Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Please provide technical details of `Jails are far more secure`.



No? Because many of them Docker specific. Neither I mentioned Docker anywhere, not Docker is a good example of software with a good security record. Another link lumps together k8s, runc and so on. I specifically mentioned systemd-nspaw in the beginning as contender to jails, not other solutions.


Misleading: the most important vulnerabilities that break shared-kernel isolation systems like Jails, Zones, and containers are kernel LPEs, and they aren’t reported as “escapes”.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: