logoalt Hacker News

throwaway2027today at 8:49 AM1 replyview on HN

All of which is useless when it just starts using big blocks of python instead. You need filesystem sandboxing for the python interpreter too.


Replies

ethanwillistoday at 8:58 AM

What we need is a capabilities based security system. It could write all the python, asm, whatever it wants and it wouldn't matter at all if it was never given a reference to use something it shouldn't.

show 3 replies