奥利维亚·约翰斯顿提到 Firecracker 是一种为过时的信任单元解决隔离问题的技术,未表达支持或反对。
Olivia Johnston ·
支持这项说法
Sidecars:沙箱的低延迟信任边界|Modal 博客
诸如 gVisor 和 Firecracker 之类的技术在近八年前就“解决”了“隔离”问题。但对我们而言不幸的是,它们所解决的是一种如今已过时的信任单元的问题。你该如何保护用户免受其“自己”代码的影响?
原始摘录
technologies like gVisor and Firecracker “solved” “isolation” nearly eight years ago. Unfortunately for us, they solved it for an now-outdated unit of trust. How do you protect users from their “own” code?
上下文
在 Modal,我们的客户依赖 Sandbox 来执行由其下游用户编写的、或者如今几乎完全由智能体编写的不受信任的代码。运行不受信任的代码并不是一个新问题:每家云提供商都必须从第 1 天起就这样做,以便将其平台与用户隔离开来,并将用户彼此隔离。幸运的是,
原始上下文
At Modal, our customers rely on Sandboxes to execute untrusted code written by their downstream users or, almost exclusively now, by agents. Running untrusted code isn’t a new problem: every cloud provider has to do this from day 1 to isolate their platform from their user and their users from each other. Fortunately,