• Skip to main content
  • Skip to secondary menu
  • Skip to footer

Technologies.org

Technology Trends: Follow the Money

  • Technology Events 2026-2027
  • Sponsored Post
  • Technology Markets
  • About
    • GDPR
  • Contact

VPN Works: Uses Linux Network Namespaces to Isolate and Log Every Connection From an Agent

October 2, 2026 By admin

A coding agent reads text written by strangers: issues on your tracker, code from repositories, instructions on web pages. One malicious instruction can make the agent send credentials somewhere it shouldn’t. On a machine-wide VPN, that request leaves the same way as everything else, and afterwards nobody can say which program sent it or where it went.

VPN Works uses Linux network namespaces to seal an agent in its own network. The agent’s only way out is through vpnw itself, so a script that ignores proxy settings finds no route anywhere. Every connection is checked against a policy and logged.

The technical innovation is policy-based isolation without virtualization overhead. A namespace is lightweight—you’re not spinning up containers. You’re carving out a network view that the agent sees but the rest of your system doesn’t. Connections are enforced at the kernel level, so the policy can’t be circumvented by userspace trickery.

Day to day it comes down to four commands. run picks the outbound path and starts the program. trace prints every connection. guard enforces a policy. learn drafts a policy from a traced run.

The technical appeal of learn is that it inverts the security model. Instead of writing a policy from scratch, you observe normal behavior and carve out the exceptions. Under a default-deny policy, a hostname that isn’t allowed is never even looked up by DNS, so DNS itself can’t leak data. Every connection is logged, so you have a record.

There’s a second engine. Scope brings the same idea to the company VPN. It learns from traffic who uses which systems inside your network and drafts least-privilege rules for the gateway.

Both are Alphas, tested on Linux. The live demo replays real runs of an agent trying to leak a token, and you can edit the policy against the real engine, compiled to WebAssembly. How It Works covers the sandbox in detail.

The technical appeal is that security becomes local and observable. You’re not trusting a remote service to enforce policy. You’re enforcing it at the machine where the code runs, and you have a log of every decision. The innovation is making default-deny practical for development without requiring infrastructure expertise or central gatekeeper.

Filed Under: News

Footer

Recent Posts

  • AltSql: An Embedded Database Engine That Syncs Devices and Gateways Without Conflicts
  • VPN Works: Uses Linux Network Namespaces to Isolate and Log Every Connection From an Agent
  • Precomputing: Materializes Dashboard Answers With SQLite Triggers as Data Arrives
  • Preconfiguration: Generates Reproducible Setup Across Multiple Cloud Platforms From One Spec
  • BareProxy: A Go Reverse Proxy That Makes Routing Decisions Explainable
  • AI Infrastructure Moves Beyond GPUs as Billions Flow Into Interconnects, Cloud, Robotics and Agent Systems
  • Supermicro Is Now Shipping NVIDIA Vera Rubin NVL72 Racks, With 1,152-GPU Scalable Units Ready to Order
  • Synopsys and TSMC Certify A14 Design Flows and Roll Out Agentic AI Chip Design Tools
  • Bird.com Secures $450M in Debt Financing and Opens Its Messaging Network to AI Agents
  • Meta AI Glasses Become the First Consumer Device to Record Dolby Atmos Audio

