<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: ushakov</title><link>https://news.ycombinator.com/user?id=ushakov</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 09 Apr 2026 12:09:43 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=ushakov" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by ushakov in "Ggml.ai joins Hugging Face to ensure the long-term progress of Local AI"]]></title><description><![CDATA[
<p>the code is not public, so we can't know. i think it's much more nuanced and certain users' comments might get a preferential treatment, based on factors other than the upvote count - which itself is hidden from us.</p>
]]></description><pubDate>Fri, 20 Feb 2026 20:16:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=47093318</link><dc:creator>ushakov</dc:creator><comments>https://news.ycombinator.com/item?id=47093318</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47093318</guid></item><item><title><![CDATA[New comment by ushakov in "Ggml.ai joins Hugging Face to ensure the long-term progress of Local AI"]]></title><description><![CDATA[
<p>of course your comment attracts more upvotes - it's at the top.</p>
]]></description><pubDate>Fri, 20 Feb 2026 18:18:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=47091663</link><dc:creator>ushakov</dc:creator><comments>https://news.ycombinator.com/item?id=47091663</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47091663</guid></item><item><title><![CDATA[New comment by ushakov in "Ggml.ai joins Hugging Face to ensure the long-term progress of Local AI"]]></title><description><![CDATA[
<p>i don't doubt this. i just find it questionable that one particular poster always gets in the spotlight when AI is the topic - while other conversations in my opinion offer more interesting angles.</p>
]]></description><pubDate>Fri, 20 Feb 2026 18:10:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=47091552</link><dc:creator>ushakov</dc:creator><comments>https://news.ycombinator.com/item?id=47091552</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47091552</guid></item><item><title><![CDATA[New comment by ushakov in "Ggml.ai joins Hugging Face to ensure the long-term progress of Local AI"]]></title><description><![CDATA[
<p>i am curious, why are your comments always pinned to the top?</p>
]]></description><pubDate>Fri, 20 Feb 2026 17:58:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=47091408</link><dc:creator>ushakov</dc:creator><comments>https://news.ycombinator.com/item?id=47091408</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47091408</guid></item><item><title><![CDATA[New comment by ushakov in "AWS Adds support for nested virtualization"]]></title><description><![CDATA[
<p>We are running Sandboxes for AI Agents using Firecracker microVMS @ E2B</p>
]]></description><pubDate>Fri, 13 Feb 2026 15:37:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=47003898</link><dc:creator>ushakov</dc:creator><comments>https://news.ycombinator.com/item?id=47003898</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47003898</guid></item><item><title><![CDATA[New comment by ushakov in "Ex-GitHub CEO launches a new developer platform for AI agents"]]></title><description><![CDATA[
<p>$1.5M seed bets, maybe. not $60M though</p>
]]></description><pubDate>Tue, 10 Feb 2026 23:57:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=46968844</link><dc:creator>ushakov</dc:creator><comments>https://news.ycombinator.com/item?id=46968844</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46968844</guid></item><item><title><![CDATA[New comment by ushakov in "Matchlock – Secures AI agent workloads with a Linux-based sandbox"]]></title><description><![CDATA[
<p>just from looking at it<p>on Linux it runs Firecracker:
<a href="https://github.com/jingkaihe/matchlock/blob/main/pkg/vm/linux/backend.go#L107-L110" rel="nofollow">https://github.com/jingkaihe/matchlock/blob/main/pkg/vm/linu...</a><p>on macOS uses the Apple's Virtualization.Framework Go wrapper:
<a href="https://github.com/jingkaihe/matchlock/blob/main/pkg/vm/darwin/backend.go#L12" rel="nofollow">https://github.com/jingkaihe/matchlock/blob/main/pkg/vm/darw...</a></p>
]]></description><pubDate>Sun, 08 Feb 2026 13:29:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=46934023</link><dc:creator>ushakov</dc:creator><comments>https://news.ycombinator.com/item?id=46934023</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46934023</guid></item><item><title><![CDATA[Almostnode – Node.js in the Browser]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/macaly/almostnode">https://github.com/macaly/almostnode</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46933982">https://news.ycombinator.com/item?id=46933982</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Sun, 08 Feb 2026 13:23:43 +0000</pubDate><link>https://github.com/macaly/almostnode</link><dc:creator>ushakov</dc:creator><comments>https://news.ycombinator.com/item?id=46933982</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46933982</guid></item><item><title><![CDATA[New comment by ushakov in "Matchlock – Secures AI agent workloads with a Linux-based sandbox"]]></title><description><![CDATA[
<p>very cool, if you want cross-platform microvms, there's an interesting project called libkrun that powers projects like Podman and Colima.<p>here's a Go binding:
<a href="https://github.com/mishushakov/libkrun-go" rel="nofollow">https://github.com/mishushakov/libkrun-go</a><p>demo (on Mac):
<a href="https://x.com/mishushakov/status/2020236380572643720" rel="nofollow">https://x.com/mishushakov/status/2020236380572643720</a></p>
]]></description><pubDate>Sun, 08 Feb 2026 12:08:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=46933574</link><dc:creator>ushakov</dc:creator><comments>https://news.ycombinator.com/item?id=46933574</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46933574</guid></item><item><title><![CDATA[New comment by ushakov in "Monty: A minimal, secure Python interpreter written in Rust for use by AI"]]></title><description><![CDATA[
<p>i think there’s a confusion around what use-case Monty is solving (i was confused as well). this seems to isolate in a scope of execution like function calls, not entire Python  applications</p>
