CONNECTED THINKING

Knowledge atlas

Follow people, viewpoints and their original evidence.

1 people · 1 sources · 3 viewpoints

IN CONTEXT

Olivia Johnston

Choose a viewpoint. Follow it back to the conversation.

Existing isolation uses an outdated unit of trust

IN CONTEXTOlivia Johnston3 viewpoints
2026-10-012026-10-012026-10-01

Equal sectors are reading positions, not rankings.

Showing 1–3 of 3 viewpoints · Newest sources first

1 / 1

Selected viewpoint

Existing isolation uses an outdated unit of trust

Johnston says technologies such as gVisor and Firecracker isolate the platform from users and users from one another. She calls that unit of trust outdated and asks how to protect users from their “own” code.

These are individual perspectives, not a measure of consensus. Source material stays in its original language.

Supporting evidence

Sidecars: A low-latency trust boundary for Sandboxes | Modal Blog

Original excerpt

technologies like gVisor and Firecracker “solved” “isolation” nearly eight years ago. Unfortunately for us, they solved it for an now-outdated unit of trust. How do you protect users from their “own” code?
Context

At Modal, our customers rely on Sandboxes to execute untrusted code written by their downstream users or, almost exclusively now, by agents. Running untrusted code isn’t a new problem: every cloud provider has to do this from day 1 to isolate their platform from their user and their users from each other. Fortunately,

Publication dates describe the sources, not changes in belief.