Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

`useradd` doesn't restrict network access.




I have used a separate user, but lately I have been using rootless podman containers instead for this reason. But I know too little about container escapes. So I am thinking about a combination.

Would a podman container run by a separate user provide any benefit over the two by themselves?


Without any credentials does network access matter?



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: