Comment by bityard

3 hours ago

Depends on the threat model. Security is not black-and-white.

Containers protect against "I don't trust this curlpipe to not crap all over my dotfiles," rather than, "there might be a sandbox escape attack in this random file I downloaded."

If a VM is not sufficient for your threat model, I'm curious what is?