Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
insanitybit
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
31.
▲
by
insanitybit
2mo ago
Yeah fair enough.
32.
▲
by
insanitybit
2mo ago
Looks extraordinarily unergonomic and I don't get why I would need a number pad as a developer.
33.
▲
by
insanitybit
2mo ago
I've explained myself gratuitously at this point.
34.
▲
by
insanitybit
2mo ago
> Browsers have been sandboxing their tabs since 2008. Yes, it's an amazing feat that has cost billions and led to major features like seccomp v2, ptrace sandboxing, etc. Do you know the history of browser sandboxing? It's pret
35.
▲
by
insanitybit
2mo ago
> The technology works fine if you use it in a disciplined way. Then obviously we have to discuss the implementation! > Or just invoking bwrap. Or sandbox-execute. There's no performance overhead. Complexity is minimal. Just read
36.
▲
by
insanitybit
2mo ago
You can't simultaneously say that we've had the tech for years and also say that it doesn't work. We have not had the tech for years. x-plat sandboxing is extremely difficult, especially in a way that's performant. Sandb
37.
▲
by
insanitybit
2mo ago
Total nonsense. Python has a massive stdlib and there are malicious packages.
38.
▲
by
insanitybit
2mo ago
If it weren't a registry it would be ./configure scripts and makefiles. The issue is that sandboxing technology is kinda shit (especially x-plat) and languages don't build it in by default.
39.
▲
by
insanitybit
2mo ago
It would be more than a minor inconvenience. I can handle sandboxing my tests and production infra, but I can't handle sandboxing build scripts because I don't own that code in any sense.
40.
▲
by
insanitybit
2mo ago
The technical mechanism is exactly the issue to figure out, there's a reason why projects don't have this and it's because different implementations have different tradeoffs.
41.
▲
by
insanitybit
2mo ago
https://github.com/insanitybit/witchy This is why I'm building this language. It's capabilities based. Build scripts can't just do whatever the hell they want to, everything is auditable, and it layers i
42.
▲
by
insanitybit
2mo ago
You're just stating things that are obviously wrong. It's a lottery ticket? So... exploitation is no better than random? > The thing is when AI goes to hack 'all the things' it only needs to pick the weakest link in t
43.
▲
by
insanitybit
2mo ago
> Moving code into gvisor virtually eliminates privilege escalation. Rereading this, it's an overstatement. It doesn't "virtually eliminate" it. It drives the cost up by like 3 orders of magnitude and it pairs well w
44.
▲
by
insanitybit
2mo ago
This is straightforwardly incorrect. Of course it's not binary. AI costs money to run, and it takes time. Even if you say that AI is 10x as efficient at finding 0days, that just means that a $1M dollar exploit now costs $100K. Even if
45.
▲
by
insanitybit
2mo ago
> but very few of them are cyber focused, so it’s not surprising IMO Yeah but that's a business decision. I work on security at a company that does sandboxing and when the company decided to build an AI harness I was brought in as
46.
▲
by
insanitybit
2mo ago
> It just takes one crack in the armor, This is incorrect. It's actually the whole point. Imagine you're an attacker in a gvisor container with a Firecracker hypervisor around you, and a proxy on the host holds a signing secret
47.
▲
by
insanitybit
2mo ago
It was a genuine question because I couldn't tell. I responded to your idea that software has to be "perfect" in your other reply so I think we can continue there. https://news.ycombinator.com/item?id=49369111
48.
▲
by
insanitybit
2mo ago
> It all has to be perfect to not be hacked. This is absolutely not true. It's a matter of cost. Exploitation can cost on the order of 10K, 100K, 1M, 10M, etc. A straightforward one would be something like "MD5 collisions are o
49.
▲
by
insanitybit
2mo ago
> Would gvisor + Firecracker + credential-injecting proxy + real network isolation solve this problem? Yeah, basically. I mean I'm handwaving but yes, some combination of those would have made the attack way too expensive.
50.
▲
by
insanitybit
2mo ago
Are you being sarcastic?
51.
▲
by
insanitybit
2mo ago
That's not what I said, nor is it what I meant. It is incredibly easy to write radically safer software than the standard. Moving code into gvisor virtually eliminates privilege escalation. Using memory safe languages without seriali
52.
▲
by
insanitybit
2mo ago
It's not that dangerous, OpenAI just shit the bed building their infra. Write safer software and you'll be okay.
53.
▲
by
insanitybit
2mo ago
Has any model managed to escape Firecracker? Maybe through KVM, but that already requires privilege in the VM, right? I personally feel that we already have the technology required to contain AI, it's just poorly leveraged. Tools like
54.
▲
by
insanitybit
2mo ago
> Is the kind of crazy hack that Rust std uses to prevent TOCTOU attacks with symlinks a language complexity issue or not? I have no clue what you're talking about and I doubt that it's relevant. The claim was made that this is
55.
▲
by
insanitybit
2mo ago
noCopy. In order to understand it, they have to learn that this is enforced only by `go vet` and that the marker relies on everything described in the `2. How go vet and noCopy work` section of this article. Of course, they don't have
56.
▲
by
insanitybit
2mo ago
This explicitly leverages a hidden "feature" of the language, which is how Sync impacts copying (rather unintuively). It leverages this to create an interface based on that hidden feature to create a marker that is consumed by a s
57.
▲
by
insanitybit
2mo ago
I don't know the answer to those things, it feels like it's sort of on the one saying "This is simple" to explain why.
58.
▲
by
insanitybit
2mo ago
How is this simple? It's basically a hint to `go vet` that uses a special interface pattern. I'm baffled by what some people call "simple" lol
59.
▲
by
insanitybit
2mo ago
The obvious parody argument is that by introducing "boring" as a term there's now confusion preventing discussion based on real technical merits. > so management has to step in to baby us. An engineer wrote that post lol
60.
▲
by
insanitybit
2mo ago
I can't believe how many words you've packed into "boring" to justify "boring" being a good word. Let's hope everyone's view of boring is identical - with that many, one word out of place could cause
More ›