logoalt Hacker News

__MatrixMan__today at 6:09 AM1 replyview on HN

This is the only kind of agent security that makes sense to me. Constrain it like you would any other subprocess. Unprivileged OS users, SELinux, firewalls, VMs... Unikernels? eBPF?


Replies

dist-epochtoday at 6:55 AM

Escalations to root are a dime the bucket.

show 1 reply