logoalt Hacker News

smallpipetoday at 12:59 PM1 replyview on HN

Docker is not a security boundary. You’re one prompt injection away from handing over your gmail cookie.


Replies

benatkintoday at 2:01 PM

No, but Podman is. The recent escapes at the actual container level have been pretty edge case. It's been some years since a general container escape has been found. Docker's CVE-2025-9074 was totally unnecessary and due to Docker being Docker.

show 2 replies