logoalt Hacker News

theptip • today at 4:43 PM • 1 reply • view on HN

> these things are given access to whatever they want on the Internet

They are intended to be fully sandboxed and not have direct internet access. Things like package managers are run from internal proxies.

The environments are built to be as reproducible as possible.

But yeah, the serious folks have been talking about rogue clusters for a long time, eg see Ajeya Cotra’s pod with Dwarkesh.


Replies

ozozozd • today at 5:40 PM

Fully sandboxed means no Internet access. You can also specify which packages are accessible and put it in the sandbox. Or you can be lazy and give them access to a package manager that had Internet access, but you don’t get to say “we intended to fully sandbox it.”

Not sure why the reproducibility is a requirement that would contribute to the security. Not that fully sandboxing is harder with reproducibility, but that is a moot point when reproducibility isn’t a requirement.

OP pointed out clusters being hijacked specifically being a bigger concern than rogue clusters, your comment hijacks their comment to talk about “rogue clusters.” Or perhaps this is a promotion for Dwarkesh?