Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
undefined | Better HN
0 points
oofbey
6mo ago
0 comments
Share
A docker container isn’t as bulletproof as a VM but it would certainly block this kind of attack. They’re super fast and easy to spin up.
0 comments
default
newest
oldest
goodpoint
6mo ago
It would not block many other attacks.
oofbey
OP
6mo ago
Can you give some examples? I think of my containers as decently good security boundaries, so I'd like to know what I'm missing.
kwar13
6mo ago
Containers share resources at the OS level, VMs don't. That's the crucial difference.
goodpoint
6mo ago
Containers share the whole kernel (and more) so there's a massive attack surface.
j
/
k
navigate · click thread line to collapse