4 ms·
With a technology used in production in a lot of places, does responsible disclosure apply here? Did the author (OP?) notify Docker and/or the Linux kernel tea
by jhardcastle 12y ago
With a technology used in production in a lot of places, does responsible disclosure apply here? Did the author (OP?) notify Docker and/or the Linux kernel team before distributing this for public consumption?
- BillinghamJ 12y agoA fix has been released already - Docker 1.0. Thus, it shouldn't really be an issue.
- zorked 12y agoWhile the author called the exploit "shocker" I don't think anybody is shocked by it. There are likely many other ways to break out of Docker. And while I assume the Docker (and kernel!) people are closing them as they come along, I don't think anyone is claiming Docker is unescapable so it's not a surprise if it is.
- zobzu 12y agoI think he might have been sarcastic
- nickstinemates 12y agoSee: http://www.docker.com/resources/security/ http://www.docker.com/resources/security/ It has been used effectively in the past! I'd encourage anyone who is researching security and Docker to send new information here. Thanks!