3 ms·
It's not an exploit when its a documented, and warned feature that reduces your security since day 1. "Warning: The docker group is equivalent to the root user
by wyaeld 11y ago
It's not an exploit when its a documented, and warned feature that reduces your security since day 1.
"Warning: The docker group is equivalent to the root user; For details on how this impacts security in your system, see Docker Daemon Attack Surface for details."
FUD
- chrisfosterelli 11y agoFair enough, you could make that argument! I did acknowledge that Docker has documented that behaviour, but that doesn't change the fact that it is a insecure-design worth being aware of. Many of the 'Docker tips' blog posts that discuss that behaviour _don't_ mention the insecurity.
- Gracana 11y agoThe article acknowledges that: > In Docker’s defense, they are aware that this is a security problem, although they apparently have no intention of actually fixing it. About half way down in their security document, they do explain that the ‘docker’ group is root-equivalent and why that is dangerous.
- 0xdeadbeefbabe 11y agoNot just FUD, but a form of speculation about how security is sooo awesome. Edit: Hey downvoters any explanation? sudo any explanation?