Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Restricting arbitrary downloads from curl, wget or bash (or better, any binary) makes these attacks pretty much useless.

Any advice what that looks like for a docker container? My border firewall isn't going to know what binary made the request, and I'm not aware of per-process restrictions of that kind



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: