• kitnahtBanned
    link
    fedilink
    arrow-up
    19
    arrow-down
    1
    ·
    1 年前

    The biggest problem that I have with docker is honestly, the fear of a supply-chain attack.

      • kitnahtBanned
        link
        fedilink
        arrow-up
        6
        arrow-down
        3
        ·
        1 年前

        Supply chain attack has a definition. And it has nothing to do with DDoS.

      • roofuskit
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 年前

        They worry about someone replacing the docker image on the hosting server with a malicious modified version for people to pull down during updates.

        • zalgotext@sh.itjust.works
          link
          fedilink
          arrow-up
          9
          ·
          1 年前

          This worry exists for literally every 3rd party dependency, not just docker, and is addressed the same way - by running tests and vulnerability scans in a sandboxed test environment before shipping to prod

      • roofuskit
        link
        fedilink
        English
        arrow-up
        4
        ·
        1 年前

        Enterprise folks also shouldn’t be pulling updates down to production environments.

        • Acters
          link
          fedilink
          arrow-up
          2
          ·
          1 年前

          CrowdStrike: lmao let’s brick half the world running on Windows PCs