Hands-On Engineering Podcasts · August 2026

“If you have access to the Internet, you're not sandboxed.” — Hussein Nasser, The Backend Engineering Show with Hussein Nasser

Nasser is working through the report that OpenAI's agents found vulnerabilities in Hugging Face, and objecting to the word sandbox. His point is that a Kubernetes cluster with outbound internet access is one hop away from everything else, whatever it is called. He follows it with: Have you not heard of a DMZ before, guys?

The Backend Engineering Show with Hussein Nasser · 2026-08-23 Listen to the episode → More from Hussein Nasser →

Transcript

The Backend Engineering Show with Hussein Nasser Around 14:22 into the episode
Hussein Nasser

if they're acting like a worm or something, right? It's like, come on, talk

Speaker 2

technical, guys.

Hussein Nasser

Let's go technical. We're not scared of the technicalities. Be as technical as possible. Oh, just say, hey, we don't know. We don't know. That's fine. I don't know a lot of stuff. Most of the stuff, this is the first time I've seen a lot of this stuff. It's okay. Just say, I don't know. People will never say, I don't know. They will just lateral movement. Come on, seriously. Anyway, so that's, they create another container. Now I have full access. Now I have SSH. Yeah, it's looked like that. Is that what happened? Tell me I'm wrong. But that, when I have access to that, you can create another container. Now you have a full access to that. And just like that, you have full access to the internet. And now they started their attack on Hugging Face, which is another story. Apparently they left credentials out there in the internet and the agents found it. How secure is that? And use that credential and they started attacking the servers to log. In and they caused havoc on hugging face, and of course, that was blocked. And that was like another sell point. There's like, oh, we used our agents to block it because it was so disastrous. Oh, my God. So, yeah, that's the useful part that we gain: vulnerabilities, Linux escalation, that's good. SSRF, that's awesome. The escalation to get access to the Kubernetes cluster, to create another container or to access other containers that had access. That was awesome. And maybe I'm wrong about that part. It's either created another container or accessed the next container that has full access to the internet. But in summary, is this a sandbox, in your opinion? Having a Kubernetes cluster that has access to the Internet? In my opinion, that's not. If you have access to the Internet, you're not sandboxed. It's just like one hop. Have you not heard of a DMZ before, guys? Right? It's like this meme where we have, oh, agents broke out and there's this door with a Cheetos as a lock. That's exactly what it feels like. It's like, yeah, you put the Cheetos and the agents broke out. Of course they did. Oh my God. Yeah. So that. So there are some amazing things here, but I don't think any of this stuff a human couldn't have discovered. A human with deep security knowledge, they could have done the same thing, in my opinion. If you give them a box with access to another container that happened to have access to the internet, of course they would. They have their knowledge. I'd like to see a sandbox that create a Kubernetes cluster that has no access to the internet. How about that crazy idea? Put them there. You don't have access to the internet. Oh, but what if they want a package that is not access to the internet? Just download. Hey, you're allowed to use these packages. That's it. You're not allowed to use other packages. I don't know. Or create a package which has everything you need. I know this is not feasible, but sometimes you may need to make the problem harder, in my opinion. All right, so that's the summary. That's what we know. I might be wrong on some of the parts, but I'll reference the articles here. I might have missed something. Let me know. And yeah, agents will rule the world at the end of the day, as long as you give them access to the internet and make it so easy for them. See you in the next one.

Speaker names from our own diarization · position estimated from where the line sits in the episode