logoalt Hacker News

cluckindanyesterday at 11:11 PM1 replyview on HN

So a threat actor buys access to a managed kubernetes service, or other linux-based shared hosting platform, and now they have access to the computer.

Hell, GitHub Actions would do.


Replies

echoangletoday at 12:19 AM

Is there any service that relies on Linux user separation or containers to separate different user accounts? I’m pretty sure you’re not supposed to do that and the proper way is to run different instances in virtual machines.

show 1 reply