logoalt Hacker News

Topfi • today at 6:37 PM • 2 replies • view on HN

> [...] keep it safe by sandboxing the agents.

No, they were not. Not a single person, prior to July 2026, would consider a shared packaged manager a sandbox in this or any other dimension. The 0-day was just incidental, this wasn't a sandbox at all.

Add to that the fact they had multiple message boards before the Hugging Face incident. They simply ignored a barrage of warning shots.

> [...] and ended up killing some kids, because it turned out the door didn't lock properly and kids were able to sneak in. Is that "negligence"?

Yes, it can be. But if you want a ridiculous comparison, then do it properly: Kids have been known by the operator to sneak in successfully multiple times and they changed nothing about the doors faulty locks and oh, by the way, the operator only found out about the kids being shot after the nearby daycare asked them about it because they are so incompetent and/or irresponsible that they never check...


Replies

akerl_ • today at 6:40 PM

Hosting an artifactory instance to mirror packages for internal systems is exactly the kind of thing that would be part of normal efforts to sandbox them from the internet and other systems.

➕ show 1 reply
gruez • today at 6:43 PM

>Not a single person, prior to July 2026, would consider a shared packaged manager a sandbox in this or any other dimension. The 0-day was just incidental, this wasn't a sandbox at all.

???

The package manager was specifically there so agents can install random packages without open access to the internet.

➕ show 1 reply