Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

More if you're running `provision --vm-name "$UserSuppliedData"` or similar. I don't know how you've built your wrapping tool, so I can't comment on how likely it would be, but I've seen such breakages IRL (I break things for a living ;) )


Good point, we do have things locked down pretty well in our go code though. The instances can only be provisioned using an API, and that API doesn't allow for arbitrary user-supplied input.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: