HN Reader
New
Top
Best
Ask
Show
Job
Allowlisting some Bash commands is often the same as allowlisting all
18
14
18 hours ago
by drewgregory
Same thing for allowing specific sudo-commands. Many tools (like vim or the tools mentioned in the article) would have the same problem when allowing them to be run with root privileges.
17 hours ago
by zufallsheld
everything
is a container these days, and yet somehow collective-we don't manage to have AI agents run in a container layer on top of our current work, so we can later commit or rollback?
16 hours ago
by eqvinox
I know they’re just being through but the “go test” part is a bit “Pray, Mr Babbage”… Test code is just code. I know of no language where tests are sandboxed in any meaningful way.
17 hours ago
by pimlottc
> I really thought `eval` would not be abused on non validated input
- your colleague, or you 1 year before.
15 hours ago
by hbogert
Allowing a "command" (executable, I believe) that isn't a read-only absolute path is a fool's errand. I will modify PATH and run my own implementation of it.
17 hours ago
by sadnboxx
“…with Claude Code”
17 hours ago
by teddyh