Backdoored images downloaded from DockerHub 5 million times https://arstechnica.com/information-technology/2018/06/backdoored-images-downloaded-5-million-times-finally-removed-from-docker-hub/ https://kromtech.com/blog/security-center/cryptojacking-invades-cloud-how-modern-containerization-trend-is-exploited-by-attackers
Malware installed through DockerHub can also escape the container, so may continue to run.
Friends don't let friends install unreproducible black box container images.
docker, not so hot take? Show more
docker, not so hot take? Show more
docker, not so hot take? Show more
docker, not so hot take? Show more
docker, not so hot take? Show more
docker, not so hot take? Show more
docker, not so hot take? Show more
@cwebber I think we're on the same page (docker image as the vector of the attack and not the root cause).
No for the non-reproducibility part, I really lack cultural background (I'm a pretty young dev, self-taught, so it does not help :/), but I think you are right
All of this is reminding me of https://hackernoon.com/im-harvesting-credit-card-numbers-and-passwords-from-your-site-here-s-how-9a8cb347c5b5
(I cannot read the link you posted, I get an error)