But the result of a compiler will run on the machine anyway, but once again, it should be in a Docker.
But the result of a compiler will run on the machine anyway, but once again, it should be in a Docker.
Container technology is awesome, and it’s a huge step forward for the industry, but are places where it’s not feasible to use, at least for now.
Even KVM escapes have been demonstrated. KVM is not a security boundary ... except that in practice it is (a quite effective one at that).
Taken to the extreme you end up with something like "network connected physical machines aren't a security boundary" which is just silly.
1. This is why some places with secret enough info keep things airgapped.
2. OTOH, from what I recall hearing the machines successfully targeted by Stuxnet were airgapped.
In our threat model the upper bound on the useful lifetime of the system is limited by the light-distance time from the nearest adversary.
What percentage of malware is programmed to exploit Docker CVEs vs. just scanning $HOME for something juicy? Swiss cheese model comes to mind.