https://brauner.github.io/2019/02/12/privileged-containers.html Christian Brauner, maintainer of #LXC fixes a vulnerability that was discovered affecting #runC, the default #Docker container runtime. As a side note I was astonished by the amount of presentations at #FOSDEM this year about running unprivileged a.k.a. rootless containers when #LXC does it since 2013. TIL that #kubernetes and friends run fully privileged containers . Scary shit.
The social network of the future: No ads, no corporate surveillance, ethical design, and decentralization! Own your data with Mastodon!