you are viewing a single comment's thread
view the rest of the comments
[–] 17 points 2 years ago* (1 child)

Defense in depth. If something escapes the container it's limited to only what's under that user and not the whole system. Having access to the whole system makes it easier for malware to hide/persist itself.

  • source
  • parent
  • hideshow 2 child comments
  • [–] -4 points 2 years ago (2 children)

    Correct me if I'm wrong but containerization is enforced by the kernel, correct? If something escapes you're pretty much screwed anyway.

  • source
  • parent
  • hideshow 4 child comments