3 ms·
> Whereas the way Docker is using Linux containers doesn't seem secure enough... Which is totally expected, because docker tries to be useful to the largest us
by skarap 11y ago
> Whereas the way Docker is using Linux containers doesn't seem secure enough...
Which is totally expected, because docker tries to be useful to the largest user-base possible. It would be quite harder to use if didn't support directory mounting (via -v). And it would be a total nightmare for almost every user if you had to specify a list of allowed syscalls for every container.
This reminds me the situation with SELinux a lot. It has improved a lot but I still see "disable SELinux" almost in every tutorial I read on CentOS, Fedora or RHEL.
- pjmlp 11y ago> This reminds me the situation with SELinux a lot. It has improved a lot but I still see "disable SELinux" almost in every tutorial I read on CentOS, Fedora or RHEL. Because security is hard. Just look at the Mac OS X users running as root and disabling Gatekeeper. Or the developers that stay away from the sandbox model. One of the nice things of mobile OSes is that there isn't a way around the container model. Although the history with permissions kind of messes it.