4 ms·
> but are not claiming that it's more secure yet That's a bit disingenous. The CLI clearly makes a security claim here, and you know very well that users will
by tuffle 12y ago
> but are not claiming that it's more secure yet
That's a bit disingenous. The CLI clearly makes a security claim here, and you know very well that users will take it as one.
I'm all for "working on ways to make image distribution more secure", but making security claims in the CLI when said security does not exist yet is -- assuming good faith -- a security bug in the user interface that should be fixed.
- shykes 12y agoI agree. The message should be more clear.
- tedivm 12y agoYour two messages contradict each other- >So, we've made it pretty clear from the start >I agree. The message should be more clear. It seems like a bit of backpedalling here. Rather than try to blame the author for not understanding or quoting the announcement that most people wouldn't have read anyways I think you should just commit to fixing the underlying problem (first the message that's passed, then the actual feature itself) and thank the author for drawing attention to it and educating your users on the security issue at hand.
- kstenerud 12y agoThe first quote is in reference to the announcement. The second quote refers to the CLI messaging. Shykes is acknowledging the problem.
- tuffle 12y agoIt's good to hear that it will be fixed, but it's also troubling that a front-facing security issue took a #1 HN post, followed by debate in the comments before Docker recognized it.
- shykes 12y agoAll the issues in this post are already known and being actively discussed on the mailing lists and repo (including with the blog post author). However nobody so far had noted that the "image verified" message is misleading and should be clarified. I'm simply acknowledging that we should fix that, too.
- Alupis 12y ago> That's a bit disingenous. The CLI clearly makes a security claim here, and you know very well that users will take it as one. This is truly one of the largest complaints about the Docker project and how they present themselves. They constantly present their product as it does X, Y, and Z today, yet upon research you will discover it really only does X, while Y and Z are planned for sometime in the future. Unfortunately, all too often X becomes some new shiny feature, while Y and Z are security related issues.
- tempVariable 12y agoDocker should not show the '...Verified...' message,- I agree. I have not used it in a while. I also remember that when I used it,- I was aware that it was not verifying the images. That was my responsibility, to double check and peer review the tool which I'm using. Docker is not meant to be used by your grandma and certain level of responsibility is expected on your part. Now, I don't care one way or another , but your message history clearly points that you troll like a maniac in each Docker thread. With all this time spent, why didn't you research a better approach, create a merge request or Docker-type of RFC post proposing a single improvement. If you already did - great! While I haven't contributed yet, I have read the source and saw this entry on GH: https://github.com/docker/docker/blob/master/CONTRIBUTING.md https://github.com/docker/docker/blob/master/CONTRIBUTING.md So there is no excuse not to!
- sillysill 12y agoI'd like you to try and get any security commits in the docker tree. Try your luck.. others have.