4 ms·
Yeah, a lot of the Linux kernel code was reachable by root, and for a long time the attitude of a lot of kernel maintainers was that privesc from root didn't ma
by staticassertion 5y ago
Yeah, a lot of the Linux kernel code was reachable by root, and for a long time the attitude of a lot of kernel maintainers was that privesc from root didn't matter much.
But now any code can be root in its own namespace... so all of this code that's far less scrutinized is now reachable.
- boring_twenties 5y agoExactly the main argument that was being made against enabling this by default all those years ago.
- octoberfranklin 5y agoIndeed, this is exactly why containers are not a security feature. Counterintuitively, using containers makes your system less secure because you have to expose this huge kernel attack surface to non-root users.
- deleted 5y ago[deleted]