← Back to context Comment by roboben 7 hours ago docker is not a security boundary but a resource boundary. 2 comments roboben Reply cute_boi 7 hours ago It is security boundary but a weak one. Escaping from docker is very hard. rvz 3 hours ago > Escaping from docker is very hard.You mean a microVM.A docker LPE (local privilege escalation) requires a kernel exploit such as Copyfail would work under docker but not in a microVM.
cute_boi 7 hours ago It is security boundary but a weak one. Escaping from docker is very hard. rvz 3 hours ago > Escaping from docker is very hard.You mean a microVM.A docker LPE (local privilege escalation) requires a kernel exploit such as Copyfail would work under docker but not in a microVM.
rvz 3 hours ago > Escaping from docker is very hard.You mean a microVM.A docker LPE (local privilege escalation) requires a kernel exploit such as Copyfail would work under docker but not in a microVM.
It is security boundary but a weak one. Escaping from docker is very hard.
> Escaping from docker is very hard.
You mean a microVM.
A docker LPE (local privilege escalation) requires a kernel exploit such as Copyfail would work under docker but not in a microVM.