In other words, your browser can snoop on what passwords you type into an X terminal if it wanted to or is compromised.
In other words, your browser can snoop on what passwords you type into an X terminal if it wanted to or is compromised.
(Of course, the Dockerfiles were also running apps--like, say, Chrome--as root, with no user namespaces, so it wasn't exactly great anyway.)
It's only bad advice if you're relying on Docker to provide security against targeted threats. Know your enemy.
But in Linux, I can run application in container or VM and then use VNC, RDP, or Spice to connect to it in secure manner.
No, it's not. OS X has GUI isolation, an application cannot read keystrokes or read other application's contents, unless you explicitly give permission to do so. This is the reason why applications that can do more, such as Alfred, require you to explicitly enable these rights in the Privacy section of the Security & Privacy prefpane.
Windows also has GUI isolation (UIPI), but it's a bit murkier. As far as I understand, lower-privileged applications cannot read events from higher-privileged applications.
So while it's possible for a program to listen to keyboard events for other non-administrative windows (such as the password for a browser), it isn't possible for a non-administrative window to grab keyboard input for stuff like windows password prompts, or information typed into administrative console windows, etc.
[0] - http://stackoverflow.com/questions/3169675/how-to-use-setwin...