this post was submitted on 28 Sep 2026
12 points (80.0% liked)

Security

2176 readers
2 users here now

A community for discussion about cybersecurity, hacking, cybersecurity news, exploits, bounties etc.

Rules :

  1. All instance-wide rules apply.
  2. Keep it totally legal.
  3. Remember the human, be civil.
  4. Be helpful, don't be rude.

Icon base by Delapouite under CC BY 3.0 with modifications to add a gradient

founded 3 years ago
MODERATORS
top 7 comments
sorted by: hot top controversial new old
[–] towerful@programming.dev 31 points 2 days ago (2 children)

... Containers were a security boundary?
No no no.
It means I can run something that needs a different dependency version than another service .... Without and clash.
That's the isolation. That's what the isolation means.
Maybe it's the wrong word to use, hence the confusion.

Just cause it's "awkward to get into a container" so it looks like a sealed box, doesn't mean it's actually a secure sealed box.
That box has different dependencies than this other box.
Oh, and these boxes? Yeh, they just run on any host set up to run boxes.
But there is no security

[–] kungen@feddit.nu 7 points 2 days ago

Exactly, it never has been. Moderately decent boundaries are just a side-effect if the runtime platform is configured adequately.

[–] balsoft@lemmy.ml 4 points 2 days ago* (last edited 2 days ago) (2 children)

You definitely don't need containers to "run something that needs a different dependency", it's a massive waste of time and resources and just not what containers were made for. There are/were a thousand other solutions for this, from Nix to chroot to building from source to LD_LIBRARY_PATH to AppImage.

Containers were initially sold as a "security boundary" of sorts. The ability to run some software with the peace of mind that it won't ruin your OS or leak all your data if it's vulnerable. It's the entire point, but it turns out to be extremely difficult to get right. We managed to make a boundary against accidentally messing something up, not against targeted attacks.

[–] kogasa@programming.dev 3 points 2 days ago

You're talking about sandbox type container-based app packaging, like flatpak, appimage, or snaps I think. Containers in the libcontainer/docker sense were always supposed to be "lightweight self-contained runtime environments." It simplified deployment and operations by decoupling infrastructure from code. If it were made with security applications in mind from the start, rootless would have been supported properly

[–] bitfucker@programming.dev 3 points 2 days ago

Yeah, but Nix and every other solution you mentioned has their own tradeoff and ease of use friction between developer and devops. Containers have good ergonomics for both that it reduces friction to achieve ci/cd

[–] onlinepersona@programming.dev 5 points 2 days ago

Oh hey, it's a vulnerability that wouldn't happen in Rust. What a surprise.

[–] exdor@programming.dev 1 points 2 days ago

Application kernels are a thing, need to get using then

Sydbox or gvisor