Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It would not block many other attacks.


Can you give some examples? I think of my containers as decently good security boundaries, so I'd like to know what I'm missing.


Containers share resources at the OS level, VMs don't. That's the crucial difference.


Containers share the whole kernel (and more) so there's a massive attack surface.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: