Sadly, skimming the docs about how the different backends work makes me think that almost this entire project was done by a recent-gen LLM that interpreted its instructions as “make these things work at all costs” instead of “make a considered design that cleanly and securely fits its use case”.
Even the bubblewrap integration docs are basically a stream of consciousness vibe splat. I have approximately zero confidence in the results.
I am really struggling to imagine the abstraction that maps well to both bubblewrap and hyperlight. (They’re both great projects. They solve different problems in different ways, although both fit with the word “sandbox”.)
I’m sure I could come up with an awkward abstraction, but bad abstractions are a bad way to build secure systems.
LLM-driven programming doesn't necessarily imply slop. I know some very good developers that use LLMs carefully. As a research tool, code reviewer, Q&A about a large codebase, error message decoder, bug-hunter, and for first-pass implementations. They're always on the newest models and they care about the craft.
Not everybody is oneshotting with Sonnet medium and pushing unreviewable code.
Even the bubblewrap integration docs are basically a stream of consciousness vibe splat. I have approximately zero confidence in the results.
(reposted from the other copy of basically this post: https://news.ycombinator.com/item?id=50026061)
I think it's a good idea to create such an abstraction, but it's still far away from a 1.0 release.
I’m sure I could come up with an awkward abstraction, but bad abstractions are a bad way to build secure systems.
Not everybody is oneshotting with Sonnet medium and pushing unreviewable code.
Maybe Microsoft can claim they have a cross-platform policy but I doubt people want to use it.
My comment on the other thread: https://news.ycombinator.com/item?id=50018898