Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's not really.

Any shared resource between containers or the kernel itself is an attack surface.

Both options have a very wide attack surface - the kernel api.

Nothing really beats virtualization in security, the surface shrinks to pretty much just the virtualization bits in the kernel and some user space bits in the VMM.



Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: