this post was submitted on 28 Sep 2026
12 points (80.0% liked)

Security

2174 readers
53 users here now

A community for discussion about cybersecurity, hacking, cybersecurity news, exploits, bounties etc.

Rules :

  1. All instance-wide rules apply.
  2. Keep it totally legal.
  3. Remember the human, be civil.
  4. Be helpful, don't be rude.

Icon base by Delapouite under CC BY 3.0 with modifications to add a gradient

founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] towerful@programming.dev 30 points 17 hours ago (2 children)

... Containers were a security boundary?
No no no.
It means I can run something that needs a different dependency version than another service .... Without and clash.
That's the isolation. That's what the isolation means.
Maybe it's the wrong word to use, hence the confusion.

Just cause it's "awkward to get into a container" so it looks like a sealed box, doesn't mean it's actually a secure sealed box.
That box has different dependencies than this other box.
Oh, and these boxes? Yeh, they just run on any host set up to run boxes.
But there is no security

[–] balsoft@lemmy.ml 3 points 10 hours ago* (last edited 10 hours ago) (2 children)

You definitely don't need containers to "run something that needs a different dependency", it's a massive waste of time and resources and just not what containers were made for. There are/were a thousand other solutions for this, from Nix to chroot to building from source to LD_LIBRARY_PATH to AppImage.

Containers were initially sold as a "security boundary" of sorts. The ability to run some software with the peace of mind that it won't ruin your OS or leak all your data if it's vulnerable. It's the entire point, but it turns out to be extremely difficult to get right. We managed to make a boundary against accidentally messing something up, not against targeted attacks.

[–] kogasa@programming.dev 3 points 3 hours ago

You're talking about sandbox type container-based app packaging, like flatpak, appimage, or snaps I think. Containers in the libcontainer/docker sense were always supposed to be "lightweight self-contained runtime environments." It simplified deployment and operations by decoupling infrastructure from code. If it were made with security applications in mind from the start, rootless would have been supported properly

[–] bitfucker@programming.dev 3 points 9 hours ago

Yeah, but Nix and every other solution you mentioned has their own tradeoff and ease of use friction between developer and devops. Containers have good ergonomics for both that it reduces friction to achieve ci/cd

[–] kungen@feddit.nu 6 points 15 hours ago

Exactly, it never has been. Moderately decent boundaries are just a side-effect if the runtime platform is configured adequately.