4 ms·
I feel like the sheer volume of OS LPEs and escape CVEs in container runtimes indicates that, at least for now, the security boundary capabilities of containers
by zbentley 2mo ago
I feel like the sheer volume of OS LPEs and escape CVEs in container runtimes indicates that, at least for now, the security boundary capabilities of containers are inferior to those of VMs.
Which is ironic, given that a lot of the tools that underly a container runtime were originally designed to facilitate security, not ease of deployment.
- throwaway84932 2mo agoYou're aware of the VM escape issues over the past decade? There's no perfect, and high overhead from running many guests can also create security risks. Wayland with all of its problems remains a logical step forward from the X model.
- zbentley 2mo agoI was narrowly responding to the point about Qubes using VMs. I have no problems with Wayland’s design; I agree that it’s a step forward.
- throwaway84932 2mo agoAh, got it! Thanks for clarifying. That makes a lot of sense.