zlacker

[parent] [thread] 1 comments
1. ashish+(OP)[view] [source] 2026-02-04 05:17:50
That's why I wrote my own sandbox. Everyone hand waives these concerns.

Further, I don't know why docker is weak security on Linux. Are you telling me that one can exploit docker?

replies(1): >>KurSix+dp1
2. KurSix+dp1[view] [source] 2026-02-04 15:42:06
>>ashish+(OP)
dockerd is a massive root-privileged daemon just sitting there, waiting for its moment. For local dev it’s often just unnecessary attack surface - one subtle kernel bug or namespace flaw, and it’s "hello, container escape". bwrap is much more honest in that regard: it’s just a syscall with no background processes and zero required privileges. If an agent tries to break out, it has to hit the kernel head-on instead of hunting for holes in a bloated docker API
[go to top]