• squaresinger@lemmy.world
    link
    fedilink
    arrow-up
    13
    ·
    2 hours ago

    Yeah, that’s a terrible decision in the docs. Don’t ever add a path where anything on the shell can execute user-modifyable code as root.

    As soon as you do that, you lose any protection that comes from separating root users and non-root users. Because now any malicious program can just use docker to elevate its code to root.