4 ms·
I'd rather run Docker as root than enable unprivileged user namespaces, security-wise.
by staticassertion 4y ago
I'd rather run Docker as root than enable unprivileged user namespaces, security-wise.
- kelnos 4y agoWhy, exactly? Personally I would trust the Linux kernel developers to find and fix security issues around unprivileged user namespaces much more than I trust the Docker team to build a secure product.
- staticassertion 4y ago> Personally I would trust the Linux kernel developers to find and fix security issues Yeah I highly recommend not having that view. Kernel upstream is the entire reason this problem exists - they spent decades downplaying and deriding security researchers who found root -> kernel privesc, and, in general, have had an incredibly hostile relationship with security professionals. I don't know the case with Docker as much but my impression is a lot more positive based on what I've seen - integration with Apparmor/SELinux, seccomp, memory safety, etc.