Hacker Newsnew | past | comments | ask | show | jobs | submit | ashahin's commentslogin

The "workaround" framing implies the docker-group trick is the issue. The deeper question: should agents be allowed to find ANY workaround around a permission boundary the user implicitly set by not granting sudo? Same blast radius whether it's docker, a setuid binary, or rewriting your scripts — needs to be flagged regardless of the specific trick.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: