23 ms·
So I read something succinct a while back - docker et al are distribution platforms not security platforms . They add "0" security against an adversary (think p
by nunchuckninja 7y ago
So I read something succinct a while back - docker et al are distribution platforms not security platforms . They add "0" security against an adversary (think padlocks). How true is it ? And what high perf securely contained systems are there? OpenVZ?
- deleted 7y ago[deleted]
- upofadown 7y agoThe generic issue seems to be that stuff like containers can be escaped with pretty much any privilege escalation exploit ... and such exploits are reasonably common in the world of Linux.
- nunchuckninja 7y agoSo either take perf hit or don't expect isolation at all?
- dilyevsky 7y agoFor completely untrusted workloads basically - yeah. For semi-trusted, there’s lots of tech that provides reasonable, lightweight isolation. There’s no reason why hardware vendors cant ship products that are both virtualizable with high performance and secure, so that may still come.
- aritmo 7y agoBut if the container is unprivileged?
- naasking 7y agoSandstorm has had a pretty good track record [1]. Then again, it was designed and run by capability security folks, who take security pretty seriously. [1] https://sandstorm.io/ https://sandstorm.io/
- angry_octet 7y agoUnfortunately it is shutting down.
- naasking 7y agoAs a hosted service, yes. You can still self-host though.
- Spivak 7y agoI think the more correct statement is that “containers” (i.e processes running with some kernel namespacing features) don’t replace the need for existing security tools like seccomp, SELinux, apparmor. Namespacing is just another tool in your arsenal to help create some logical separation between security domains but you still likely need more to be sure that the separation is enforced. “Docker”, the tool that is slowly acquiring the ability to natively use all of these security tools and apply them to the containers it launches is/will be a security platform.