Comment by Joker_vD

8 hours ago

> An agent cannot be its own security authority. It must run within a boundary defined by the developer or organization and enforced independently of the agent itself.

...so make it its own security principal, distinct from the human user?

> Without a managed execution boundary, the agent may decide that changing the server configuration is the fastest way to complete the task and potentially break the production site.

It can decide that even with the execution boundary in place, you know. What matters if it can actually act that out.

All in all, a very sloppily written announcement. Almost as if it was written by—

> ...so make it its own security principal, distinct from the human user?

That presumes the existence of a security context, which this product provides. Where do you configure the security principal otherwise?

  • Windows already has a multi-user security context, with file- and API-level permissioning. We often call it “Users” or “RBAC”. I’ve read it and I’m still not sure what I can do now that I couldn’t a week ago.

    • The same-machine-multi-user security paradigm has been dead for a long time. Even on linux, you pretty much assume root or non-root and leave it at that. You then use other layers (namespacing, kvm, etc) to enforce actual security isolation and controls.

      root/non-root split is almost entirely used as a "don't let people accidentally shoot themselves in the foot" mechanism these days. Like you don't want your point-of-sale operator to accidentally disable the network or mess up the firewall rules effectively bricking the machine. Requiring an IT person to make the trip to fix it for them. But you would never "trust" the separate user profile on that POS machine as something keeping a purposefully malicious employee out of a secure system. The entire machine, regardless of the user profile, is the same security context. The uid/gid concept is an antique from the 80s that stopped working a long time ago. It's just an organizational primitive now for the most part.

      I remember the fun days of the 90s and early 2000s when there were shared machines that a ton of people would ssh or rdp into with different user account and "share compute". It was fun, but absolutely no bueno for a long time now.

      1 reply →