upvote
They don't have access to the host filesystem nor environment variables and this attack wouldn't work.
reply
Just because this attack example did not contain container escape exploits does not mean this is safe. Its better than nothing but nothing that will save us.
reply
Those supply chain attacks we are seeing are bad, but if someone burns a 0day container escape for it, it would probably be a net positive effect on security overall. Just saying this is FUD.
reply
FUD is crypto and tech bro speech. Using containers without vm, gvisor or similar is just irresponsible.
reply
Oh you are young, FUD was criticism to IBM sales people scaring customers away from PC compatible clones.
reply