Comment by vog
9 years ago
I fully agree that whitelisting is safer than blacklisting.
But on the top of the article, the author explicitly recognzied this and explained why they went down that route:
> I wanted specifically to find a minimal set of restrictions to run untrusted code. This isn't how you should approach containers on anything with any exposure: you should restrict everything you can. But I think it's important to know which permissions are categorically unsafe!
Fair point. And the article does make a good read, with explanations about why each capability in particular should be disallowed.