Comment on Security and docker

<- View Parent
Lemongrab@lemmy.one ⁨1⁩ ⁨month⁩ ago

It is not speculation, it is reducing attack surface. Security is preemptive. Docker/Podman are not strong isolation solutions. Rare does not mean we shouldn’t protect against the chance of kernel vulnerabilities. The linux kernel around 30 million lines of code long and written in a memory unsafe language. Code isn’t safe just because we dont know the vulnerabilities, this is basic cybersec reasoning.

source
Sort:hotnewtop