| ▲ | minraws 6 hours ago | |
Why is everyone making their own code execution agent runtime engines I have an entire project built on top of openshell already, why not first come up with a sandboxing policy design, like unix did, and then build on top of that. Currently all project do tend to agree on what and how they work but certain things being different makes porting tedius, if all of them have a bare minimum subset common amongst them it would be much easier to switch, and validate security surface area. I feel like there are more vulnerabilities in this vibe coded slop sandboxes, and it's more likely everyone one of us trusting them to build projects around them will shoot our foot off once a cve is hit in one that's common in all of them but since they are all slop copies someone will have to figure out how they apply to all others and then manually fix it properly, and if one of them makes a CVE public it will leave dozens of these runtimes open to exploits. I wish the best to my future self with regards to security I feel like we are completely screwed. Since we can no longer depend on upstream for security. | ||
| ▲ | lifeisloving 4 hours ago | parent | next [-] | |
I saw a tweet that said: "Im really fkin worried we're all building the same thing" Everyone has been building a harness/sandbox the last 6 months. Ive seen dozens and dozens shared in discords. Even companies are totally stuck focused on the same paradigms. The previous iteration of this was RAG/Chat interfaces. See PewDiePie's project. Last month it was briefly everyone building the same classifier. Peter Thiel, gave a lecture about this same phenomenon 15 years ago likely because he observed the same things going on during other hype cycles. Everyone building the same things. Its called something like "Dont build the obvious thing" This is why Im moving towards hardware for personal projects, it forces me to be much more creative and think outside the "How can I make something AI adjacent/powered" trap thats so easy to fall into in pure software right now. | ||
| ▲ | torginus 5 hours ago | parent | prev | next [-] | |
The problem with OS level sandboxes, and the reason why WebAssembly's being explored in this space (and Electron is so popular), is that relying on OS/hardware features means your TAM shrinks to a fraction of total, and it's historically well known you set yourself up to lose. History is littered with tons of super cool OS features that didn't manage to gather enough market share and ended up as cool futures, and fodder for 'we invented the future 20 years ago' style articles. | ||
| ▲ | hobofan 6 hours ago | parent | prev | next [-] | |
Different use-cases have different requirements. e.g. this one puts multi-platform support as a high requirement, a requirement that OpenShell doesn't fulfil (and likely won't given it's architecture/goals). | ||
| ▲ | fg137 3 hours ago | parent | prev | next [-] | |
My guess is that Microsoft thinks this can be deployed with standard, company-wide policy across platforms (mostly) with their IT management tools which poses a unique advantage. In reality, however, knowing how much difference there is between OSes, how tricky it is to configure these things to make them actually useful, and how bad Microsoft products are, I'm not enthusiastic about this project -- there are so many others on the market already, and I'll wait to see if this gains traction. (Notice that on MacOS it only supports seatbelt? That's not nearly the same as microvm.) | ||
| ▲ | rock_artist 5 hours ago | parent | prev | next [-] | |
That’s exactly it. There should be some permission logic for delegating. But as always, there are rivals trying to set their tone on what’s the standard. We all wish there was one unified agreed concept that will work but I guess the most common one will eventually survive. Just as Microsoft in a sense embraces Linux with WSL and also Apple has their virtualization framework. I hope we’ll eventually get unified model management system to include also permissions designed properly | ||
| ▲ | booster-rooster 5 hours ago | parent | prev [-] | |
[flagged] | ||