4 ms·
I always run such tools inside sandboxes to limit the blast radius.
by ashishb 7mo ago
I always run such tools inside sandboxes to limit the blast radius.
- wswin 7mo agoI don't think it would help here, they were stealing credentials
- tux1968 7mo agoWhenever possible, credentials shouldn't be inside the sandbox either. Credential proxying, or transparent credential injection, for example with Sandcat: https://github.com/VirtusLab/sandcat https://github.com/VirtusLab/sandcat
- ashishb 7mo ago> I don't think it would help here, they were stealing credentials So, stealing credentials in the current directory and in all other directories are the same thing?
- PunchyHamster 7mo agoThe sandbox will need internet access (to update data) and you will need to send code to test into it; so compromise already equals leaking all your code, without even breaking the sandboxing
- ashishb 7mo ago> The sandbox will need internet access (to update data) and you will need to send code to test into it; so compromise already equals leaking all your code, without even breaking the sandboxing Compromising all code in one directory is bad. Compromising all my data in all other directories, including mounted cloud drives, is worse. I restrict most dev tools to access only the current directory.
- staticassertion 7mo agoYou only need internet access to grab the image, I don't think trivy requires internet access itself. All of my image scanning tools run in isolation.
- mkesper 7mo agoIt needs internet access for upgrading the check bundle and for full Java library resolution (pom.xml). See e.g. https://github.com/aquasecurity/trivy/discussions/9698 https://github.com/aquasecurity/trivy/discussions/9698
- staticassertion 7mo agoNice, thanks! Yeah, so exfil is definitely still a thing to watch out for, even if you run in an unprivileged env.