4 ms·
Also, terminal access is extremely powerful on its own. Why should an agent even get access to that? I see it as a potential violation of least privileges.
by gmueckl 10d ago
Also, terminal access is extremely powerful on its own. Why should an agent even get access to that? I see it as a potential violation of least privileges.
- lelanthran 10d ago> Also, terminal access is extremely powerful on its own. Why should an agent even get access to that? I see it as a potential violation of least privileges. When even the official software from the token providers have never had human eyes on 800kSLoC, I'm afraid that ship has sailed: the principle of least privileges has already been ravaged to hell and back. Sealing a pin-prick hole in a dam wall is pointless if half the dam has already been washed away.
- datsci_est_2015 10d agoWhy trust any user with access to any terminal? UNIX solved this decades ago. It’s just we’re all learning to be sysadmins for the most creatively destructive and persistent set of users of all time.
- gmueckl 10d agoUNIX didn't really solve this scenario. Yes, you can limit what local files a user has access to. But with web applications and cloud services being so ubiquitous, the local boundaries are pretty much meaningless. Forcing an agent through an MCP is a way to grant access to remote services while still restricting how the network access can be used.
- datsci_est_2015 10d agoNetwork administrators also solved these things, e.g. you can limit what websites a virtual machine is allowed to access. Now, if you’re letting your agents abuse network traffic there becomes a point where you’re criminally liable. Unfortunately the current US government has no interest in prosecuting such abuse.