Hacker News

Favorites Setup
Comment by moomin | original | Mxc: Microsoft Execution Containers version 1.0.0
[−]moomin · 2026-10-10 Sat 16:49 UTC · link
I’ve had a good think about this, and while it’s good to see them finally answering bubblewrap, the truth is that we as an industry have been ridiculously at permissioning for some time and this does not solve this. It’s all very well saying we have read only resource access, but then you connect up to JIRA and all of a sudden you’ve got a different identity system, different resource model and and more complexity than you can shake a stick at.

Our current answer of just making the security model more and more complex isn’t working. It just means that, when things inevitably fail, we can say “well, they didn’t secure it correctly”. When even describing what is correct is hard, and setting it up is harder.

Honestly, this looks good, but we need a root and branch rethink of security if we want something that can protect us from rogue agents.

[−]3eb7988a1663 · 2026-10-10 Sat 17:44 UTC · link
Microsoft security is a bimodal. They might have exquisite delineation for network resources in Sharepoint or Azure but consumer applications are a joke.

Excel, VSCode, Outlook, etc the permission model is a modal, "Do you trust this?" binary choice to enable full permissions to everything.

[−]saltamimi · 2026-10-11 Sun 00:12 UTC · link
End users aren't expected to care about security and if they do, usually they are in an enterprise setting where it's taken care of automatically by enterprise settings.

Not to say it's good or bad, just not the target market.

[−]mey · 2026-10-11 Sun 01:05 UTC · link
End users should be expected to care about security. They should not be the only guard rail, but they are part of the defense in depth plan.

You do know about all those security training courses HR makes your take every year that you skip over?

[−]pjmlp · 2026-10-11 Sun 08:48 UTC · link
Unfortunately they are there for compliance, unless there is a strong IT in place, which then again, makes them hated by everyone else.
[−]3eb7988a1663 · 2026-10-11 Sun 01:27 UTC · link
VSCode is targeted at a step above the standard end user, but even there extensions are not sand-boxed and the Workspace Trust is a single toggle.
[−]rsalus · 2026-10-11 Sun 01:50 UTC · link
Don't even get me started on PowerBI...
[−]xienze · 2026-10-11 Sun 09:16 UTC · link
> Excel, VSCode, Outlook, etc the permission model is a modal, "Do you trust this?" binary choice to enable full permissions to everything.

Because years of experience has shown that even users who should know better (developers) get extreme permission fatigue. The demand end users make is "it should just know without me having to click 'approve' all the time." Well, that's tough. You're basically stuck between a rock (fine-grained permissions) and a hard place (don't make me deal with it).

[−]Melatonic · 2026-10-10 Sat 20:31 UTC · link
Seriously. Mobile devices have done a better job with this (in some ways) but it really should be a standardised thing of least permissions by default. And way. Way less confusing.
[−]IanCal · 2026-10-11 Sun 10:43 UTC · link
I feel like there's got to be something more core around how many things we could make revertable. You can't "un-leak" a document, but you could reverse financial transactions / structure as escrow, and we know that having version control removes certain permanent loss scenarios.

Sometimes this may be just law. In the UK we have "direct debit" from accounts which fundamentally lets companies I approve take money from my account - as much as they choose. But the way of managing that risk is that banks will immediately and in full refund any money taken if I say so. Frankly lots of payment is the same online, we hand over enough information for the other party to take money from us, rather than explicitly sending it - with guarantees that we can get it back if it shouldn't have been allowed.