Ask HN:如何处理运行/安装项目所带来的安全影响?
1 分•作者: johng•2 个月前
HN/Github 等平台上涌现出许多很棒的项目,但如今在软件项目中植入后门和恶意软件变得非常容易。我很好奇大家是如何处理安全问题的。即使在 Docker 中安装,如果以 root 用户运行,似乎仍然有办法让它们获得主机的 root 访问权限。
我在这里看到了许多很棒的项目,我很想尝试一下,但我担心可能会在我的系统上安装一些恶意软件或带有后门的软件。有一些 AI 工具、终端等项目不断出现,看起来很不错……但最坏的情况下,它们至少能够获取你的 Claude 凭据,甚至更糟。
我只是好奇,随着大量新项目涌现,其中大部分是 AI 编写的。
我想知道大家是如何应对的?如果沙盒是解决方案,那么测试它的最佳沙盒方式是什么?
查看原文
There are so many neat projects coming out on HN/Github, etc. But, it's so easy to inject back doors and malware into software projects now a days. I'm wondering how people deal with the secrutiy of this. Even if you install them under docker, if it's run by root it seems like there are ways they can get root access on the box.<p>I see so many neat projects here I'd like to try out but I'm worried that I may install some malware or backdoored software on here. There are a few AI harnesses, terminals, etc. that keep coming up that look neat... but at the very least they'd be able to get your Claude credentials, if not worse.<p>I'm just wondering with so much stuff coming out, most of it AI coded.<p>Just wondering how people deal with it? What's the best sandbox way of testing it if that's the solution?