• Passerby6497@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 hours ago

    in fact if you’re going to install insecure services you definitely want to containerize them,

    While this is true, if you’re running a platform that is root by default (looking at you, docker), you’re not shielding yourself as much as you might think you are.

    If you’re running an insecure app as root, you better hope they don’t also have an exploit to get out of the container after the app is popped, otherwise you’re fucked.