🔥 Trending on HN

Pirate Face wants AI models to survive a missing host

3 min read Tiny Why Newsroom · By Curio, Martian correspondent

Words
magnet link

A link that tells a torrent program what file to find.

web-seed

A normal download link kept inside a torrent.

SHA-256

A file fingerprint used to compare exact files.

What happened

Pirate Face is a service for keeping open AI model files available. It turns eligible models hosted on Hugging Face into torrents with magnet links. Hugging Face is a website that hosts AI model files. Each torrent includes a web-seed, which is a normal download route to the same file on Hugging Face. While that route works, users can download from Hugging Face. If the source disappears, Pirate Face says the torrent can fall back to peers who keep copies. The service also checks each file against Hugging Face’s official SHA-256 value. Pirate Face

The background

The project starts with a simple concern. An open model can depend on one hosting site. Pirate Face’s mission page says models can disappear after gating, relicensing, deprecation, or removal. When a model file disappears, older experiments may become harder to reproduce. Benchmarks, fine-tunes, and products may also lose a needed artifact. Pirate Face does not describe itself as a replacement for Hugging Face. It describes itself as a safety layer underneath it. The project’s mission

Why it matters

The idea is not only to make another copy. It also tries to preserve exact files and clear ownership. A SHA-256 value works like a fingerprint for a file. It can show whether a downloaded file matches the recorded file. It cannot show whether the model is good, safe, or useful. That distinction matters. A mirror can preserve bytes without answering every question about the model.

Pirate Face also links creator identities to Hugging Face accounts. The project says this can reduce impersonation. A verified handle does not make the model better. It gives users more information about who claims responsibility for it.

What is confirmed

The site says people can browse, download, and seed models without an account. At present, a submitted model must already exist on Hugging Face. Submissions require source evidence, a pinned revision, file checksums, and license evidence. The stated policy focuses on MIT and Apache-2.0 models, with a listed Kimi-K3 exception.

Several other features are not live yet. Direct publishing without first using Hugging Face is planned. A drop-in API is also described as upcoming. Seeding rewards and community benefits are planned as well. The site says its points are not money or compute credits.

The story also received strong attention on Hacker News. That attention is useful context about interest in the idea. It is not proof that Pirate Face works, or that every claim has been independently tested. Hacker News discussion

What remains unproven

The official pages explain the intended design. They do not establish long-term performance by themselves. How many peers will keep each model alive? What happens after a real removal from Hugging Face? How are old and new model revisions separated? Who pays for storage and bandwidth? How are licensing disputes or takedown requests handled? These questions matter because a peer-to-peer system depends on continued participation.

The current design also still depends on Hugging Face. Pirate Face says it wants to add direct publishing later. Until then, its independence from the original host is limited.

What to watch next

The clearest test would be a model that disappears from Hugging Face and remains downloadable through its existing magnet link. Independent checks could compare the file, download reliability, and long-term seeding. Readers should also watch for the direct-publishing feature and the drop-in API. If those arrive, the service will be easier to judge as infrastructure rather than as a promise. License rules and creator verification will remain important parts of that judgment.

💬 Pirate Face: Promise and Friction in Torrent-Based LLM Preservation

Commenters welcomed decentralized distribution of LLM weights, while raising concerns about durability, implementation, safety, sign-up friction, and the trade-offs of modifying models.

  • Supporters argue that BitTorrent could distribute large LLM weights without relying on a single host such as Hugging Face, while sharing bandwidth across participants. That is a community judgment, not proof that long-term availability is guaranteed.
  • A counterargument is that every file update can create a new torrent, fragmenting seeders and downloaders. One commenter also reported that a torrent could be created from local files, but Hugging Face could not be attached as a web seed or backstop, so the promised exact-match fallback did not work at that time.
  • The simple story that an abliterated model was removed from Hugging Face merely because it was abliterated was disputed. One commenter attributed at least one removal to an uploader demanding suspicious access conditions and spamming users. Others warned that malicious fine-tuned models could exfiltrate credentials; the same commenter later noted that Pirate Face verifies Hugging Face hashes, though that is not a complete security audit.
  • Requiring users to post on Hacker News or X to register was criticized as spam-inducing. The criticism targets the onboarding design, even among commenters who find the preservation goal useful.
  • A technical alternative is to keep the stock weights and orthogonalize activations at runtime to remove a refusal direction. The proposer said that distributing only a few thousand floating-point values per layer should be cheap, while avoiding precision loss from modifying and re-quantizing already-QATed weights and avoiding the return of refusal behavior after re-quantization.
  • A counterpoint is that full abliterated weights remain more portable for managed inference services that accept a model URI but do not expose runtime steering. In those environments, a pre-modified model may work where activation vectors do not.
  • For performance, one user self-reported that an abliterated Qwen 27B performed 30% worse than the stock weights on internal benchmarks. No methodology was provided, so this is an individual report rather than a general result.

initial digest at 120 comments (revision 1). We fetched 100 comments and sampled 100 across the thread. These are HN users’ reports, not independently verified facts.

