HN user

pamcake

289 karma
Posts4
Comments165
View on HN

Yes you should. It will come naturally if you go down the road of separating code from data and properly isolating dev and prod environments, applying principle of least privilege as you do.

.env files for creds are a convenience for dev and testing. They were never supposed to be used for security or carried around with sensitive stuff inside. None of this is new.

The answer is the same: You give it either read-only or its own copy separate from the one you care about.

The requested feature wouldn't be a robust solution here either for the same reasons.

Besides, have you noticed the amount of other amateur-hour bugs anf jank in Codex going for weeks or months without proper resolution? Given that, why would you want and trust their solution here over alternatives, specifically?

Vivaldi 8.0 2 months ago

You can test this locally yourself with mitmproxy, opensnitch, or whatever.

You can try building the (supposedly) open-source apps you use from source.

Everyone opining here should MitM themselves every now and then. If not for your own security then maybe to make sure you're not participating in psyop when opining online and resharing hearsay or old truisms.

What of it?

You are not responding to the debunking of your "Value doesn't have anything to do with utility" claim.

The only relevant thing I can see here is that yes, the volume is too low to provide any sense of untracability for the scenario discussed. It might for paying your VPN subscription.

In this case it does. You can't funnel huge amounts through a coin with usually small volume and market cap and expect any sense of anonymity or privacy. The delta makes it obvious. It would probably be visible via movements on markets too.

For smaller amounts this is not a problem for the same coin and network.

Your volume might support $10k but not $10m.

I think I agree. But at the same time we have strength in numbers and people will find something close to what they want and fork off that.

So I think the same thesis holds for audiences of 10-100 and 100-1000.

A cambrian explosion of software.

The agent harness needs different sandbox(es) with different privileges. Nothing here supports not containing its access. It's a mistake to think and talk about "the sandbox" in the way the article does.

Look, if they namedrop specific distros in their announcement (marketing) blog post as affected, I think a heads-up before publishing that is appropriate and expected.

I don't think they would have gotten as much flame if it weren't for how the RHEL 14 mention and such were put.

This is a security company with a professional(?) communications department banking on pointing fingers at distro maintainers. We are not talking about solo security researchers or academics here.