Y
Hacker News
new
|
ask
|
show
|
jobs
by
anvuong
19 days ago
What kind of logic is this? It's standard in the Linux world to give important services a separate user domain.
1 comments
khalic
19 days ago
The standard here is not enough when the agent can escalate by finding 0 days, for example. It’s like giving a black hat a limited account. Sure it might restrict him, but not giving him an account at all is way better
link
gowld
19 days ago
The black hat can find 0-day escalation in your sandbox, too.
A user account
is
a sandbox.
link
khalic
19 days ago
Not as air tight as a container
Edit: it’s about the attack surface
link
chrisweekly
19 days ago
microvms are better than containers running on your host. see eg the "smolvm" microvms from
https://smolmachines.com
link
khalic
19 days ago
thanks, will take a closer look
link