Comment by oblio
9 hours ago
Why? We probably need more sandboxing, not less.
Especially with LLMs automating all sorts of code and operational aspects, we could do Tcl/Lua type whitelist sandboxes where the application can only call a limited set of functions.
I warn you to not try to argue with ai shilling people
I'll be fine, I outlasted the NoSQL and cryptocurrency people :-)
I think it makes more sense to use the kernel‘s’s sandboxing utilities (like seccomp, SELinux, namespaces, prctl and eBPF) than to rely on the process to try to isolate itself purely in userspace which will always have holes.