Earlier quoted context omitted.
I've heared this too, but as far as I know it's only because there are potential bugs in the container software that allow the malware to escape. To me, this is kind of like saying you should just run stuff as root, because there might be a privelege escalation vulnerability which lets the code run as root anyway. Correct me if I'm wrong. My goal was to make things more secure, not completely secure. Previously, dodg…
A full VM seems somewhat of a better stance on this no ?
I could counter your "VM is better than container", with "Separate hardware is better than VM".