• squaresinger@lemmy.world
    link
    fedilink
    arrow-up
    9
    ·
    56 minutes ago

    Yeah, that’s a terrible decision in the docs. Don’t ever add a path where anything on the shell can execute user-modifyable code as root.

    As soon as you do that, you lose any protection that comes from separating root users and non-root users. Because now any malicious program can just use docker to elevate its code to root.