3 ms·
"A malicious container running on a Docker-run host is deployed and ran" A most relevant question being, how does this "malicious container" get onto the host
by trynton 6y ago
"A malicious container running on a Docker-run host is deployed and ran"
A most relevant question being, how does this "malicious container" get onto the host in the first place?
- orra 6y agoCloud hosting... if you're on the same physical node as a malicious actor, then ouch.
- AnHonestComment 6y agoDon’t most cloud hosts layer VMs between customers? Ie, for cloud physical server A, customer 1 and customer 2 have different VMs as their Docker host.
- ta988 6y agoDid you ever see cloud hosting where you can run privileged containers on a shared machine?
- orra 6y agoPrivileged? Maybe not. But in general, Docker is not a security boundary, but people treat it like one.
- krab 6y agoThe services I have experience with host containers on a VM that is not shared between customers.
- orra 6y agoThat's good. But I don't think the major cloud providers make it very obviously, either way. And when something's not clear, often the answer isn't good.
- rodgerd 6y agoYou might be surprised by the number of developers who get really upset if their workplace doesn't allow "pull random containers off the Internet" as part of their workflow.
- piaste 6y agoWell if you don't want to let devs run arbitrary code off the internet on their machines, that cuts off more than Docker Hub, it cuts off almost every package manager under the sun. If I had to work under such a restriction, I would ask for a cheap spare machine, running on a guest network and hosting no sensitive code, where I could download and try random packages off the internet before I could submit them for audit, approval and vendoring.