]]></description><pubDate>Sat, 07 Feb 2026 01:48:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=46920508</link><dc:creator>ushakov</dc:creator><comments>https://news.ycombinator.com/item?id=46920508</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46920508</guid></item><item><title><![CDATA[New comment by ushakov in "Monty: A minimal, secure Python interpreter written in Rust for use by AI"]]></title><description><![CDATA[
<p>we’re not disagreeing here - i meant for general use-case VMs are better, for some application-specific calls Monty this might suffice.<p>although you’d still need another boundary to run your app in to prevent breaking out to other tenants.</p>
]]></description><pubDate>Sat, 07 Feb 2026 01:46:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=46920495</link><dc:creator>ushakov</dc:creator><comments>https://news.ycombinator.com/item?id=46920495</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46920495</guid></item><item><title><![CDATA[New comment by ushakov in "Monty: A minimal, secure Python interpreter written in Rust for use by AI"]]></title><description><![CDATA[
<p>agree. you still need a secure boundary like VM to isolate the tenants in case the model breaks out of the sandbox.<p>everything that you don’t want your agent to access should live outside of the sandbox.</p>
]]></description><pubDate>Sat, 07 Feb 2026 01:32:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=46920399</link><dc:creator>ushakov</dc:creator><comments>https://news.ycombinator.com/item?id=46920399</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46920399</guid></item><item><title><![CDATA[New comment by ushakov in "Monty: A minimal, secure Python interpreter written in Rust for use by AI"]]></title><description><![CDATA[
<p>best answer is probably to have a layered approach - use this to limit what the generated code can do, wrap it in a secure VM to prevent leaking out to other tenants.</p>
]]></description><pubDate>Sat, 07 Feb 2026 01:23:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=46920355</link><dc:creator>ushakov</dc:creator><comments>https://news.ycombinator.com/item?id=46920355</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46920355</guid></item><item><title><![CDATA[New comment by ushakov in "Monty: A minimal, secure Python interpreter written in Rust for use by AI"]]></title><description><![CDATA[
<p>there’s no way around VMs for secure, untrusted workloads. everything else, like Monty has too many tradeoffs that makes it non-viable for any real workloads<p>disclaimer: i work at E2B, opinions my own</p>
]]></description><pubDate>Sat, 07 Feb 2026 01:19:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=46920338</link><dc:creator>ushakov</dc:creator><comments>https://news.ycombinator.com/item?id=46920338</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46920338</guid></item><item><title><![CDATA[New comment by ushakov in "Deno Sandbox"]]></title><description><![CDATA[
<p>Factory, Nvidia, Perplexity and Manus are using E2B in production - we ran more than  200 million Sandboxes for our customers</p>
]]></description><pubDate>Tue, 03 Feb 2026 22:21:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=46878179</link><dc:creator>ushakov</dc:creator><comments>https://news.ycombinator.com/item?id=46878179</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46878179</guid></item><item><title><![CDATA[New comment by ushakov in "Sandboxing AI Agents in Linux"]]></title><description><![CDATA[
<p>for personal use, many ways: Vargant, Docker Sandbox, NixOS VMs, Lima, OrbStack.<p>if you want multi-tenant: E2B (open-source, self-hosted)</p>
]]></description><pubDate>Tue, 03 Feb 2026 21:46:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=46877774</link><dc:creator>ushakov</dc:creator><comments>https://news.ycombinator.com/item?id=46877774</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46877774</guid></item><item><title><![CDATA[New comment by ushakov in "Deno Sandbox"]]></title><description><![CDATA[
<p>we aren’t worried about that.<p>when we were starting out we figured there was no solution that would satisfy our requirements for running untrusted code. so we had to build our own.<p>the reason we open-sourced this is because we want everyone to be able to run our Sandboxes - in contrast to the majority of our competitors who’s goal is to lock you in to their offering.<p>with open-source you have the choice, and luckily Manus, Perplexity, Nvidia choose us for their workloads.<p>(opinions my own)</p>
]]></description><pubDate>Tue, 03 Feb 2026 21:30:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=46877569</link><dc:creator>ushakov</dc:creator><comments>https://news.ycombinator.com/item?id=46877569</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46877569</guid></item><item><title><![CDATA[New comment by ushakov in "Deno Sandbox"]]></title><description><![CDATA[
<p>we offer secure cloud VMs that scale up to 100k concurrent instances or more.<p>the value we sell with our cloud is scale, while our Sandboxes are a commodity that we have proudly open-sourced</p>
]]></description><pubDate>Tue, 03 Feb 2026 20:56:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=46877182</link><dc:creator>ushakov</dc:creator><comments>https://news.ycombinator.com/item?id=46877182</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46877182</guid></item><item><title><![CDATA[New comment by ushakov in "Sandboxing AI Agents in Linux"]]></title><description><![CDATA[
<p>both Docker and bubblewrap are not secure sandboxes. the only way to have actually isolated sandboxes is by using VMs<p>disclaimer: i work on secure sandboxes at E2B</p>
]]></description><pubDate>Tue, 03 Feb 2026 20:51:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=46877098</link><dc:creator>ushakov</dc:creator><comments>https://news.ycombinator.com/item?id=46877098</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46877098</guid></item><item><title><![CDATA[New comment by ushakov in "Deno Sandbox"]]></title><description><![CDATA[
<p>10 seconds is actually not that impressive. we spin up Sandboxes around 50-200ms at E2B</p>
]]></description><pubDate>Tue, 03 Feb 2026 20:39:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=46876945</link><dc:creator>ushakov</dc:creator><comments>https://news.ycombinator.com/item?id=46876945</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46876945</guid></item></channel></rss>