3 ms·
Wait. Do people run agents as their own user? Does nobody setup a dedicated user/group with a very specific set of permissions? It's not even hard to do! *NIX
by Chabsff 1y ago
Wait. Do people run agents as their own user? Does nobody setup a dedicated user/group with a very specific set of permissions?
It's not even hard to do! *NIX systems are literally designed to handle stuff like this easily.
- jvanderbot 1y agoNo I'm fairly certain almost nobody does that.
- andai 1y agoI'd have to follow some kind of tutorial, or more realistically, ask the AI to set it up for me ;)
- johnQdeveloper 1y agoI only run AI within docker containers so kinda?
- deleted 1y ago[deleted]
- mrklol 1y agoSame with the browser agents, they are used in a browser where you‘re also logged into your usual accounts. Means in theory they can simply mail everyone something funny, do some banking (probably not but could work for some banks) or something else. Endless possibilities
- mathiaspoint 1y agoI run mine as it's own user and self host the model. Unlike most services the ai service user has a login shell and home directory.
- MadnessASAP 1y agoWhat's its preferred shell and window manager?
- mathiaspoint 1y agoIt just uses bash. I haven't been giving it an X session yet although I probably will start at some point since the newer models can handle it.
- MadnessASAP 1y agoThank you for a serious answer to a facetious question.
- electroly 1y agoVMs are common, consider going that additional step. Once you have one agent, it's natural to want two agents, and now they will interfere with each other if they start running servers that bind to ports. One agent per VM solves this and a lot of other issues.
- adastra22 1y agoThat seems hardly sufficient. You are still exposing a massive attack surface. I run within a rootless docker container.
- deleted 1y ago[deleted]
- f33d5173 1y agoUser level separation, while it has improved over the years, was not originally designed assuming unprivileged users were malicious, and even today privilege escalation bugs regularly pop up. If you are going to use it as a sandboxing mechanism, you should at least ensure the sandboxed user doesn't have access to any suid binaries as these regularly have exploits found in them.
- mansilladev 1y agoAn agent can be designed to run with permissions of a system/bot account; however, others can be designed to execute things under user context, using OAuth to get user consent.