logoalt Hacker News

pkulak • yesterday at 5:21 PM • 1 reply • view on HN

Way better isolation, is my guess. Plus, you can use a different kernel this way.

I used to poo-poo when people said that containers aren't a _real_ security boundary, at least for personal stuff, and not a multi-tenant server. But I bet even mid-tier LLMs can break out of LXC/Docker/nspawn at this point.


Replies

fhn • yesterday at 5:56 PM

can they not break out of a VM?

➕ show 3 replies