen•1d ago•66 comments

Emitting metadata early makes building/checking Rust up to twice as fast

https://github.com/PowderworksCode/headstart
111•knuckleheads•14h ago•30 comments

Xray-core concealed a certificate verification bypass vulnerability

https://github.com/net4people/bbs/issues/672
12•timbill•3h ago•0 comments