http://blog.docker.com/2014/07/new-dockercon-video-docker-se...
http://blog.docker.com/2014/07/new-dockercon-video-docker-se...
[1] https://groups.google.com/forum/#!searchin/docker-user/SELin...
Future hardware isolation: http://css.csail.mit.edu/6.858/2013/readings/intel-sgx.pdf
Mbox is a lightweight sandboxing mechanism that any user can use without special privileges in commodity operating systems.
http://pdos.csail.mit.edu/mbox/
I had trouble running it in Ubuntu because of AppArmor..
What am I missing? (Or is it just that some rootkits use ptrace/Seccomp?)
Interposing (i.e violating API contracts) with ptrace is great for debugging or research prototypes, but the knowledge gained from that research needs to be made interoperable with existing APIs that have been battle tested. Paper said that ptrace/debug overhead is 100%, seccomp (an existing, non-debug API) reduces the need to use ptrace, halving runtime overhead.
Separately, a kernel exploit could break the "sandboxing" of ptrace or docker, hence the need for AppArmor and SE Linux. Here is a year-old Windows article about breaking out of Adobe and Chromium, principles are similar for Linux:
https://www.corelan.be/index.php/2013/03/15/blackhateu2013-d...