Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Don't user namespaces have significant security issues themselves?


There have been security bugs involving allowing unprivileged user namespaces, but that doesn't matter at all in this case -- seccomp is used by effectively all container runtimes to block things like CLONE_NEWUSER inside containers.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: