Ask HN:如何处理运行/安装项目所带来的安全影响?

1 分•作者: johng•2 个月前
HN/Github 等平台上涌现出许多很棒的项目,但如今在软件项目中植入后门和恶意软件变得非常容易。我很好奇大家是如何处理安全问题的。即使在 Docker 中安装,如果以 root 用户运行,似乎仍然有办法让它们获得主机的 root 访问权限。 我在这里看到了许多很棒的项目,我很想尝试一下,但我担心可能会在我的系统上安装一些恶意软件或带有后门的软件。有一些 AI 工具、终端等项目不断出现,看起来很不错……但最坏的情况下,它们至少能够获取你的 Claude 凭据,甚至更糟。 我只是好奇,随着大量新项目涌现,其中大部分是 AI 编写的。 我想知道大家是如何应对的?如果沙盒是解决方案,那么测试它的最佳沙盒方式是什么?
查看原文
There are so many neat projects coming out on HN&#x2F;Github, etc. But, it&#x27;s so easy to inject back doors and malware into software projects now a days. I&#x27;m wondering how people deal with the secrutiy of this. Even if you install them under docker, if it&#x27;s run by root it seems like there are ways they can get root access on the box.<p>I see so many neat projects here I&#x27;d like to try out but I&#x27;m worried that I may install some malware or backdoored software on here. There are a few AI harnesses, terminals, etc. that keep coming up that look neat... but at the very least they&#x27;d be able to get your Claude credentials, if not worse.<p>I&#x27;m just wondering with so much stuff coming out, most of it AI coded.<p>Just wondering how people deal with it? What&#x27;s the best sandbox way of testing it if that&#x27;s the solution?