3 ms·
It certainly depends how your company views its risks and how docker fits into their “threat model” - you’re running someone else’s code on your secure internal
by graystevens 8y ago
It certainly depends how your company views its risks and how docker fits into their “threat model” - you’re running someone else’s code on your secure internal networks, so it should be treated like external/unauthorised software.
It’s not unheard of for Docker images to be backdoored or tampered with, just look at last month - https://arstechnica.com/information-technology/2018/06/backdoored-images-downloaded-5-million-times-finally-removed-from-docker-hub/ https://arstechnica.com/information-technology/2018/06/backd...
If they’re trivial images, maybe mirror them internally and walk through their internals if that doesn’t consume too much time.