Even when written, the study made inaccurate claims about rkt (the SELinux support in rkt is identical to that in Docker, because rkt uses the same code from libcontainer - there is literally no difference there). It certainly wasn't an accurate depiction of rkt's state of security as of August.

(Disclaimer: I implemented some, but definitely not all, of those security features in rkt, and I currently work at CoreOS)

