* the false sense of security from putting signatures in the manifests then ignoring them
* loading signing certs via the network with no provision for pinning
* happily loading untrusted/unsigned images by default (npm, rubygems, installtools, etc. also do this but why repeat their awful design mistake?)
* running basically everything as root (because why deal with all those messy permissions?)
My sysadmin Spidey-sense has been tingling at the rate of change in the Docker ecosystem since it went from "interesting POC" to "we think it's production ready" in a shockingly short period of time. Things like this sadly confirm that initial pessimistic view.
Things like this are really putting everything that is happening with Rocket and the drama around it in perspective.