85
you are viewing a single comment's thread
view the rest of the comments
[-] hottari@lemmy.ml 5 points 2 years ago

I never said I was relying on it alone. Not sure why you think that.

....

...all my services aren’t running as root.

If it turns out a vulnerability is discovered in lemmy tomorrow that allows people to access my server through my lemmy container, the attacker will only have access to a dummy account that hosts my containers.

This was your argument according to you for why you think podman is more secure (than docker I presume). Seemed to imply rootless podman will save you from an attacker. I was simply disproving the flawed notion.

[-] BlueBockser@programming.dev 1 points 2 years ago

I think you're interpreting too much. Security is about layers and making it harder for attackers, and that's exactly what using a non-root user does.

In that scenario, the attacker needs to find and exploit another vulnerability to gain root access, which takes time - time which the attacker might not be willing to spend and time which you can use to respond.

[-] hottari@lemmy.ml 1 points 2 years ago

You don't know enough about security to lecture me. The kernel has before/continues to suffer(ed) from successful root shell exploits, particularly in this case via unprivileged userns. Something podman or even rootless docker can't do anything about.

[-] BlueBockser@programming.dev 2 points 2 years ago

Funny how you claim to know so much about security but can't even seem to comprehend my comment. I know root shell exploits exist, that's why I wrote that it takes additional time to get root access, not that it's impossible. And that's still a security improvement because it's an additional hurdle for the adversary.

[-] apigban@lemmy.dbzer0.com 3 points 2 years ago

the person you are replying to either lacks comprehension or maybe just wants to be argumentative and doesn't want to comprehend.

[-] hottari@lemmy.ml 1 points 2 years ago

Containers cannot be viewed as security tools. They suffer from poor isolation and inadequate and some cases non-existent sandboxing. All these are proven security essentials. You would know about them if you knew anything about (defensive) security!

[-] BlueBockser@programming.dev 2 points 2 years ago

Once again, you're going off on an unrelated tangent. If you don't want to listen, I can't help you. We're done here.

this post was submitted on 26 Sep 2023
85 points (100.0% liked)

Selfhosted

60951 readers
700 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS