6 ms·
Why are they not?
by someuname 5y ago
Why are they not?
- dastbe 5y agonot the op but aws made the same determination. the tl;dr is that the surface area of containerization leads to an unacceptable risk of privilege escalation.
- someuname 5y agoThat explains what, but not why
- withinboredom 5y agoBecause if you can get root in a container, you have root outside the container. While escaping a container isn’t exactly easy or always possible, it is a huge risk.
- native_samples 5y agoContainers were never actually designed to be sandboxes, and inside you have access to many system calls and a comparatively huge surface area inside the kernel and userland, all written in C, with a long history of local root exploits due to C based bugs.