Skip to content

Comment on We eliminated 1,400 CVEs in NanoClaw's container imagesparent

Comments

I'm pretty skeptical you can call any claw-like thing secure unless you solve prompt injection.

Security isn't binary. There's nothing that's "secure" unless you define a threat model first.

Sounds like the kind of stuff devs that introduce security vulnerbilities say.

if you can't define a threat model, or know why you need one, you will write vulnerable code.

Unrelatedly, I wonder why I don't see the downvote arrows on comments any more.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.