← Back to context

Comment by trollbridge

5 hours ago

Well:

1. Park your Python or whatever code inside a VM with no connectivity to anything (other than to accept inbound ssh) and with a canned set of PyPi etc packages available for it to use

2. Park hypervisor for that in a machine with no connectivity except thru a firewall that only admits the relevant ssh traffic.

3. Make sure to use ssh clients that can’t be exploited by a remote server. If this is too challenging, then use telnet or rlogin instead.

4. You can extend this to eg allow outbound calls to an LLM. Alternatively, place the GPU hardware and LLM weights inside the hypervisor machine.

Congratulations, now nothing can escape except what you allow to from the output from rsh.