21 pointsby pheonixblade910 hours ago1 comment
  • woodruffw6 hours ago
    I have this nagging feeling with these kinds of agentic cloud products (and there seem to be so many these days): the promise is secure (as in isolated) workflows, but it’s unclear what that means when so many of the workflows themselves are privileged.

    Or in other words: I often struggle to see the security value of a VM that I’m just going to load all of my sensitive credentials into anyways (since the agent needs them). The usability argument seems strong, but the security argument seems to hinge on me treating my local machine as a sort of bastion host, which I don’t think is generally true.

    (This isn’t to denigrate the work itself: it seems very good. But it also seems like we’re still groping around a very weak definition of “security” for agentic workflows.)