Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ATechGuy
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
31.
▲
by
ATechGuy
8mo ago
I'm not saying sandboxes are not needed, I'm saying VMs/containers already provide the core tech and it's easy to DIY a sandbox. Would love to understand what value E2B offers over VMs?
32.
▲
by
ATechGuy
8mo ago
I will ask what I've asked before: how to know what resources to make available to agents and what policies to enforce? The agent behavior is not predefined; it may need access to a number of files & web domains. For example, you s
33.
▲
by
ATechGuy
8mo ago
In the last one year, we have seen several sandboxing wrappers around containers/VMs and they all target one use case AI agent code execution. Why? perhaps because devs are good at building (wrappers around VMs) and chase the AI hype.
34.
▲
by
ATechGuy
8mo ago
> allowNet: ["api.openai.com", "*.anthropic.com"], How to know what domains to allow? The agent behavior is not predefined.
35.
▲
by
ATechGuy
8mo ago
What about VMs? They offer strong isolation, as they don't share kernels, and have long been a foundational piece for multi-tenant computing. Then, why would we put an extra layer on top and rebrand it as an AI agent sandboxing solutio
36.
▲
by
ATechGuy
8mo ago
Congrats on launching, and great testimonials! What problem does it solve compared to bazillion code execution sandboxing agents (and containers/VMs)? Overall, a lot of people are building their own code execution sandboxing agents aro
37.
▲
by
ATechGuy
8mo ago
> They fail because the environment is flaky: missing deps, slow setup, weird state, unclear feedback loops. Why can't agents install missing deps based on the error message?
38.
▲
by
ATechGuy
9mo ago
> There's no "OAuth for syscalls" yet. This exists today in OSes in form of discretionary/mandatory permissions (e.g., SELinux, AppArmor, LandLocked).
39.
▲
Ask HN: Have your views about AI / LLMs changed? What triggered it?
4 points
by
ATechGuy
9mo ago
|
1 comments
40.
▲
by
ATechGuy
9mo ago
What was the first concrete thing you needed that existing sandboxing tools (Docker/VMs/bwrap) just didn't provide?
41.
▲
by
ATechGuy
9mo ago
> As long as there is a full OS running, you are one libc function away from a sandbox escape. Does this mean, all software in the world is just one function away from escape?
42.
▲
Ask HN: Why are so many rolling out their own AI/LLM agent sandboxing solution?
32 points
by
ATechGuy
9mo ago
|
18 comments
43.
▲
by
ATechGuy
9mo ago
That's a fair criticism. My thought process was that the original comment was based on their personal experiences and since ChatGPT is trained on a large dataset, it may offer a different perspective derived from experiences of a lot m
44.
▲
by
ATechGuy
9mo ago
When scaling out, edge latency will overshadow kernel boot-up times: speeding up boot-up from 1.5s to 150ms will not have any perceived impact on app performance when scaling on edge to meet the demand.
45.
▲
by
ATechGuy
9mo ago
Fast boot up means nothing if your agent/app is slow at runtime (due to virtualization tax or QEMU emulation). Fast boot up is a PR term, which can easily be optimized for compared to designed a better virtualization layer that perform
46.
▲
by
ATechGuy
9mo ago
@nl But this uses nested virtualization on GCP, which severely hurts performance. Faster boot up means nothing if everything else is slow.
47.
▲
by
ATechGuy
9mo ago
Genuine question: why not just use GCP/AWS VMs for agentic execution? What is missing?
48.
▲
by
ATechGuy
10mo ago
Scrapers use residential IP proxies, so blocking based on IP addresses is not a solution.
49.
▲
by
ATechGuy
10mo ago
It is really free? Genuinely asking.
50.
▲
by
ATechGuy
10mo ago
From ChatGPT: This approach can stop very basic scripts, but the claim that “99.9999% of scrapers can’t execute JS or handle cookies” isn’t accurate anymore. Modern scraping tools commonly use headless browsers (Playwright, Puppeteer, Selen
51.
▲
by
ATechGuy
10mo ago
Genuine question: if traffic to websites is down and likely to continue the trend, what would be the value? Do you plan to address agentic browsing in the near future?
52.
▲
by
ATechGuy
10mo ago
Why not use KVM?
53.
▲
by
ATechGuy
11mo ago
Having used this for our research, I highly recommend Rtrvr.
54.
▲
by
ATechGuy
11mo ago
Maybe we should write an agent that writes an agent that writes an agent...
55.
▲
by
ATechGuy
1y ago
Then why only apply to VMs, why not apps?
56.
▲
by
ATechGuy
1y ago
Side-channel attacks apply to multi-tenant cloud environments, not local.
57.
▲
by
ATechGuy
1y ago
Why not use VMs from AWS (EC2) or GCP? E2b is built on top of GCP anyway.
58.
▲
by
ATechGuy
1y ago
Startups would build on big tech, so are likely to add their margins. Have you looked into (bulk) discounts from GCP/AWS?
59.
▲
by
ATechGuy
1y ago
Thanks! While I agree with you on "saving seconds" and overall latency argument, according to my understanding, most agentic use cases are asynchronous and VM boot up time may just be a tiny fraction of overall task execution time
60.
▲
by
ATechGuy
1y ago
> It does take 1-5 seconds to boot the environment (firecracker vms). I'd say 1-5 secs is fast. Curious to know what use cases require faster boot up, and today suffer from this latency?
More ›