logoalt Hacker News

mentalgeartoday at 8:55 AM2 repliesview on HN

For credential stealing, that is true, but at least it would protect your local machine. But I just read these worms also try container escape ...


Replies

silon42today at 9:03 AM

We need to prevent direct connections to internet for containers... once you have a proxy, predefined credentials (api keys) can maybe be added there (per container/target).

show 1 reply
fnoeftoday at 9:05 AM

You need to use full isolated VM with its own kernel. But then again, I've read somewhere that this malware is also trying to escape the VM isolation as well...

show 1 reply