|
|
|
|
|
by lxgr
1 day ago
|
|
If you let your container write setuid binaries to your path, give it admin access to your network, let it access the Docker daemon socket etc., sure, you're going to have a bad time. But how is that different from e.g. giving software running in a VM SSH access to your host or a writable bind mount to the host's root directory? |
|
AFAICT all the security problems are fairly obvious own goals inflicted after that point.