Hacker News new | ask | show | jobs
by nicce 1848 days ago
Every additional mount can be considered as extra failure in design in terms of security or just being considered as laziness. Those all increase the attack vector. Even though containers are not designed in terms of isolation, every mount and volume are one step closer to break this isolation. Of course, the total risk depends on where from you are mounting.