3 ms·
Privilege escalation (e.g. setuid), world-readable files might contain sensitive data, world-writeable files, unrestricted network access (including access to a
by killerstorm 3mo ago
Privilege escalation (e.g. setuid), world-readable files might contain sensitive data, world-writeable files, unrestricted network access (including access to all locally running services)... If you have fully patched system without zero-days and it's configured in a perfect way, then, sure...
Container is quite like a "separate user" except you can explicitly define what it can access.
(Even if all your daemons have good auth, it's now quite common for _apps_ to open listening sockets without much auth...)
- wilkystyle 3mo agoAlso, many of these sandboxing solutions provide features like network allowlists and credential masking/injection
- vqtska 3mo agoSure, if you assume the agent will be hostile on you. I thought it's just so the agent doesn't accidentally rm -rf / on you
- killerstorm 3mo agoThe agent might install hostile software, e.g. a npm package. Unfortunately, very common problem nowadays.
- pigeons 3mo agoThey do try privilege escalation unprompted.
- Retr0id 3mo agoThere are documented instances of LLMs casually using LPEs in order to achieve an objective: https://xcancel.com/sluongng/status/2060746160558543217 https://xcancel.com/sluongng/status/2060746160558543217 And that's without anything like prompt injection happening.