Your Container Is Not a Sandbox

27 points by jryans


dpc_pw

It's a silly black and white thinking to say containers are not a security boundary. They are. Here is a potential VM escape vulnerability. Does it mean VMs are not a security boundary either?

Container security is weaker and attack surface larger, so they will get broken more often. Much more often. Is it a strong enough boundary depends on what you are trying to secure. If you are e.g. trying to wrap your coding clanker you are probably worried about it randomly decide to modify or send data it was not supposed to touch and chances it will use a container escape are near zero. Container is going to be good enough for that. If you are trying to security public infrastructure where anyone can upload arbitrary code at any time, container are not strong enough and too risky.