Media Partners

  • Market Analysis
  • Cybersecurity Market
  • App Coding
An AI Lab Is Paying Up Front for Atlas Energy’s (AESI) Generators as Agentic AI Multiplies Token Demand
Oracle’s Force Majeure Notice on Project Jupiter Shows Where AI Data Center Risk Is Landing
AI Infrastructure Credit Costs Rise as CoreWeave-Tied Bonds Price at 9.25% and China Chipmaker Profits Jump 620%
OpenAI and Anthropic Cut AI Model Prices as $1.75B in Funding Flows to Data, Security and Infrastructure
Semiconductor Revenue Hits Record $425B in Q2 2026, but Omdia’s $500B Q3 Forecast Implies Growth Halves
AI Extinction Warnings Went Global in Six Days. Nothing in the Technology Changed.
Anthropic Walks Away From $6 Billion Decart Acquisition: The Deal Was About Inference Cost, Not World Models
VR Status Report 2026: Quest Sales Keep Falling While Smart Glasses Take the Money
The Case That the US Can Grow Out of $40 Trillion in Debt: Three Conditions the Clinton Surpluses Actually Met
The $40 Trillion Debt: Why AI Capex Raises Treasury Borrowing Costs Faster Than It Raises the Tax Base
Cybersecurity Weekly: Zero-Days Hit the Internet’s Defensive Edge as AI Starts Changing the Attack Cycle
Trust Only Software That Can Explain Itself
Zenity AI Agent Security Summit New York 2026, October 21, Pier Sixty, New York
Zenity AI Agent Security Summit London 2026, October 8, 8 Bishopsgate, London
SecTor 2026, October 6–8, Metro Toronto Convention Centre, Toronto
Cyera Takes $400 Million From Goldman Sachs, Pushing Its 2026 Funding to $1.4 Billion
Visa Buys BioCatch, Munich Re Buys At-Bay: The Biggest Cybersecurity Buyers Aren’t Security Companies
Flock Safety Cameras Run Android 8.1 With Hardcoded API Keys, Researchers Find
Brevo Supply Chain Attack Pushed ClickFix Malware to 100,000 Sites Through One Hardcoded Cloudflare Key
FBI and Coast Guard Boarded Hacked Oil Tankers, and Maritime OT Security Became a Budget Line
AltSql: Gives IoT Devices a 15 KB Database That Keeps Working When the Link Drops
BareProxy: A Small Go Web Server and Reverse Proxy That Explains Every Routing Decision
Precomputing: Keeps Dashboard Answers Ready in a SQLite File as the Data Arrives
Preconfiguration: Writes Coding Agent Setup Files From One Spec and Tests Them on a Clean Machine
VPN Works: Gives Each AI Agent Its Own Network and a Record of Every Connection
Cloudflare Worker Previews Setup: Which Bindings Isolate Per Branch and Which You Configure Yourself
Nine Apps Worth Coding, and the Hard Part Buried in Each One
Application Performance Optimization: Where Most Teams Waste Their Time
AI App Builders by Use Case: Lovable, Bolt.new, Replit Agent, Softr, FlutterFlow and v0
AI App Builders Reviewed: Lovable, Base44, Bolt, Replit and v0 Compared

Media Partners

  • Market Research Media
  • Technology Conferences
  • API Coding
The Economist Is Right About a Million AI Jobs. It’s a Construction Boom, Not a Tech Boom.
AI Slop Earns Higher CPMs Than Clean Inventory: Why the Ad Market Cannot Fix the Web It Funds
Weekly Network Analytics, July 19 to July 25, 2026: Visits Up 14%
Adobe (ADBE) and Figma (FIG) Have Each Lost Roughly Half Their Value to a Competitor Set Worth $34 Million
Getty Images Kills the $3.7 Billion Shutterstock Merger Rather Than Sell the Editorial Business the UK Demanded
Fox’s $22B Roku Deal: 4.6x Sales, Paid in 1.5x Stock
Tuesday Open: AI Earnings Engine Holds the Line as Iran Overhang Fades to Noise
China’s U.S. Treasury Holdings: The Great Repositioning (2021–2025)
Infographic: Why the 2025 CIPA Data Proves the APS-C Renaissance is Real
How WiFi Changed Media
JNUC 2026, September 23–25, Kansas City Convention Center, Kansas City
Startup World Cup Grand Finale 2026, November 4–6, Hilton San Francisco Union Square, San Francisco
FYUZ 2026, November 3–5, The Westin Seattle, Seattle
ONUG AI Networking Summit 2026, October 28–29, Penn District, New York
Networking Field Day 2026, October 6–9, San Jose
Nova Future Summit 2026, September 28–30, Napa
Breakbulk Americas 2026, September 22–23, George R. Brown Convention Center, Houston
Gartner CIO & IT Executive Conference 2026, September 21–23, Sheraton São Paulo WTC Hotel, São Paulo
ITC Vegas 2026, September 29–October 1, Mandalay Bay, Las Vegas
Sidoti Small-Cap Virtual Conference: September 23-24, Online
Audit an API Field's Completeness Before You Build a Feature on It
Caching a Third-Party API Response in a Cloudflare Pages Function
Fetching a Remote JSON API at Build Time in Hugo with resources.GetRemote
GBIF's API Returns CC BY-NC Images by Default, Which Breaks Commercial Use
Querying USAspending for Federal Contract Awards With a POST Search and No API Key
Reading the Launch Library API for Rocket Launch Schedules Without a Key
API Monetization Models: How Companies Actually Charge for Access
API Testing Strategies: What to Test and When
AI Platforms for Designing APIs in 2026: Spec Editors, SDK Generators, MCP Builders and AI Gateways Reviewed
Every Accident in Your API Becomes a Contract

Copyright © 2026 Technologies.org

Media Partners: Market Analysis · Market Research · Referently · Photography