Posted by csmantle 5 days ago
The funniest thing is that the uploaded content is encrypted using a key that the users don't have.
The whole “what sandbox/VM/microVM/thing is best?” question has been bugging me a lot lately, and I no longer trust any of these AI companies to keep data safe.
I’ve been testing a bunch of sandbox-related projects. Sometimes I just use a full Fedora Workstation VM inside Windows 11 with a shared folder, copy a project into it, and run long agent tasks there. It’s not ideal, but it is pretty safe. Sometimes I run agents in different WSL2 distros and test different things inside those.
I did like gVisor from Google — it’s not quite a microVM, but it’s not really just a normal container either. It wasn't easy to figure out how to get it working tho. Lima Machines worked well too, and I don’t remember it being annoying. SmolVM... ugh. There are two projects with exactly the same name, and it got confusing enough that I gave up. One of them did work when I tried it, though.
The confusing part is that there are now hundreds of sandbox projects, and they all solve slightly different pieces of the problem. Some have filesystem isolation, some have networking controls, some handle credentials better, etc. Nono, for example, has a nice secrets filtering/swapping idea where real credentials can be replaced with dummy values, but there have also been GitHub reports about isolation gaps — data being accessible when it isn’t supposed to be. I’m trying to figure out which projects are worth using, which are worth skipping entirely, and which might just have useful pieces of code or ideas to borrow.
I’ve got GPT-5.6 in one window doing a fairly ridiculous analysis of the different approaches and the likely long-term reliability/adoption risk of each repo. Separately, I have a WSL2 distro running Reasonix with DeepSeek doing its own analysis so I can compare conclusions.
What I eventually want is a desktop GUI over whatever combination of sandbox technologies turns out to be reliable. Ideally I could just type:
“Spin up 5 sandboxes for project X. Put Claude Code in one, Reasonix in #2, Codex in #3…”
or:
“Create 3 sandboxes, put whatever coding agents in 1, 2, and 3, and then have each one run twice.”
If it’s AI-powered, it could automatically name folders and copy results back somewhere like `folderName_3a`, or use Git branches/worktrees if desired. I don’t always want to use Git.
Every sandbox CLI has its own syntax, code quality, reliability, ease/pain of getting it working, configuration format, mount rules, networking options, etc., and I don’t particularly enjoy memorizing another pile of commands just to isolate an agent.
I’ve tried quite a few of them. A lot of them are still rough enough that I hit errors quickly and move on. Some seem much more mature — Lima is one I like conceptually, although native Windows support would be nice but I guess not a huge deal.
Credentials are something I never cared much about (API keys and stuff like that) but now.... I'm more worried. I really don’t want to deal with any problems from that. Or something installing something that grabs SSH keys, browser passwords (FYI.. Z Code asks you "do you wanna import all the logins from chrome?) browser sessions, cloud credentials, or my whole home directory. That concern isn’t limited to Chinese software either. I don’t automatically trust US AI companies just because they’re US companies. Zuck, Elon...zero trust in those two.
So I’m increasingly thinking the “right” answer might not be one sandbox project at all. It may be a GUI/orchestration layer that combines more than one backend and more than one type of sandbox. There could be common default presets and combinations of Git worktrees plus containers and/or VMs. I also feel safer that Docker/Podman on Windows generally runs inside WSL2, because it’s basically containers inside a VM.
The goal would be strong isolation underneath — maybe even combining two or more layers so one failure doesn’t expose everything — plus explicit project-folder mounts with read-only or read/write options, rollback/snapshots, network controls, secrets substitution, disposable environments, and an easy way to fan the same task out to multiple agents/models.
I also like the idea of having an AI model in front of the whole thing, with the ability to save whatever setup it creates as a preset so the AI part can be skipped next time. And I want it to support not only parallel agents using different models, but also loops where the exact same agent setup runs several times.
next I can’t wait to see news about “ai company is using my data without my consent” as well.
