If you really wanted to sandbox a machine you’d offline cache the packages and not give it any physical route to the internet, not via a jump box, not via a proxy, nothing.
This was poorly executed.
This was poorly executed.
It seems like whatever virtualized sandboxes they have are not enough. But it’s equally hard to imagine their SWEs jumping on a plane to a data center to do this work locally
You can take far greater measures to lock down external traffic than just that.
An offline package cache (aka artifactory WITHOUT its own internet access) likely would have precluded this whole thing.
Air gapped environments are nothing new and they're standard practice for sensitive applications.