4 ms·
> Docker (and LXC) seems like a huge step backwards for security. Sry but link says it all. No further comment from me: http://marc.info/?l=openbsd-misc&m=1193
by sarnowski 13y ago
> Docker (and LXC) seems like a huge step backwards for security.
Sry but link says it all. No further comment from me:
http://marc.info/?l=openbsd-misc&m=119318909016582&w=2 http://marc.info/?l=openbsd-misc&m=119318909016582&w=2
- rdl 13y agoVT-d, VT-x. 2007 != 2013. The number of hypervisor exploits is far fewer than the number of local root exploits on various shitty OSes (including OpenBSD).
- sarnowski 13y agoDo you have a link for this statistic? Since I don't know of a local root privilege escalation since several years in OpenBSD, this is a quite high mark. Edit: this is not a os-or-vm problem. You will have local problems and now, in addition, rooting a server may give you access to even more servers that run on your hyp.
- j_s 13y agoI don't think that your link disagrees with the OP at all. Yes, bare metal is more secure than hardware virtualization; but hardware virtualization still provides greater security than kernel virtualization.