Hacker News new | ask | show | jobs
by reegnz 1403 days ago
This is painfully reductionist. The mount namespace is only one of multiple namespaces (eg. pid, network, user, etc.) that containers utilize. Security doesn't stop at linking and shipping binaries.