Commenters debated Microsoft's Mxc execution containers as a response to agent containment, with several arguing it doesn't address the deeper permissioning mess. Moomin said the industry has become “ridiculously bad” at permissioning and warned Mxc risks adding complexity across identity and resource models; Joker_vD questioned whether an agent can be its own security principal and criticized the announcement as sloppy. 3eb7988a1663 asked if Mxc can serve as a general app-permissions boundary or will be limited to labeled “agents,” and expressed suspicion that advanced controls will be gated to corporate customers. Esafak pressed for clarity on where the security principal is configured.
Other commenters were more practical or upbeat: chris_money202 predicted enterprise demand, while freeone3000 noted Windows already offers user- and API-level RBAC and wondered what’s new. Tomrod described existing mitigation patterns - running agents as untrusted users, using Firecracker, and wanting a Vault-like local secret broker - and mentioned VS Code workspaces as a partial shortcut. Tuwtuwtuwtuw and others raised integration questions for dev containers and package operations. A few responses were dismissive or jokey (DeepYogurt, edoceo). The split centers on whether Mxc is useful incremental tooling for enterprises or a superficial answer that fails to rethink foundational security and consumer access.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.