Earlier quoted context omitted.
Memory safety isn’t why containers are considered insufficient as a security boundary. It’s exposing essentially the entire Linux feature surface, and the ability to easily interact with the host/other containers that makes them unsafe by themselves. What you’re saying about VMs vs containers makes no sense to me. VMs are used to sandbox containers. You still need to sandbox containers if your kernel is written in ru…
[flagged]
> Memory safety is the primary issue with containers as a security boundary.
"No it isn't" "Yes it is" "No it isn't" "Yes it is"