8 ms·
But there are some environments where security is (almost) the only relevant factor, e.g. banking IT-infrastructure. I don't want my bank to pull arbitrary imag
by ThreeFx 7y ago
But there are some environments where security is (almost) the only relevant factor, e.g. banking IT-infrastructure. I don't want my bank to pull arbitrary images from Dockerhub because that increases their comfort.
Conversely, if I were sysadmin at a bank I would most definitely be concerned what was running in my network.
- buzzkillington 7y ago>Conversely, if I were sysadmin at a bank I would most definitely be concerned what was running in my network. I've worked at a bank. It's a docker file. Running Hadoop. On top of a Linux Container. Running in Rhel 5. On top of a vmware hypervisor.
- ownagefool 7y agoIn 2015 I was running docker containers for a Gov organisation, where: - docker containers were built from source - Dockerfile published with the code - Built in a new CI environment - Pushed, Pulled and deployed from the sha - Collecting network traffic, undertaking protective monitoring, that looks for those backdoors. Just because you can pull arbitrary bullshit doesn't mean you have to. Though for the record, the same sysadmins that whine about newer tools are generally the same ones that implicitly trust their older toolsets. Just because you can compile it, doesn't make it secure, so you need to be running monitoring solutions and hedging your bets no matter the tech.