<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[I’ve mentioned this before: this is one of the oncoming trains for corp-security.]]></title><description><![CDATA[<p>I’ve mentioned this before: this is one of the oncoming trains for corp-security. We’ve long failed at least-privilege, but weren’t often punished for it.</p><p>Helen in HR (or Bob in accounts) didn’t know what to do with the extra perms they didn’t know they had.</p><p>Their agents will.</p>]]></description><link>https://board.circlewithadot.net/topic/622ec5c4-71f2-4778-b9c2-9b167e5252ee/i-ve-mentioned-this-before-this-is-one-of-the-oncoming-trains-for-corp-security.</link><generator>RSS for Node</generator><lastBuildDate>Sat, 06 Jun 2026 05:13:56 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/622ec5c4-71f2-4778-b9c2-9b167e5252ee.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 31 May 2026 20:02:53 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to I’ve mentioned this before: this is one of the oncoming trains for corp-security. on Mon, 01 Jun 2026 15:45:07 GMT]]></title><description><![CDATA[<p><span><a href="/user/webhat%40infosec.exchange">@<span>webhat</span></a></span> <span><a href="/user/haroonmeer%40infosec.exchange">@<span>haroonmeer</span></a></span> also add:  "don't say anything about goblins"</p>]]></description><link>https://board.circlewithadot.net/post/https://techhub.social/ap/users/116070070148560601/statuses/116675622159516438</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://techhub.social/ap/users/116070070148560601/statuses/116675622159516438</guid><dc:creator><![CDATA[aj@techhub.social]]></dc:creator><pubDate>Mon, 01 Jun 2026 15:45:07 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve mentioned this before: this is one of the oncoming trains for corp-security. on Mon, 01 Jun 2026 15:05:52 GMT]]></title><description><![CDATA[<p><span><a href="/user/haroonmeer%40infosec.exchange">@<span>haroonmeer</span></a></span> Will this still work if docker is not run as root but as an unprivileged user?</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.sandwich.net/users/shadur/statuses/116675467861435268</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.sandwich.net/users/shadur/statuses/116675467861435268</guid><dc:creator><![CDATA[shadur@mastodon.sandwich.net]]></dc:creator><pubDate>Mon, 01 Jun 2026 15:05:52 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve mentioned this before: this is one of the oncoming trains for corp-security. on Mon, 01 Jun 2026 14:41:12 GMT]]></title><description><![CDATA[<span><a href="/user/feld%40friedcheese.us" rel="ugc">@<span>feld</span></a></span> <span><a href="/user/haroonmeer%40infosec.exchange" rel="ugc">@<span>haroonmeer</span></a></span> Why are we so worried about agents using this when the user had the rights in the first place? Agents/LLMs should change nothing in that equation.]]></description><link>https://board.circlewithadot.net/post/https://fluffytail.org/objects/3a35d744-235e-4952-b23d-9506491b0e55</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://fluffytail.org/objects/3a35d744-235e-4952-b23d-9506491b0e55</guid><dc:creator><![CDATA[phnt@fluffytail.org]]></dc:creator><pubDate>Mon, 01 Jun 2026 14:41:12 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve mentioned this before: this is one of the oncoming trains for corp-security. on Mon, 01 Jun 2026 14:39:11 GMT]]></title><description><![CDATA[<span><a href="/user/haroonmeer%40infosec.exchange" rel="ugc">@<span>haroonmeer</span></a></span> why are we so worried about agents using this when this was already the first thing any attacker would do?<br /><br />Pop a shell on Linux, check for docker group access. That makes life very easy.]]></description><link>https://board.circlewithadot.net/post/https://friedcheese.us/objects/9fe0c17e-1f5e-4910-bfa1-c6abbe8e1ac6</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://friedcheese.us/objects/9fe0c17e-1f5e-4910-bfa1-c6abbe8e1ac6</guid><dc:creator><![CDATA[feld@friedcheese.us]]></dc:creator><pubDate>Mon, 01 Jun 2026 14:39:11 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve mentioned this before: this is one of the oncoming trains for corp-security. on Mon, 01 Jun 2026 13:58:57 GMT]]></title><description><![CDATA[<p><span><a href="/user/mdione%40en.osm.town">@<span>mdione</span></a></span> <span><a href="/user/haroonmeer%40infosec.exchange">@<span>haroonmeer</span></a></span> Honestly, I can see the appeal of docker as a sort of web services oriented package manager; but it's terrifying to see people treating it as though it's a VM-tier isolation tool or security boundary. It's certainly not impossible to use it in ways that provide at least some protection from container contents; but the overall intent is much closer to easing dependency wrangling and keeping configs contained than to hard isolation.