this post was submitted on 28 Sep 2026
12 points (80.0% liked)
Security
2174 readers
53 users here now
A community for discussion about cybersecurity, hacking, cybersecurity news, exploits, bounties etc.
Rules :
- All instance-wide rules apply.
- Keep it totally legal.
- Remember the human, be civil.
- Be helpful, don't be rude.
Icon base by Delapouite under CC BY 3.0 with modifications to add a gradient
founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
... Containers were a security boundary?
No no no.
It means I can run something that needs a different dependency version than another service .... Without and clash.
That's the isolation. That's what the isolation means.
Maybe it's the wrong word to use, hence the confusion.
Just cause it's "awkward to get into a container" so it looks like a sealed box, doesn't mean it's actually a secure sealed box.
That box has different dependencies than this other box.
Oh, and these boxes? Yeh, they just run on any host set up to run boxes.
But there is no security
You definitely don't need containers to "run something that needs a different dependency", it's a massive waste of time and resources and just not what containers were made for. There are/were a thousand other solutions for this, from Nix to
chrootto building from source toLD_LIBRARY_PATHto AppImage.Containers were initially sold as a "security boundary" of sorts. The ability to run some software with the peace of mind that it won't ruin your OS or leak all your data if it's vulnerable. It's the entire point, but it turns out to be extremely difficult to get right. We managed to make a boundary against accidentally messing something up, not against targeted attacks.
You're talking about sandbox type container-based app packaging, like flatpak, appimage, or snaps I think. Containers in the libcontainer/docker sense were always supposed to be "lightweight self-contained runtime environments." It simplified deployment and operations by decoupling infrastructure from code. If it were made with security applications in mind from the start, rootless would have been supported properly
Yeah, but Nix and every other solution you mentioned has their own tradeoff and ease of use friction between developer and devops. Containers have good ergonomics for both that it reduces friction to achieve ci/cd
Exactly, it never has been. Moderately decent boundaries are just a side-effect if the runtime platform is configured adequately.