4 ms·
> Despite what some people will tell you (including many in the security indistry), Docker is not a strong security boundary, and it should not be treated as on
by throw0101c 5mo ago
> Despite what some people will tell you (including many in the security indistry), Docker is not a strong security boundary, and it should not be treated as one. It shares a kernel with the running system.
Solaris Zones and FreeBSD Jails (their inspiration) also share a kernel with the running system and do not seem to have as many escape vulnerabilities.
(Though partly because there may not be as much scrutiny of course.)
- Icathian 5mo agoYeah, I'm reminded of 15 years ago being told Linux was super secure because people were popping Windows all the time. Turns out it was mostly just a function of effort pointed at the target, and I don't have any reason to believe that's not the case here too.
- ErroneousBosh 5mo agoLinux has had 100% market penetration for 20 years or so now. Everyone using a computer uses Linux *somewhere* in it. You'd think if it was that easy, there would be exploits all over the place. Why isn't every single desk phone and router part of a botnet?
- pyinstallwoes 5mo agoI mean? Many of them are…
- Icathian 5mo agoKimwoolf and Aisuru kind of make my point better than yours, I think?