logoalt Hacker News

ashishbtoday at 5:36 PM2 repliesview on HN

I always run such tools inside sandboxes to limit the blast radius.


Replies

PunchyHamstertoday at 6:14 PM

The sandbox will need internet access (to update data) and you will need to send code to test into it; so compromise already equals leaking all your code, without even breaking the sandboxing

show 2 replies
wswintoday at 5:50 PM

I don't think it would help here, they were stealing credentials

show 2 replies