The Sandbox Explosion

2 pointsposted 6 hours ago
by alexellisuk

1 Comments

cope123

6 hours ago

Containers assumed reviewed code. AI agents break that assumption.

The interesting shift here isn’t Docker vs microVMs, it’s that “execute first, reason later” has become normal — and that forces isolation to move down to the kernel boundary.