logoalt Hacker News

oblio • today at 2:00 PM • 2 replies • view on HN

Why? We probably need more sandboxing, not less.

Especially with LLMs automating all sorts of code and operational aspects, we could do Tcl/Lua type whitelist sandboxes where the application can only call a limited set of functions.


Replies

Pesthuf • today at 2:07 PM

I think it makes more sense to use the kernel‘s’s sandboxing utilities (like seccomp, SELinux, namespaces, prctl and eBPF) than to rely on the process to try to isolate itself purely in userspace which will always have holes.

hollowturtle • today at 2:05 PM

I warn you to not try to argue with ai shilling people

➕ show 1 reply