Comment by eranation
3 hours ago
Daily reminder that containers are not considered a safe security boundary, and never were. If you really need to run untrusted code, use a MicroVM.
3 hours ago
Daily reminder that containers are not considered a safe security boundary, and never were. If you really need to run untrusted code, use a MicroVM.
What microVM do you recommend ?
not op but firecracker exists, as does docker sbx (not container!),
firecracker is a lot more of a headache to setup than docker sbx (not container!) but if you can get it going it probably “feels” the best
of a different variety some people feel better using stuff like bubblewrap/fire jail but idk if these are still microvm as opposed to the above
but it’s my opinion (perhaps completely criticizable), that sandboxing for personal home use machines is 1) somewhat overkill 2) somewhat theatre 3) psychologically sometimes exhausting and unrealistic always assuming the worst is going to happen and 4) not really worth the time and creates quite a bit of friction that there wasn’t previously. In the end I spent more time tinkering with the sandbox to get it “just” right that it drained my time actually using the agents so …