3 ms·
Because almost every thing that Linux implements is poorly done. Let’s take the subject at hand. Containers. They never created containers. Instead they came up
by X86BSD 9y ago
Because almost every thing that Linux implements is poorly done. Let’s take the subject at hand. Containers. They never created containers. Instead they came up with docker. And never designed it to be secure. Hence all these efforts to figure out how to secure docker. They keep trying to retroactively bolt security on. Which is never going to secure it. Eventually someone’s going to have to throw it out and redo it with the initial goal of making it secure. When it should have been designed secure as the main feature. Like Zones or Jails were.
Also for sand boxing apps you really should look at CloudABI. Ed has put a ton of work into it.
The last time I looked at capsicum for Linux it wasn’t complete. That’s changed?