5 ms·
The point of smaller images to me isn't about disk savings as much as minimizing dependencies and surface area of attacks such as for glibc, bash, and OpenSSL i
by devonkim 9y ago
The point of smaller images to me isn't about disk savings as much as minimizing dependencies and surface area of attacks such as for glibc, bash, and OpenSSL in the past several years. Updating container images quickly is absolutely essential given the myriad of possible problems if they were to become stale.
I suppose it wouldn't hurt to have smaller image layers when updating these containers more frequently to save on bandwidth at least.
- peterwwillis 9y agoReducing attack surface by only minimizing dependencies is a bit like putting your house on stilts.
- ridruejo 9y agoCan you elaborate why you think that is the case? This is a well-established security practice. I don't see much upside to having code or binaries around that are not needed but can be potentially exploited. One of the first things I did when I used to manage servers was shutdown and remove any services not needed, disable all Apache modules not in use, etc.
- peterwwillis 9y agoA house on stilts makes it difficult to rob, but not for the man who walks on stilts. Security practices need to be implemented holistically or they are easily defeated. By themselves they aren't worth much and end up being unnecessarily cumbersome. Removing outlying code that could be used as part of an attack can be useful for complex attacks. But they are essentially outliers - the actual code that you are actually running and is the actual target is still there, waiting to be pwnd. The time you spend trimming fat can often be better used to actually harden a system's access control or policies/procedures, perform auditing, etc.
- wvenable 9y agoYou're arguing a straw man by putting the word only in there.
- peterwwillis 9y agoThe author said 3 different things in their comment. I was answering this: "The point [..] isn't about disk savings as much as minimizing dependencies and surface area of attacks such as for glibc, bash, and OpenSSL in the past several years." Technically they didn't say specifically how they would minimize surface area of attacks, so my assumption that they meant only by minimizing dependencies (seeing as their comment was followed by a list of dependencies) may have been faulty. Thanks for letting me know that in such a kind way.