The number of people who do it in production is correlated with the complexity of the thing they are trying to do and how much the "fuck it, just do <some terrible idea>" relieves that complexity.
Because of this escape, giving access to /var/run/docker.sock to regular users is the same as giving them root access.
Also as the article says mounting /var/run/docker.sock is (now, because of this escape) the same as giving that container access to the host system.
docker run -itv /:/host ubuntu chroot /hostThe idea, of course, is to minimize the surface area for attacks. That container has a need for it to run that way; the vast majority of our other containers do not.
Ironically, attackers would have access to more valuable data (and more freedom of movement) on your personal/dev box than on a monitored production host.