<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: molson8472</title><link>https://news.ycombinator.com/user?id=molson8472</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Fri, 05 Jun 2026 04:25:03 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=molson8472" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by molson8472 in "Running Claude Code dangerously (safely)"]]></title><description><![CDATA[
<p>Once approval fatigue and ongoing permission management kicks in, the temptation is strong to run `--dangerously-skip-permissions`. I think that's what we all want - run agents in a locked-down sandbox where the blast radius of mistakes and/or prompt injection attacks is minimal/acceptable.<p>I started running Claude Code in a devcontainer with limited file access (repo only) and limited outbound network access (allowlist only) for that reason.<p>This weekend, I generalized this to work with docker compose. Next up is support for additional agents (Codex, OpenCode, etc). After that, I'd like to force all network access through a proxy running on the host for greater control and logging (currently it uses iptables rules).<p>This workflow has been working well for me so far.<p>Still fresh, so may be rough around the edges, but check it out: <a href="https://github.com/mattolson/agent-sandbox" rel="nofollow">https://github.com/mattolson/agent-sandbox</a></p>
]]></description><pubDate>Tue, 20 Jan 2026 17:17:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=46694641</link><dc:creator>molson8472</dc:creator><comments>https://news.ycombinator.com/item?id=46694641</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46694641</guid></item><item><title><![CDATA[New comment by molson8472 in "Crystal 0.29"]]></title><description><![CDATA[
<p>I must have been living under a rock for the past five years, because Crystal went completely unnoticed until last week. As a long time Ruby programmer, I'm eager to give it a try.</p>
]]></description><pubDate>Thu, 06 Jun 2019 01:17:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=20110705</link><dc:creator>molson8472</dc:creator><comments>https://news.ycombinator.com/item?id=20110705</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=20110705</guid></item><item><title><![CDATA[New comment by molson8472 in "How the Valley treats experienced people"]]></title><description><![CDATA[
<p>Nailed it.</p>
]]></description><pubDate>Sun, 30 Dec 2018 17:28:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=18790217</link><dc:creator>molson8472</dc:creator><comments>https://news.ycombinator.com/item?id=18790217</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=18790217</guid></item><item><title><![CDATA[Show HN: Pollse, our weekend Rails Rumble submission]]></title><description><![CDATA[
<p>Article URL: <a href="http://tectonics.r13.railsrumble.com/">http://tectonics.r13.railsrumble.com/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=6586601">https://news.ycombinator.com/item?id=6586601</a></p>
<p>Points: 2</p>
<p># Comments: 1</p>
]]></description><pubDate>Mon, 21 Oct 2013 16:33:31 +0000</pubDate><link>http://tectonics.r13.railsrumble.com/</link><dc:creator>molson8472</dc:creator><comments>https://news.ycombinator.com/item?id=6586601</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=6586601</guid></item><item><title><![CDATA[New comment by molson8472 in "Software Development Estimates: Where Do I Start?"]]></title><description><![CDATA[
<p>I really like this statement: "Every new piece of software is a machine that has never been built before. The process of describing how the machine works is the same as building the machine."<p>That's probably the best way of relating the problem to non-engineers that I've heard.</p>
]]></description><pubDate>Mon, 16 Sep 2013 05:35:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=6391819</link><dc:creator>molson8472</dc:creator><comments>https://news.ycombinator.com/item?id=6391819</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=6391819</guid></item><item><title><![CDATA[Nothing To Hide? Good, Because You Can't.]]></title><description><![CDATA[
<p>Article URL: <a href="https://medium.com/surveillance-state/6957a3ef4139">https://medium.com/surveillance-state/6957a3ef4139</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=5906663">https://news.ycombinator.com/item?id=5906663</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 19 Jun 2013 16:51:19 +0000</pubDate><link>https://medium.com/surveillance-state/6957a3ef4139</link><dc:creator>molson8472</dc:creator><comments>https://news.ycombinator.com/item?id=5906663</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=5906663</guid></item></channel></rss>