‹ BackHN Continuity

Thread

Is sandboxing sufficient to contain rogue agents?

52 points · 99 comments · zdw

  1. rvz · · focus · HN ↗
    Counting down to the next Linux LPE 0day or KVM vulnerability that agents will use to trivially escape their "sandbox".

    Might need a re-think about whether if Linux is still fit for purpose on sandboxing in the first place given its memory model is riddled with C-style security issues.

    1. lukehandcool · · focus · HN ↗
      Are you suggesting proprietary software is safer than open source?
      1. jasomill · · focus · HN ↗
        Not sure what licensing has to do with software engineering or system design.

        I’m sure there are proprietary systems with fewer memory safety vulnerabilities than Linux (and many others with more).

        1. bzzzt · · focus · HN ↗
          It's got nothing to do with the licensing, but it used to be 'with enough eyes all bugs are shallow' for code developed in the open.

          Now, open code allows anyone with tokens to burn to analyze it for hidden weaknesses. That makes publishing code a risky move unless you've already invested a lot of effort in securing it.

          1. ben_w · · focus · HN ↗
            Agents seem to be* getting better at decompiling; if that appearance is true, binaries are vulnerable in a similar way to source code.

            * I don't know how useful any of the specific benchmarks on this are, so I'm only saying "seem to be"

            1. angry_octet · · focus · HN ↗
              Agents are quite capable of using Binary Ninja and Ghidra if they are hinted with a reverse engineering skill.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.