logoalt Hacker News

dymkyesterday at 8:32 PM3 repliesview on HN

You give it command line access in a VM...


Replies

noduermetoday at 1:31 PM

Yeah, fine... but it's like daily that a non-tech-savvy friend of mine tells me they just installed some shiny "harness" on their laptop now to organize their emails, and they "just put it in one folder" and "8n8 says", what does it say on the tin, Dave? "it says it's highly unlikely it will escape from the folder". Your work computer? "Yeah, but it's a real company. They're all about security."

So telling someone who just wants to upload an .xlsx file to a bot that they should just find a harness to give CLI access to their work computer - right after they say they work in a regulatory capacity - is just freakin malpractice.

ycui1986today at 12:28 AM

i give it in real ubuntu, no vm, no docker. so long I don't ask it to organize files, it will behave. it has not screw me so far.

show 1 reply
koen_hendriksyesterday at 9:49 PM

You mean a VM like the one that contains a 0day that can escape the sandbox that gets found every year at pwn2own?

show 4 replies