Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
undefined | Better HN
0 points
oofbey
7mo ago
0 comments
Share
A docker container isn’t as bulletproof as a VM but it would certainly block this kind of attack. They’re super fast and easy to spin up.
0 comments
default
newest
oldest
goodpoint
7mo ago
It would not block many other attacks.
oofbey
OP
7mo ago
Can you give some examples? I think of my containers as decently good security boundaries, so I'd like to know what I'm missing.
kwar13
7mo ago
Containers share resources at the OS level, VMs don't. That's the crucial difference.
goodpoint
7mo ago
Containers share the whole kernel (and more) so there's a massive attack surface.
j
/
k
navigate · click thread line to collapse