Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Can I use this as a generic app permissions boundary or do I have to somehow fake it as an "agent"? We are well past the point where I need to be able to lock down that my music player has no ability to read my SSH keys or whatever.

Naturally, this will be gated to corporate customers - the plebs do not get access to better security unless they pay for a top tier license.

 help



FANTASTIC question here. I've been locking down agents by running them as untrusted users (mostly linux here) as even docker boundaries aren't really great. Firecracker is a step in the right direction (older tech, sure, but useful). I really want a local hashicorp-like vault that I can give agents specific access permissions and it can take forever to review and manage those access boundaries.

Indeed, Linux users pretty much provide enough protection and if you are willing to fiddle with SELinux you can get whatever you need.

There are many things that would be good to lock down. NPM install comes to mind.

I wonder if I will be able to integrate this with dev containers somehow, so my dev container could run in stricter isolation.


I've seen folks using the VS Code workspaces concept for this. It's a bit limited but a good step in the direction I prefer.

VS Code workspaces doesn't seem to offer any protection:

https://code.visualstudio.com/docs/editing/workspaces/worksp...

Maybe you use GitHub codespaces?


No, I did mean VS Code workspaces. Now I'm going to go down this rabbit hole to better understand the boundary limits :)

I did some reading of the docs and can't see anything in VS Code workspaces that would help.

I guess buy a Mac then.



Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: