‹ BackHN Continuity

Thread

Show HN: Drop – A rootless Linux sandbox with gVisor support

193 points · 63 comments · mixedbit

  1. gregwebs · · focus · HN ↗
    Glad to see this coming with gVisor support to help secure the Kernel- IMHO we should expect frontier models to find Kernel exploits.

    I am working on a project similar in spirit that uses microsandbox (libkrun) to run inside a tiny and fast VM. It includes other security properties that are needed for some workloads.

      * network allow lists
      * credential masking
      * github allow list
    
    <a href="https:&#x2F;&#x2F;github.com&#x2F;gregwebs&#x2F;agent-vm&#x2F;#agent-vm" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;gregwebs&#x2F;agent-vm&#x2F;#agent-vm
    1. NewJazz · · focus · HN ↗
      Couldn&#x27;t you use fine grained github tokens for some of what you&#x27;re accomplishing with the github&#x2F;network filtering?
      1. asb · · focus · HN ↗
        The fine-grained tokens have some surprising permissions for &quot;read only&quot; <a href="https:&#x2F;&#x2F;github.com&#x2F;orgs&#x2F;community&#x2F;discussions&#x2F;180063" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;orgs&#x2F;community&#x2F;discussions&#x2F;180063
      2. gregwebs · · focus · HN ↗
        You definitely want to do that. I have a Github App that I use for my AI agents, and that has its own associated restricted credential.

        There are going to be cases where you want to white list an org or a repo for read access that is not under your control and Github filtering will be a simple way to do that.

        Github can be a source of hostile code, prompt injections, and exfiltration- you may want to lock down using repos that aren&#x27;t yours.

        The tool inherited this feature from the prior implementation and its something I am still exploring.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.