Earlier quoted context omitted.
They are a security boundary. The fact that you need a vulnerability to escape them is proof of that. They just don't have a particularly high cost of escape because reachable kernel vulnerabilities are so common.
Some people clearly do use containers as deployment mechanism, with security not in mind.
That's not meant to be snide, just true, I think.