Indeed. The point discussed in the grandparent relates to indirect access to the daemon. E.g., a process (not under direct user control) communicating with the Docker daemon via http API. The point being that the cp endpoint can be compromized without the user having direct control over the API parameters.