4 ms·
Docker is a rootkit over HTTP.
by codemac 11y ago
Docker is a rootkit over HTTP.
- voltagex_ 11y ago>A rootkit is a collection of computer software, typically malicious, designed to enable access to a computer or areas of its software that would not otherwise be allowed (for example, to an unauthorized user) while at the same time masking its existence or the existence of other software. Doesn't really describe Docker, does it?
- codemac 11y agoIt does if you're talking about `docker -d` and --privileged.
- KirinDave 11y agoRootkits hide themselves. Docker makes no effort to do so. I know you're trying to make joke, but it's not funny.
- codemac 11y agoThat's the joke, literally. This is a blog post about how docker is insecure when you can get root perms over a socket the docker daemon exports when you explicitly map it back into a docker container... as if it's unexpected when it's explicitly docker's design and the command line you provided. Oh well, I did think it was funny.
- totony 11y agoit hides in plain sight