ÖFFENTLICHE AUSGEDRÜCKTE MEINUNGEN

Olivia Johnston

1 Quellen · 3 Standpunkte · 3 Themen

Inhalt aktualisiert:

Olivia Johnston zu agent security risk, performance-security tradeoff, trust boundary design. Entdecke 3 Standpunkte nach Thema, mit Belegen aus 1 Quelle.

Zusammenhänge erkunden

Standpunkte nach Thema

Zugeordnete Standpunkte nach Veröffentlichungsdatum der Quelle. Eine Momentaufnahme dieser Beiträge, keine abschließende Darstellung persönlicher Überzeugungen.

Übersetzungen dienen dem Leseverständnis; die Originalauszüge bleiben die Quellenevidence.

trust boundary design

Thema ansehen

Existing isolation uses an outdated unit of trust

Johnston says technologies such as gVisor and Firecracker isolate the platform from users and users from one another. She calls that unit of trust outdated and asks how to protect users from their “own” code.

Stützende Belege

Sidecars: A low-latency trust boundary for Sandboxes | Modal Blog

Originalauszug

technologies like gVisor and Firecracker “solved” “isolation” nearly eight years ago. Unfortunately for us, they solved it for an now-outdated unit of trust. How do you protect users from their “own” code?
Kontext

At Modal, our customers rely on Sandboxes to execute untrusted code written by their downstream users or, almost exclusively now, by agents. Running untrusted code isn’t a new problem: every cloud provider has to do this from day 1 to isolate their platform from their user and their users from each other. Fortunately,

performance-security tradeoff

Thema ansehen

Sidecars provide 3x faster cross-boundary communication in the stated comparison

Johnston describes Sidecars as isolated containers that run alongside a main Sandbox on the same host. She reports 3x faster communication across trust boundaries than using separate Sandboxes, particularly for operation-heavy workloads.

Stützende Belege

Sidecars: A low-latency trust boundary for Sandboxes | Modal Blog

Originalauszug

Sidecars enable 3x faster communication across trust boundaries than using separate Sandboxes — which is particularly helpful for operation-heavy workloads.
Kontext

Today we’re excited to introduce Sidecars, which are our broader answer to this problem. Sidecars are isolated containers that run alongside your main Sandbox on the same host and provide a real security boundary between trusted or untrusted code.

agent security risk

Thema ansehen

Agent harness in same Sandbox creates lethal trifecta

Johnston cites Simon Willison’s “lethal trifecta”: access to private data, exposure to untrusted content and the ability to communicate externally can allow a tricked agent to leak data. She says a coding agent whose harness runs in its Sandbox has all three by default.

Stützende Belege

Sidecars: A low-latency trust boundary for Sandboxes | Modal Blog

Originalauszug

Simon Willison calls it the lethal trifecta : an agent with access to private data, exposure to untrusted content, and the ability to communicate externally can be tricked into leaking that data. A coding agent whose harness runs in its Sandbox has all three by default.
Kontext

Hosting the harness and the tool calls together is a security risk. The harness's credentials sit next to generated code, the agent can read untrusted content from the web, like packages and repos, and anything in the Sandbox can make network calls..

Aussagen nach Quelldatum1

Die Aussagen sind nach dem Veröffentlichungsdatum der Originalquelle geordnet; unterschiedliche Formulierungen belegen keinen Positionswechsel.