Comment on Rybbit - Open source Google Analytics replacement

<- View Parent
LordKitsuna@lemmy.world ⁨1⁩ ⁨month⁩ ago

In its default state i think thats fair. Example docker bypasses most firewalls as it runs before iptables rules process. So if you don’t either use 127.0.0.1:port:port (many compose files offered by projects do not do this) or add specialized iptables rules to fix that up you can end up directly exposing services with meaning to or even realizing.

And yeah privilege escalation etc. There are solutions like what you mentioned but it can be a lot of work to set all that up so most people won’t

source
Sort:hotnewtop