logoalt Hacker News

clawsyndicateyesterday at 9:15 PM3 repliesview on HN

legit issue for local installs but this is why we run the hosted platform in gVisor. even with the exploit you're trapped in a sandbox with no access to the host node. we treat every container as hostile by default.


Replies

hughwyesterday at 9:59 PM

You sound like the confident techie character in a Michael Crichton novel pronouncing "We've thought of everything there's no way for the demon to escape" shortly before the demon escapes.

show 1 reply
chrisjjyesterday at 9:46 PM

So... what use is an agent that cannot reach out of its trap?

electroglyphyesterday at 9:21 PM

that response is not comforting