3 ms·
> Memory safety is the primary issue with containers as a security boundary. I don't know where you're getting your information, but this is NOT the consensus
by t8sr 3y ago
> Memory safety is the primary issue with containers as a security boundary.
I don't know where you're getting your information, but this is NOT the consensus on the LMKL, among most Linux kernel people or at any serious large scale tech company.
If you wish to learn about this stuff, lwn.net has a good series of articles on the problems people are actually working on. Most of the problems are related to namespace confusion, privilege escalation through, e.g. block-level access to the filesystem, etc.
> Sometimes the issues are not memory safety ones! But many, most are.
Huge citation needed. In 15 years of security, 8 in Linux kernel security, I have seen maybe one practical exploit related to containers that boiled down to a C-level memory issue.
> That's on you, but I'd be happy to explain more to you if you have questions.
No, you're very confidently stating things that are at the very least debatable. This thread has people doing kernel security as a day job.
- deleted 3y ago[deleted]