4 ms·
To keep your machine secure, run third-party tools inside Docker
- unixhero 1y ago95% of the OS is third party and everything I install afterwards is 3rd party.
- ashishb 1y agoThat's true. However, you are reducing your attack surface by running some of those tools inside Docker.
- soraminazuki 1y agoBy running Docker, you are introducing tons of more code that runs with root privileges. There are numerous privilege escalation vulnerabilities discovered over the years. Combined with the fact that root inside a Docker container is root on the host, you are increasing your attack surface instead of reducing it. It's the wrong tool to be using for security.
- unixhero 1y agoWell maybe not on the bsds when I come to think of it
- hulitu 1y ago> To keep your machine secure, run third-party tools inside Docker Firefox and Chrome ? Building programs for languages which connect to the internet (python, rust), although that does not protect against random malicious packages?
- ashishb 1y agoThird-party CLI tools. It is doable, but hard to run a browser inside Docker. Further, the browser itself has a layer of safety against executing malicious code.
- atmanactive 1y agoQubes OS, anyone?
- ashishb 1y agoDocker can be used on Mac, Linux, BSD [and probably even Windows]. Switching to Qubes OS requires a much bigger shift.
- soraminazuki 1y agoIt's Linux VM on Mac, Linux, Linux VM on BSD, and Linux VM on Windows. I'm sure Qubes OS can run on VMs as well. I mean for Windows, yes Windows containers technically exist, but no one uses them and therefore has no flourishing ecosystem.