Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I posted the original release to /r/StableDiffusion but all the comments are "why not compatable with A1111?" and I can't find a good script to do the conversion: https://www.reddit.com/r/StableDiffusion/comments/15r5k3i/i_...

Civitai has syndicated the LoRA: https://civitai.com/models/128708/sdxl-wrong-lora



You will get more users if you provide a safetensors file instead of bin and pickletensors a lot of people have gotten really scared by the malware scare that was going through social media a few months ago.


Thank you for note on this. I had not heard there were already trojan horse malware being slipped into tensor files as python scripts. Apparently torch pickle uses eval on the tensor file with no filter.

Heard surprisingly little commentary on this topic. The full explanation of how Safetensors are "Safe" can be found from the developer at: https://github.com/huggingface/safetensors/discussions/111



And for a good reason. A big hunk of floating-point numbers really shouldn't be able to execute arbitrary code. Or any code at all.


I would also ask that sha hashes are posted somewhere. It annoys me to know end how difficult it can be to confirm you are using the real model.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: