*golf clap*
Qualys published multiple bypasses not even a month ago.
Know what's better than a user namespace? Not having users in your image to begin with! You can deploy your software without users with nanos unikernels.
*golf clap*
Qualys published multiple bypasses not even a month ago.
Know what's better than a user namespace? Not having users in your image to begin with! You can deploy your software without users with nanos unikernels.
Of course if you were using nanos unikernels you wouldn't need to think about this.
Of course if you were using nanos unikernels you wouldn't need to think about this.
while most of this should prob be done at the network level we've added more control to our fw klib to drop fragments at the unikernel instance level
while most of this should prob be done at the network level we've added more control to our fw klib to drop fragments at the unikernel instance level