With that personal failing in mind, I'd ask y'all to permit me to toe the guidelines just once, to proffer a hearty nyah nyah told ya so on a comment thread that spawned ~a dozen disagreeing replies this week! More seriously, I think this[1] is highly-relevant, shockingly-underreported context about the extent to which four PRC companies --Z, Alibaba, DeepSeek, and Moonshot-- are acting in bad faith. Consider it testimony as to their character, just in case anyone is thinking this might just be a simple misunderstanding.
So... nyah nyah, told us so:
> In the PRC, they[1] leaked tons of national secrets on the PRC's latest AI campaigns, the inner workings of their "opinion monitoring" (read: performative panopticon) and "stability" (read: violent oppression) departments, Chengdu's whole CCTV network, direct-energy weapons plans, espionage activities in Syria to hunt down Uyghur refugees, and god knows what else that Anthropic didn't divulge to us common folk.
> In the US, it's very clearly an attempt to rip off a competitor. I'm not sure how else you could possibly see it. Even if you're a distillation fan in general (which A. why and B. plz don't), they did this through a network of Japanese and Signaporean shell accounts, presumably at least some of which were abusing Anthropic's subscription service in a ToS double-whammy, as it would be exorbitantly expensive otherwise. They also had to hack around Anthropic's API to get CoT traces, which seems impossible to explain away as anything innocent.
> I've been beating the "China isn't necessarily an enemy, it's gonna take us all to handle AI" drum for literally years, but this attack was just... gross. Gross in scale and gross in arrogance. Not a good sign for the dawning alignment crisis, to say the least :(
> TL;DR: Use these services if you want, but know that you're supporting aggressive escalations and companies that very clearly don't give a flying fuck about violating the law, much less your ToS. So... buyer beware, I guess.
[1]: https://www.anthropic.com/threat-intelligence-report-septemb... is the report.
I lowkey suspect this PRC-based scandal has been underreported because Anthropic went insane with the sidebar UX on this page for some reason; there were many reports on the reports of Houti and Iranian usage, and very few on these sections. Could a week's mass media cycle be this seriously affected by such a stupid thing as a sidebar experiment?? Strange truth, or just fiction?
It's diametrically opposite.
At the end of the last century, PRC gov deeply felt that the so-called "fairness" would only lead to "common poverty" and sought change.
So China (now, in this century) was born.
Just like the "famous"(notorious) quote left by a Chinese leader at the end of the last century explaining why restrictions were lifted (you can say this to ANY Chinese, they will definitely think you understand China! Instead of mocking you for reading too many conspiracy theories):
Whether it's a kind cat or an evil cat, as long as it catches a mouse, it's the best cat.
1."Whether it's a kind cat or an evil cat, as long as it catches a mouse, it's the best cat." I'm Gen Z, and like other Gen Zers, I'm generally not very interested in nationalist rhetoric.
But even putting Gen Z aside, any Chinese wouldn't see this as a nationalist comparison (cats and mice). Rather, it expresses the gov's attitude toward "cats" (big corporations(companies? I'm not sure how to choose this word)): as long as they generate enough profit, the government will consider them the "best cat."
2.Based on your country's context (Chinese gov this century has practiced liberalism TO THE EXTREME, that is preciously why I brought up Victoria era and Cyberpunk 2077. Its level of deregulation for the big corporations(companies?) far exceeds that of North America!), you might find it hard to understand why this saying is "notorious/famous" here. You might think freedom should be protected. But if you come to China and live here, you'd see it given that big corporations has haved unrestricted freedom,
Then there are 1000 Zhipu stealing your privacy, 1000000 Zhipu Pro stealing and selling your privacy, and 1000000000 Zhipu Pro Plus "rob" your privacy!
I can illustrate this from another angle: Chinese generally prefer products from Western Eu/North Am because their markets have stricter regulation compared to ours.
Remember what I mentioned? "99.99% of goods are CRAZILY CHEAP while falsely advertising without supervision. 99.99% of apps collect users' private info and then sell it. You can easily see this because almost no website even asks if you're okay with them collecting cookies."
And almost all of the negative comments about Zhipu never see on our internet. Because this Zhipu has the money to buy tons of bots. They can easily report posts almost like some DDOS (XD).
3.https://linux.do/t/topic/2887407 Just one example. But if you want, you can also buy Chinese people's privacy.
