7 ms·
If you believe containers cannot be secure, than you should be able to capture the flag and get paid for beating https://contained.af/ https://contained.af/ Ha
by nmjohn 7y ago
If you believe containers cannot be secure, than you should be able to capture the flag and get paid for beating https://contained.af/ https://contained.af/
Having said that, I agree that by default containers are a poor security boundary - but saying they are wholesale inadequate is not accurate.
- ploxiln 7y agocontained.af uses seccomp to block a bunch of syscalls that you would not block for a real service, for example socket()