Hacker News
new
past
comments
ask
show
jobs
points
by
myaccountonhn
5 hours ago
|
comments
by
__MatrixMan__
5 hours ago
|
next
[-]
This is the only kind of agent security that makes sense to me. Constrain it like you would any other subprocess. Unprivileged OS users, SELinux, firewalls, VMs... Unikernels? eBPF?
reply
by
dist-epoch
4 hours ago
|
parent
|
[-]
Escalations to root are a dime the bucket.
reply
by
drdec
2 hours ago
|
parent
|
[-]
That argument is letting the perfect be the enemy of the good.
There is no perfect security.
reply
by
mlperson
4 hours ago
|
prev
|
[-]
Me too.
reply