</p>]]></description><link>https://board.circlewithadot.net/post/https://cyberplace.social/users/fuzzyfuzzyfungus/statuses/116675204679570882</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://cyberplace.social/users/fuzzyfuzzyfungus/statuses/116675204679570882</guid><dc:creator><![CDATA[fuzzyfuzzyfungus@cyberplace.social]]></dc:creator><pubDate>Mon, 01 Jun 2026 13:58:57 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve mentioned this before: this is one of the oncoming trains for corp-security. on Mon, 01 Jun 2026 13:40:57 GMT]]></title><description><![CDATA[<p><span><a href="/user/mdione%40en.osm.town">@<span>mdione</span></a></span> <span><a href="/user/haroonmeer%40infosec.exchange">@<span>haroonmeer</span></a></span> Docker can map to a user other than root; but it leaves whether or not it does so up to you. I'm not sure if there's some specialty lockdown config that tightens this; but by default docker doesn't even seem to intend to protect the host from the user; and leaves it up to the user whether they want any actual protection from container contents or not. </p><p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://www.docker.com/blog/understanding-the-docker-user-instruction/" title="Understanding the Docker USER Instruction | Docker">
<img src="https://www.docker.com/app/uploads/2023/12/square_docker-tips-1024x1024.png" class="card-img-top not-responsive" style="max-height: 15rem;" alt="Link Preview Image" />
</a>



<div class="card-body">
<h5 class="card-title">
<a href="https://www.docker.com/blog/understanding-the-docker-user-instruction/">
Understanding the Docker USER Instruction | Docker
</a>
</h5>
<p class="card-text line-clamp-3">Discover best practices and common pitfalls associated with the Docker USER instruction. Also get a hands-on demo to learn the importance of these practices.</p>
</div>
<a href="https://www.docker.com/blog/understanding-the-docker-user-instruction/" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://www.docker.com/app/uploads/2024/02/cropped-docker-logo-favicon-32x32.png" alt="favicon" class="not-responsive overflow-hiddden" style="max-width: 21px; max-height: 21px;" />







<p class="d-inline-block text-truncate mb-0">Docker <span class="text-secondary">(www.docker.com)</span></p>
</a>
</div></p>]]></description><link>https://board.circlewithadot.net/post/https://cyberplace.social/users/fuzzyfuzzyfungus/statuses/116675133930152264</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://cyberplace.social/users/fuzzyfuzzyfungus/statuses/116675133930152264</guid><dc:creator><![CDATA[fuzzyfuzzyfungus@cyberplace.social]]></dc:creator><pubDate>Mon, 01 Jun 2026 13:40:57 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve mentioned this before: this is one of the oncoming trains for corp-security. on Mon, 01 Jun 2026 13:08:02 GMT]]></title><description><![CDATA[<p><span><a href="/user/haroonmeer%40infosec.exchange">@<span>haroonmeer</span></a></span> <span><a href="/user/jackeric%40beige.party">@<span>jackeric</span></a></span> agents are very clever. I’ve seen them try all kinds of things like this just to “get the task done.” I’ve only noticed because I put them in sandbox-exec.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/kumarvibe/statuses/116675004483206172</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/kumarvibe/statuses/116675004483206172</guid><dc:creator><![CDATA[kumarvibe@mastodon.social]]></dc:creator><pubDate>Mon, 01 Jun 2026 13:08:02 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve mentioned this before: this is one of the oncoming trains for corp-security. on Mon, 01 Jun 2026 08:54:10 GMT]]></title><description><![CDATA[<p><span><a href="/user/mdione%40en.osm.town">@<span>mdione</span></a></span> <span><a href="/user/stux%40mstdn.social">@<span>stux</span></a></span> <span><a href="/user/haroonmeer%40infosec.exchange">@<span>haroonmeer</span></a></span> </p><p>Feels like sabotage</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/expertenkommision_cyberunfall/statuses/116674006221647473</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/expertenkommision_cyberunfall/statuses/116674006221647473</guid><dc:creator><![CDATA[expertenkommision_cyberunfall@mastodon.social]]></dc:creator><pubDate>Mon, 01 Jun 2026 08:54:10 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve mentioned this before: this is one of the oncoming trains for corp-security. on Mon, 01 Jun 2026 08:51:45 GMT]]></title><description><![CDATA[<p><span><a href="/user/haroonmeer%40infosec.exchange">@<span>haroonmeer</span></a></span> but isn't the docker's `root` user mapped to a host's transient normal user?