Hacker News

Favorites Setup
Comment by Meleagris | original | Unikernels were hard. key word: were
[−]Meleagris · 2026-10-11 Sun 01:07 UTC · link
Totally agree with this article. With AI, I think now is the perfect time to consider where Unikernels might fit into your architecture, and how you can leverage them to minimize your attack surface.

I’ve started looking at them myself, and have been comparing them to mature VMMs like Firecracker, and asking myself where each piece of my stack might be best run.

Virtual machines and containers are no longer an effective isolation mechanism when AI is involved. VM breakouts are becoming trivial. So everyone should be considering how to bake better security into the their runtimes.

[−]lolakutty · 2026-10-11 Sun 06:36 UTC · link
>VM breakouts are becoming trivial.

How exactly?

[−]rfgplk · 2026-10-11 Sun 09:41 UTC · link
Most human written code (even when written by experts) is quite bad. Really bad actually. If you have a compliant agent (Daybreak/abliterated or otherwise) you can just provide them with a list of most likely VM escape routes and there's a ~100% chance they'll succeed unless the code has been explicitly pruned by an LLM prior.