4 ms·
That is completely insane. Getting root on one container = complete access to the entire system with administrator level access? What kind of security operation
by native_samples 5y ago
That is completely insane. Getting root on one container = complete access to the entire system with administrator level access? What kind of security operation are they running there exactly? Local root exploits aren't exactly unheard of, so you'd think the infrastructure would be designed to tolerate that sort of thing, not simply hand out private keys to management APIs to all and sundry.
- beardedwizard 5y agoWhat kind of development operation is the question I would ask. Security mostly involves convincing developers to do the right thing with a lot of resistance. Not sure I would assume the security team is behind this, rather than some "risk acceptance" forced on them to launch the feature on time.
- xbar 5y agoA close reading of the DevSecOps infinity lifecycle has lots of security+development touchpoints that yield better software security than this. The trade-off you mention is a management decision, not really a development or security decision.
- citizenpaul 5y agoTom This feature is due friday at 4pm but we want to review it so we need it done by lunch. Dont forget to make it secure. Sure its as secure as i was givem time to test security none and none. Thanks Tom great work. See ya at 12. This is more the reality than resistance.
- beardedwizard 5y agoWhy won't Tom include this in his estimates to begin with? Did Tom forget?