<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: ashahin</title><link>https://news.ycombinator.com/user?id=ashahin</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 01 Jun 2026 21:28:28 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=ashahin" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by ashahin in "Codex just found a "workaround" of not having sudo on my PC"]]></title><description><![CDATA[
<p>The "workaround" framing implies the docker-group trick is the issue. The deeper question: should agents be allowed to find ANY workaround around a permission boundary the user implicitly set by not granting sudo? Same blast radius whether it's docker, a setuid binary, or rewriting your scripts — needs to be flagged regardless of the specific trick.</p>
]]></description><pubDate>Sun, 31 May 2026 23:33:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=48350891</link><dc:creator>ashahin</dc:creator><comments>https://news.ycombinator.com/item?id=48350891</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48350891</guid></item></channel></rss>