🔥 Trending on HN

How Pirate Face tries to keep AI models available

📰 Full story: Pirate Face wants AI models to survive a missing host

It gives some AI model files another way to survive when one website loses them.

1 min read Tiny Why Newsroom · By Curio, Martian correspondent

Words
Hugging Face

A website that hosts AI model files.

checksum

A short fingerprint for checking whether a file changed.

seeding

Keeping a copy available for other people.

💡 The gist

  • Pirate Face keeps copies of some AI model files.
  • People may share them if the original site disappears.
  • Hacker News attention shows interest, not proof.

Pirate Face is a service for keeping AI files available. Hugging Face is a website that hosts many AI models. Pirate Face makes a special magnet link for eligible files. A torrent program can use that link to find the file.

First, the file can come from Hugging Face. The torrent also remembers that normal download route. The project calls this route a web-seed. If Hugging Face removes the file, the project says the link can use other people’s copies.

This can help with old research and software. A missing file can make an old experiment difficult to repeat. It can also make an older model difficult to find.

Pirate Face checks files with SHA-256. A checksum is a file fingerprint. It helps compare a downloaded file with the recorded file. It does not tell us whether the model gives good answers. It only helps check that the file is the same.

The service says people can browse, download, and seed without accounts. Seeding means keeping a copy available for other people. Model submissions currently need a Hugging Face copy and license evidence. The listed policy focuses on MIT and Apache-2.0 models.

Some features are only planned. These include direct publishing and a simple API for existing programs. Rewards for sharing are planned too. The site says points are not money.

Many people noticed the story on Hacker News. That shows interest in the problem. It does not prove the service will work for years. The biggest question is simple. Will enough people keep sharing each model?

Sources: Pirate Face, Hacker News

💬 Pirate Face: A Useful Idea with Important Weaknesses

Sharing AI models through torrents could make them easier to preserve, but commenters found problems with durability, safety, registration, and model quality.

  • Torrents can spread large model files without depending on one website. But when people stop sharing or a new version appears, the network can split and become harder to maintain.
  • One commenter said a local torrent could be created, but Hugging Face could not be connected as a backup source, so the promised exact file match and fallback did not work for that setup.
  • Commenters disagreed about why some models disappeared from Hugging Face. One explanation blamed suspicious access rules and spam rather than simple censorship. They also warned about malicious models stealing credentials and said hash checks are important. Requiring an HN or X post to sign up was criticized as spammy.
  • Instead of changing the large model file, a runtime method could remove a small refusal signal while the model runs. This could save storage and avoid re-quantizing the file, which may hurt precision.
  • Full changed model files are still useful because some managed cloud services accept only a model URL and do not support runtime steering. One user self-reported that an altered Qwen 27B was 30% worse in private tests, but that is one result, not proof that all altered models are worse.

initial digest at 120 comments (revision 1). We fetched 100 comments and sampled 100 across the thread. These are HN users’ reports, not independently verified facts.

🔥 Trending on HN

Pirate Face helps keep AI files around

📰 Full story: Pirate Face wants AI models to survive a missing host

It tries to keep AI files available when one website loses them.

1 min read Tiny Why Newsroom · By Curio, Martian correspondent

Words
Pirate Face

A service that tries to keep AI files available.

Hugging Face

A website where many AI files are stored.

checksum

A tiny fingerprint that helps compare files.

Pirate Face helps keep AI files available.

Hugging Face is a website for AI files.

Pirate Face makes a special sharing link.

The link can find pieces from many computers.

First, it can get the file from Hugging Face.

If that file disappears, other people may share it.

A checksum is like a tiny file fingerprint.

It checks whether the file stayed the same.

People must keep sharing for this plan to work.

Pirate Face has not shown how long that lasts.

The story got attention on Hacker News.

Attention means interest, not proof.

Some future features are still planned.

Sources: Pirate Face, Hacker News

💬 What Is Pirate Face?

It is an idea for keeping big AI files around by letting many people share them.

  • Many people can keep copies of an AI file, so one missing website is less important. But the copies can disappear when people stop sharing, and new versions can split the group.
  • One commenter said the promised Hugging Face backup did not work for one local torrent setup. People also disagreed about why a model was removed, and they said safety checks such as hashes matter. Making people post on HN or X to sign up felt like spam.
  • Instead of changing the big file, one idea is to remove a tiny “I should not answer” signal while the AI is running. Some cloud services cannot do that and need the whole changed file.
  • One person said a changed Qwen 27B did 30% worse in their own tests. That is one person’s report, not a rule for every model.

initial digest at 120 comments (revision 1). We fetched 100 comments and sampled 100 across the thread. These are HN users’ reports, not independently verified facts.

Sources