Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Container escapes can however be quite easy

This is certainly true of docker-style container setups where the host kernel is shared directly with other tenants, but it seems to me like a bold claim to make of gvisor as used by these systems.

 help



Fair enough, I kind of assumed their sandbox was just some generic container or bwrap thing everyone uses for agents nowadays



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: