In general running containers rootless is better from a security standpoint and podman makes this much easier. So, yes.
This is not my main point though. Both are based on cgroups and cgroups are the wrong tool for the job.
Wouldn't it need a super critical exploit, I mean zero-day vulnerability, to escape from that kind of sandbox ? And if you think further, then isn't that risk also applicable to pretty much any kind of sandboxing ?
Wouldn't it need a super critical exploit, I mean zero-day vulnerability, to escape from that kind of sandbox ? And if you think further, then isn't that risk also applicable to pretty much any kind of sandboxing ?