logoalt Hacker News

tcdenttoday at 5:37 PM0 repliesview on HN

Ah yes sandbox it because Docker has never experienced a CVE.

Also you admit your own failure points: restricting access to the home dir, when a user needs access to the home dir, will just result in users exposing their home dir. Defense at the expense of utility is not a sustainable design.