</p>]]></description><link>https://board.circlewithadot.net/post/https://en.osm.town/users/mdione/statuses/116673996746592401</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://en.osm.town/users/mdione/statuses/116673996746592401</guid><dc:creator><![CDATA[mdione@en.osm.town]]></dc:creator><pubDate>Mon, 01 Jun 2026 08:51:45 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve mentioned this before: this is one of the oncoming trains for corp-security. on Mon, 01 Jun 2026 08:50:30 GMT]]></title><description><![CDATA[<p><span><a href="/user/expertenkommision_cyberunfall%40mastodon.social">@<span>expertenkommision_cyberunfall</span></a></span> <span><a href="/user/stux%40mstdn.social">@<span>stux</span></a></span> <span><a href="/user/haroonmeer%40infosec.exchange">@<span>haroonmeer</span></a></span> and some corps forces us to do it.</p>]]></description><link>https://board.circlewithadot.net/post/https://en.osm.town/users/mdione/statuses/116673991851133331</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://en.osm.town/users/mdione/statuses/116673991851133331</guid><dc:creator><![CDATA[mdione@en.osm.town]]></dc:creator><pubDate>Mon, 01 Jun 2026 08:50:30 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve mentioned this before: this is one of the oncoming trains for corp-security. on Mon, 01 Jun 2026 05:49:56 GMT]]></title><description><![CDATA[<p><span><a href="/user/stux%40mstdn.social">@<span>stux</span></a></span> <span><a href="/user/haroonmeer%40infosec.exchange">@<span>haroonmeer</span></a></span> </p><p>And corp encourages them to do do.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/expertenkommision_cyberunfall/statuses/116673281793028639</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/expertenkommision_cyberunfall/statuses/116673281793028639</guid><dc:creator><![CDATA[expertenkommision_cyberunfall@mastodon.social]]></dc:creator><pubDate>Mon, 01 Jun 2026 05:49:56 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve mentioned this before: this is one of the oncoming trains for corp-security. on Mon, 01 Jun 2026 05:12:08 GMT]]></title><description><![CDATA[<p><span><a href="/user/haroonmeer%40infosec.exchange">@<span>haroonmeer</span></a></span> As a last resort it would have probably tried running the copyfail exploit.</p>]]></description><link>https://board.circlewithadot.net/post/https://social.tchncs.de/users/cgudrian/statuses/116673133182341768</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.tchncs.de/users/cgudrian/statuses/116673133182341768</guid><dc:creator><![CDATA[cgudrian@social.tchncs.de]]></dc:creator><pubDate>Mon, 01 Jun 2026 05:12:08 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve mentioned this before: this is one of the oncoming trains for corp-security. on Mon, 01 Jun 2026 03:56:37 GMT]]></title><description><![CDATA[<p><span><a href="/user/haroonmeer%40infosec.exchange">@<span>haroonmeer</span></a></span> at least it didn't use the latest linux exploit</p>]]></description><link>https://board.circlewithadot.net/post/https://mamot.fr/users/tdelmas/statuses/116672836270784157</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mamot.fr/users/tdelmas/statuses/116672836270784157</guid><dc:creator><![CDATA[tdelmas@mamot.fr]]></dc:creator><pubDate>Mon, 01 Jun 2026 03:56:37 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve mentioned this before: this is one of the oncoming trains for corp-security. on Mon, 01 Jun 2026 00:33:47 GMT]]></title><description><![CDATA[<p><span><a href="/user/haroonmeer%40infosec.exchange">@<span>haroonmeer</span></a></span> feeling less stupid for being paranoid enough to not add my user to the docker group.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/ap/users/116660985003036425/statuses/116672038675977990</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/ap/users/116660985003036425/statuses/116672038675977990</guid><dc:creator><![CDATA[ahhhhhhhhhhh@mastodon.social]]></dc:creator><pubDate>Mon, 01 Jun 2026 00:33:47 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve mentioned this before: this is one of the oncoming trains for corp-security. on Sun, 31 May 2026 23:57:37 GMT]]></title><description><![CDATA[<p><span><a href="/user/haroonmeer%40infosec.exchange">@<span>haroonmeer</span></a></span> People are willingly installing malware now, heck.. they’re even paying for it</p>]]></description><link>https://board.circlewithadot.net/post/https://mstdn.social/users/stux/statuses/116671896482893341</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mstdn.social/users/stux/statuses/116671896482893341</guid><dc:creator><![CDATA[stux@mstdn.social]]></dc:creator><pubDate>Sun, 31 May 2026 23:57:37 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve mentioned this before: this is one of the oncoming trains for corp-security. on Sun, 31 May 2026 23:05:47 GMT]]></title><description><![CDATA[<p><span><a href="/user/haroonmeer%40infosec.exchange">@<span>haroonmeer</span></a></span> </p><p>Yeah it's like Cliff Stoll and sendmail all over anew (yes I'm that old). Docker frequently writes root owned files to the FS. We are a dumb species.