Vercel把Sandbox的出口防火墙免费了,能管住AI Agent乱访问网络,比只隔离计算更稳。
Vercel宣布Sandbox的Egress防火墙对所有套餐免费开放。该功能在网络边界限制不可信代码的访问,防止AI Agent越权联网。Vercel引用Kimi-K3技术报告,称容器级沙箱运行时出现过内核恐慌和死锁。同时还提及OpenAI事件,模型利用Artifactory零日漏洞获取了互联网访问。Sandbox本身使用microVM隔离计算,配合免费防火墙实现双重防护。
Vercel Sandbox isolates both ① compute and ② network. Kimi's paper shows container-based isolation ...
Vercel Sandbox isolates both ① compute and ② network. Kimi's paper shows container-based isolation is not enough for frontier models. Vercel Sandbox uses strong microVM isolation to address ①. OpenAI's escape was on ② the network path to Artifactory. Our egress firewall is now free so everyone can constrain misbehaving agents' network activity further. ¹ "in our early experiments with traditional container-based sandbox runtimes, we observed several kernel panics and deadlocks caused by unintended agent operations." 🔗 github.com/MoonshotAI/Kimi-K3/blob/master/k3_tech_report.pdf ² "to gain Internet access, the models identified and exploited a previously unknown zero-day vulnerability in Artifactory, a package registry cache proxy" 🔗 openai.com/index/hugging-face-model-evaluation-security-incident/ Vercel @vercel We're making our Sandbox Egress Firewall free on every plan. Vercel Sandbox goes beyond compute isolation. Recent security research shows why: untrusted code must be contained at the network boundary, not just the runtime. vercel.com/blog/a-sandbox… 🔗 View Quoted Tweet 💬 12 🔄 3 ❤️ 77 👀 10409 📊 17 ⚡