▲ | franga2000 2 days ago | ||||||||||||||||
But those containers DON'T have socket access. ONE container has socket access, then it creates other containers WITHOUT socket access. Those containers ARE isolated. Since the untrusted (user provided) code runs in those, the setup is reasonably secure. An RCE in OneDev is an RCE on the host, but that's a completely different threat model. The important part is that user code is isolated, which it is. | |||||||||||||||||
▲ | hamdingers 2 days ago | parent [-] | ||||||||||||||||
> The important part is that user code is isolated, which it is. It isn't for the reasons I stated in previous comments, which you are unable to refute. Your dogged insistence to the contrary is bizarre. I hope you do not work in this area. | |||||||||||||||||
|