Tagged articles

landlock

2 articles · Page 1 of 1
Tech Musings
Tech Musings
Aug 31, 2026 · Cloud Native

Securing DeepSeek Harness in Multi-Tenant Containers: Removing Filesystem Plugins to Reduce Attack Surface

The author details removing filesystem tool plugins from DeepSeek Harness (DSH) to secure multi-tenant container deployments, covering plugin architecture, overlay-based disabling, impact on 6 tools, real-model attack testing showing bash as a residual channel mitigated by sandbox fail-closed behavior, and resource metrics showing negligible savings.

Attack SurfaceDeepSeek HarnessPlugin Architecture
0 likes · 15 min read
Securing DeepSeek Harness in Multi-Tenant Containers: Removing Filesystem Plugins to Reduce Attack Surface
Linux Kernel Journey
Linux Kernel Journey
Apr 9, 2026 · Information Security

Why Traditional AI Agent Sandboxes Fail and How Sandlock Provides a Lightweight Alternative

The article argues that heavy container‑ or micro‑VM‑based sandboxes mis‑solve AI agent security, because the real threat is prompt injection at the application layer, and demonstrates that a policy‑first approach using Linux Landlock, seccomp and per‑tool isolation—embodied in the open‑source Sandlock sandbox—delivers strong protection without root or heavyweight isolation.

AI AgentsLinuxPolicy
0 likes · 15 min read
Why Traditional AI Agent Sandboxes Fail and How Sandlock Provides a Lightweight Alternative