logoalt Hacker News

3eb7988a1663 • today at 4:23 PM • 3 replies • view on HN

Can I use this as a generic app permissions boundary or do I have to somehow fake it as an "agent"? We are well past the point where I need to be able to lock down that my music player has no ability to read my SSH keys or whatever.

Naturally, this will be gated to corporate customers - the plebs do not get access to better security unless they pay for a top tier license.


Replies

tomrod • today at 5:43 PM

FANTASTIC question here. I've been locking down agents by running them as untrusted users (mostly linux here) as even docker boundaries aren't really great. Firecracker is a step in the right direction (older tech, sure, but useful). I really want a local hashicorp-like vault that I can give agents specific access permissions and it can take forever to review and manage those access boundaries.

doctorpangloss • today at 6:57 PM

I guess buy a Mac then.

tuwtuwtuwtuw • today at 5:36 PM

There are many things that would be good to lock down. NPM install comes to mind.

I wonder if I will be able to integrate this with dev containers somehow, so my dev container could run in stricter isolation.

➕ show 1 reply