5 ms·
Ah yes sandbox it because Docker has never experienced a CVE. Also you admit your own failure points: restricting access to the home dir, when a user needs acc
by tcdent 1mo ago
Ah yes sandbox it because Docker has never experienced a CVE.
Also you admit your own failure points: restricting access to the home dir, when a user needs access to the home dir, will just result in users exposing their home dir. Defense at the expense of utility is not a sustainable design.
- mafuy 1mo agoIt's better than the alternative. Don't complain about someone offering an imperfect improvment, if you don't have something even better to offer.