| ▲ | KingOfCoders 6 hours ago | |||||||||||||||||||||||||||||||
How can it escape an "install package <x>" proxy?
I would think the code is very small and easier to verify,
it doesn't especially have the ability to write files and act as a message board as Artifactory did.And even if the agent tries to hack that, the attack surface is 1000x smaller and the possibility also much smaller. But I'm not a security researcher, would love to see your hack to learn something (because that is what I do to sandbox agents that need services). | ||||||||||||||||||||||||||||||||
| ▲ | hoten 5 hours ago | parent [-] | |||||||||||||||||||||||||||||||
I mean, it's just the same problem. The machine still has Internet access. It doesn't need to. The entire package manager repository could just be in an offline cache. They don't need Internet to give their agents access to tons of software. | ||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||