It makes a good sandbox because it uses a chroot/pivot_root + unshares pid/net/uts/mnt/ipc namespaces, but it doesn't use user namespaces so root in the container is root on the host which is a bit scary.
- Not running as root.
- Enabling the no_new_privs prctl to prevent attacks on buggy setuid binaries.
- Using an aggressive seccomp-bpf filter.
- Hiding /proc, /sys, most of /dev, etc.
- Other things I'm forgetting at the moment. :)
It's ok that Docker containers are not yet secure sandboxes, and it would be a great if that changed.
But potentially breaking compatibility with existing apps is understandably not something Docker wants to do. (Whereas it's something sandstorm.io is happy to do, because apps already need to be tweaked in other ways for it.)