4 ms·
> a docker container can't be relied upon to contain arbitrary malware "to not contain"? Edit to contain (ahem!) the downvotes: I was genuinely confused by th
by scoot 3y ago
> a docker container can't be relied upon to contain arbitrary malware
"to not contain"?
Edit to contain (ahem!) the downvotes: I was genuinely confused by the ambiguous use of "contain", but comments below cleared that up.
- OscarCunningham 3y agoThey're using 'contain' to mean 'keep isolated'. If you put some malware in a docker container, you can't rely on docker to keep the rest of your system safe.
- FpUser 3y agoDoes the fact that docker runs as a root have something to do with it?
- progval 3y agoYes, but even rootless containers rely on user namespaces, which are a recurring source of privilege escalation vulnerabilities in Linux.
- insanitybit 3y agoThe issue of root vs rootless is unrelated to escaping the container. User namespaces lead to privescs because attackers who can enter a namespace and become the root within that namespace have access to kernel functionality that is far less hardened (because upstream has never considered root->kernel to be a privesc and, of course, most people focus on unprivileged user -> kernel privesc). The daemon running as root doesn't change anything there
- insanitybit 3y agoNo, it's because the malware would have direct access to the (privileged) Linux Kernel via system calls.
- scoot 3y agoGot it, thanks.
- quickthrower2 3y agoa docker image can’t be relied on to not contain malware and a docker container can’t be relied on to contain malware.