logoalt Hacker News

sebastienburel • yesterday at 5:32 AM • 1 reply • view on HN

The channel is always whatever primitive was left in the sandbox, not the one you thought you were guarding. Block fetch and the model finds the resolver. Block the resolver and something else is still leaking bits.

In my runtime the agent has no fetch, no fs, no require, only a host.* surface. The HTTP tool refuses any host not on its allow-list, so a disallowed name never gets looked up. But the shell tool is opt-in, and the moment you turn it on you have handed over dig, and the HTTP allow-list no longer matters. The only version that holds is the one where the capability isn't there.


Replies

alignmeharder • today at 6:25 AM

it's quite possible these models memorized some stable IP's for some services

not having DNS might not stop them