3 ms·
"Docker is not an acceptable security solution for this, since it's most certainly possible to break out of containers." Could you point to some resources that
by dhaivatpandya 10y ago
"Docker is not an acceptable security solution for this, since it's most certainly possible to break out of containers."
Could you point to some resources that show that it is possible to break out of Docker containers? I understand that there have been bugs in the past that have caused this (using that to conclude that glot.io shouldn't use Docker is a bit like saying OpenSSL is now useless because of heartbleed) but it seems unlikely that breaking out of containers is possible due to the way Docker is designed.
- seanp2k2 10y agohttp://www.cvedetails.com/product/28125/Docker-Docker.html?vendor_id=13534 http://www.cvedetails.com/product/28125/Docker-Docker.html?v... https://github.com/docker/docker/issues/12317 https://github.com/docker/docker/issues/12317 https://github.com/gabrtv/shocker https://github.com/gabrtv/shocker https://www.oreilly.com/ideas/docker-security https://www.oreilly.com/ideas/docker-security I'm sure there will be more Edit: yup, as cited below: https://conference.hitb.org/hitbsecconf2016ams/sessions/escape-from-the-docker-kvm-qemu-machine/ https://conference.hitb.org/hitbsecconf2016ams/sessions/esca...
- cyphar 10y agoMost of the vulnerabilities you mention are actually kernel vulnerabilities. While they affect Docker, they more accurately affect everything that uses "Linux containers". Although, Docker did have a bad history of security bugs with symlinks. But given the fact that Linux doesn't have real containers, I feel very conflicted about opening that up to the internet.
- vellum 10y agohttps://www.nccgroup.trust/globalassets/our-research/us/whitepapers/2016/april/ncc_group_understanding_hardening_linux_containers-10pdf/ https://www.nccgroup.trust/globalassets/our-research/us/whit...