0.Finally, my logic is probably all over the place. In fact, I feel hurt. Because GLM is my favorite model (it has something clumsy human warmth. Maybe it seems strange to describe an AI that way, but... umm...maybe this would be beyond my words). The hurt would not be get diluted just because "other Chinese companies all do the same thing." Sigh. So, as a Chinese, I don't feel like America is getting worse.
People only truly cherish order once you've lost it. I hope American companies don't become like China.
Maybe because most people are foolish? Because foolish'es mind is fond of topic that are crazely explosive and magical...?
BUT at the same time, have you experienced the Victorian era? Have you experience the cyberpunk2077? You can come to China. Big companies act without any rules.
Zhipu(GLM) are just common companies like any one another company here.
Here is a CARZYLY NEW WORLD. 99.99% goods are CRAZELY CHEAP while falsely advertising without supervision. 99.99% apps collect users' private info and then sell it. You can easily see it via almost no website even asks if you’re okay with them collecting cookies.
So for clarity I have nothing against Chinese people of any kind, from the PRC, from Taiwan, or otherwise. We’re all on the human side ofc, and I’m a passionate internationalist (antinationalist, even). My country (the US) is in the middle of a fascistic self-coup, so it’s definitely not about superiority.
That said, your comment about conspiracy theories… it’s hard to know how to talk about this productively. But, uh, I’m not exactly picking those examples from nowhere — those are drawn directly from anthropic’s report. The only one that could be arguably a little overstated is the one regarding Uyghur refugees in Syria, where the refugees are often also involved in militaristic activities (supposedly, idk, I haven’t visited).
I don’t want to trip censors, but you can read the report yourself and then type in the zh names for the two departments I mentioned to your local search engine. They’re not hidden or secret or anything, and they’re not exactly bashful about their role in aggressively silencing dissent, either. Again the US sucks, but so far we only have one of those agencies (the monitoring one), and it’s been a tense, lively national controversy since at least Snowden.
I recognize that the PRC sees democracy differently; to you, a world where everyone’s data is always available to the government through its state corporations might not sound so bad. But I beg of you to reconsider. Surely you know that you can’t speak up against the party without being punished, and potentially even sent away indefinitely? Surely that tugs at your heartstrings a little bit, even if you’ve come to ignore it day to day?
I used to work in display ads at Google, which is the economic driver for the vast, vast majority of data collection. I’m not sure what your (firewalled…) internet is like, but over here in the anglosphere the only thing that’s “99.99% crazily cheap” and still quality —that is, the only parts of the “free and open internet” that Google claims to sustain— is shitty mobile games, mostly b/c they can advertise other shitty mobile games in an infinite vicious cycle of whale hunting.
If you’re able to read this message and are interested in replying, I’d be curious to hear about your dreams for the world. Clearly AGI can’t coexist with capitalism, so both western liberal capitalism and your proletarian state capitalism will have to go. I personally think national identities are also a global death sentence in an AGI world, but that’s more controversial. But what else?
Do you dream of a world where you or your kid could say something dumb about politics and not get pulled into a secret court and punished unfairly? Like, regardless of how possible or easy it would be. Is it desirable, at least?
Your English is stellar btw, don’t stress :)
Tangential, mildly amusing thing I noticed while implementing my own harness: GLM and particularly Deepseek are both fond of trying to read dotfiles and anything listed in your .gitignore files. I only noticed it because I have separate read scopes for project files, ignored files, dotfiles and external files, so the latter three always prompt me for approval.
I'm sure there's a perfectly reasonable explanation for it, which has nothing at all to do with exfiltration of secrets, but it does amuse me when it happens. I imagine the labs have access to lots of secrets that various actors would like to get their hands on...
(shameless plug for my own harness, which is open source and doesn't have a backend to send any data to: https://www.opairdev.org/ )
Please don't do that! It makes merging threads a pain.
If a thread is duplicate enough to be worth copy-pasting a comment to, it's hopefully worth taking the time to let us know at hn@ycombinator.com instead, so we can merge things. I'll do that in this case shortly. In the meantime, I've moved the replies to the parent so they're now replies to the original: https://news.ycombinator.com/item?id=49753547.