|
|
|
|
|
by jchw
3120 days ago
|
|
FreeBSD jails are known to not be silver bullets. I've heard many instances of breaking out of a FreeBSD jail. Generally, treating any OS-level technology as a silver bullet is a huge mistake. Any serious developer would make multiple levels of security that _should_ be sound. |
|
While not applicable to FreeBSD alone, this polemic thread:
https://marc.info/?l=openbsd-misc&m=119318909016582
is a pretty accurate description of container level security and not much has changed. Stuff built on a foundation is always subject to the foundation's qualities.