logoalt Hacker News

xmodemyesterday at 7:18 PM2 repliesview on HN

> FROM scratch just reduces the surface.

The actual attack surface of your application? Or the attack surface of you and your team's attention from a busybody security org.

It's important not to confuse the two.


Replies

fc417fc802today at 12:21 AM

Both. Many attacks take the form of an exploit to get a shell, then using available utilities to exploit the kernel to escape to the host. If your image has neither a shell nor utilities that won't get very far.

monkpittoday at 3:57 AM

Important to whom?