Be Using Rootless Containers

(blog.miguelgrinberg.com)

29 points | by ibobev 1 day ago

3 comments

  • ma2kx 1 day ago
    In my opinion the biggest advantage of podman is that it uses pods with basically the same config and behavior as kubernetes does. As long as you just use podman pods instead (or possibly via) compose files you likely just notice that only the pod has one (and not any more) veth interface, that you reach other containers inside a pod via localhost:$port (instead of $service-name:$port) but when you switch later on to kubernetes you are already familiar with some basics.
  • orangea 8 hours ago
    Why would an adversary being able to execute code as root on a personal computer be a bigger threat than their being able to execute code as non-root? Surely just about any of the stuff that a malicious hacker might want to do to someone's personal computer can be done without root... right?
    • HarlequinHair 8 hours ago
      There are substantial differences.

      For one, as non-root user you are tied to the permissions system and can't access most of the data. If one of your services (let's say sql) get hacked, they are tied to sql user, and unless the achieve privilege escalation, they can't mangle with other services data (eg webserver).

      Also network wide, a non-root user can't use different protocol than tcp and udp. The only reason you can ping as a regular user is because of the setuid on the ping program, otherwise icmp is not allowed to non-root users.

      There are of course other reasons, but these are some examples on how it would be different.

      • orangea 8 hours ago
        I think you're just illustrating my point. Those concerns don't apply to personal computers and they don't stop an intruder from doing anything they might practically want to do for gain. Like installing ransomware, participating in a botnet, exfiltrating personal files/browser cookies/etc (all accessible as non-root!), ...
        • HarlequinHair 2 hours ago
          I kind of think I am doing the opposite?

          Apart from rootkit and backdoors that are more difficult to install as non-root, you cannot build specific tunnels as you don't have network permissions.

          There are some user space network capabilities, but they are easily breaking, or discovered and in general not resilient to simple reboots. This is one of the reasons you shouldn't leave your client 24/7 on.

        • fificjcj274 7 hours ago
          The difference is with root it’s easier to install further, more resident, malware
    • SmasherEpilepti 8 hours ago
      With a user shell, I can grab their browser data, personal documents, and try to set up persistent background daemons that listen on programs and do keylogging/screenshotting (harder on Wayland than it was on X11).

      With root, I can read all program memory, try to extract decryption keys for encrypted filesystems, modify the kernel, punch open backdoors, modify any arbitrary program, read all user files, etc.

      A notable extra issue is the rise of AI agents, which often eagerly test the boundaries of every sandbox they are placed within. I would not run an AI agent as root, nor would I give it full access to a rootful container runtime.

      • orangea 7 hours ago
        The kinds of things that you list that an attacker could do with root access don't sound like things that an actual attacker would want if they are infiltrating random people's personal computers for their own gain. Modifying the kernel or arbitrary programs is so far beyond what typical malware tries to do that I think it seems kind of silly to consider those things when evaluating the security of an operating system designed for personal computers.
        • SmasherEpilepti 7 hours ago
          To me, they do sound like the kind of things an attacker would want, if they found a reliable, reproducible, automatable path to them. If I was writing malware, ransomware, or just exfiltrating data, I'd be much happier to have root access to do it. Even simple botnets, I'd probably want to try to replace a regular service that most everybody runs (like cupsd) with one that functions exactly like the real one, but also does the malicious activity, and similarly try to patch the package manager to persist it on updates.
    • myaccountonhn 8 hours ago
      I run all agents as a different user for this reason.
      • aktau 1 hour ago
        My view is this isn't sufficent. They're pretty good at breaking out of stuff. A VM would be the minimal isolation boundary for me.
  • venussnatch 8 hours ago
    >the one led by the racist, so it isn't getting a mention here

    Are people really terminally online enough to understand this?

    • nosioptar 7 hours ago
      I'm pretty sure he's talking about Omarchy. They had some container related issue not too long ago.

      OpenMandriva would be my next guess, but it's not a newer distro.

      • Fordec 7 hours ago
        No, it's definitely a reference to the DHH/Romani drama from July and the Omarchy privilege escalation a few weeks back.
    • SoftTalker 8 hours ago
      I don't know what he's referring to but I stopped reading at that sentence.
      • procone 7 hours ago
        Yes, I really don't want to read about American politics when discussing operating systems and technology. It's already shoehorned into so many discussions that it no longer makes any sense.

        A blog post talking about security but refusing to mention which operating was vulnerable to an exploit out of virtue signaling(?) is absurdist comedy.

        If the author is referring to Omarchy, should we also stop using and mentioning Ruby on Rails? Preposterous.

        • SmasherEpilepti 7 hours ago
          I agree with your main point, and found it stupid that I had to search around to find what the hell was even being talked about directly. That said, the accusation of racism is about a Dane attending far-right British rallies, British anti-immigration protests, and saying things about deporting the populations of Muslims and Romani from Britain, Copenhagen, and Denmark. It doesn't make much sense to call the DHH racism issue "American politics".
      • fixjruciri 7 hours ago
        I decided to read it at this one