HNHacker News
TopNewBestAskShowJobs

ashahin

0 karma · joined October 27, 2025

submissionscomments
ashahin··on Codex just found a "workaround" of not having sudo on my PC
The "workaround" framing implies the docker-group trick is the issue. The deeper question: should agents be allowed to find ANY workaround around a permission boundary the user implicitly set by not granting sudo? Same blast radius whether it's docker, a setuid binary, or rewriting your scripts — needs to be flagged regardless of the specific trick.