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/megatronicthronbanks/statuses/116671692624312808</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/megatronicthronbanks/statuses/116671692624312808</guid><dc:creator><![CDATA[megatronicthronbanks@mastodon.social]]></dc:creator><pubDate>Sun, 31 May 2026 23:05:47 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve mentioned this before: this is one of the oncoming trains for corp-security. on Sun, 31 May 2026 22:41:12 GMT]]></title><description><![CDATA[<p><span><a href="/user/webhat%40infosec.exchange">@<span>webhat</span></a></span> <span><a href="/user/haroonmeer%40infosec.exchange">@<span>haroonmeer</span></a></span> <br />ha ha ha <br />Uninstalling the Agent is the only solution.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.ie/users/raymaccarthy/statuses/116671595997484325</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.ie/users/raymaccarthy/statuses/116671595997484325</guid><dc:creator><![CDATA[raymaccarthy@mastodon.ie]]></dc:creator><pubDate>Sun, 31 May 2026 22:41:12 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve mentioned this before: this is one of the oncoming trains for corp-security. on Sun, 31 May 2026 22:32:32 GMT]]></title><description><![CDATA[<p><span><a href="/user/haroonmeer%40infosec.exchange">@<span>haroonmeer</span></a></span> I had a problem with corporate security theatre getting in the way of something I needed to do.</p><p>So I asked the corporate provided AI how to get round the corporate security theatre.</p><p>And instead of reporting me to security it gave me some code. (Which, in the nature of AI generated code, didn't actually work, but it did give me the clue necessary to write my own code which did work.)</p>]]></description><link>https://board.circlewithadot.net/post/https://c.im/users/TimWardCam/statuses/116671561872321448</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://c.im/users/TimWardCam/statuses/116671561872321448</guid><dc:creator><![CDATA[timwardcam@c.im]]></dc:creator><pubDate>Sun, 31 May 2026 22:32:32 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve mentioned this before: this is one of the oncoming trains for corp-security. on Sun, 31 May 2026 21:41:33 GMT]]></title><description><![CDATA[<p><span><a href="/user/rickf%40indieweb.social">@<span>rickf</span></a></span> <span><a href="/user/haroonmeer%40infosec.exchange">@<span>haroonmeer</span></a></span> <span><a href="/user/tindrasgrove%40infosec.exchange">@<span>TindrasGrove</span></a></span> </p><p>Still no use case for <a href="https://infosec.exchange/tags/Ai" rel="tag">#<span>Ai</span></a> and apparently <a href="https://infosec.exchange/tags/LLM" rel="tag">#<span>LLM</span></a> are useless...</p><p>(I should start a file of these)</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/n_dimension/statuses/116671361386767652</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/n_dimension/statuses/116671361386767652</guid><dc:creator><![CDATA[n_dimension@infosec.exchange]]></dc:creator><pubDate>Sun, 31 May 2026 21:41:33 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve mentioned this before: this is one of the oncoming trains for corp-security. on Sun, 31 May 2026 21:26:50 GMT]]></title><description><![CDATA[<p><span><a href="/user/haroonmeer%40infosec.exchange">@<span>haroonmeer</span></a></span> I mean, right away the solution would be podman, not docker. Podman doesn't require root level privs to run.</p>]]></description><link>https://board.circlewithadot.net/post/https://social.linux.pizza/users/wydamn/statuses/116671303562850304</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.linux.pizza/users/wydamn/statuses/116671303562850304</guid><dc:creator><![CDATA[wydamn@social.linux.pizza]]></dc:creator><pubDate>Sun, 31 May 2026 21:26:50 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve mentioned this before: this is one of the oncoming trains for corp-security. on Sun, 31 May 2026 21:05:40 GMT]]></title><description><![CDATA[<p><span><a href="/user/haroonmeer%40infosec.exchange">@<span>haroonmeer</span></a></span> I wasn't even aware codex ran locally? I thought it was just in the browser with shitty github connections.</p>]]></description><link>https://board.circlewithadot.net/post/https://hear-me.social/ap/users/115696907373093865/statuses/116671220335496103</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hear-me.social/ap/users/115696907373093865/statuses/116671220335496103</guid><dc:creator><![CDATA[netraven@hear-me.social]]></dc:creator><pubDate>Sun, 31 May 2026 21:05:40 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve mentioned this before: this is one of the oncoming trains for corp-security. on Sun, 31 May 2026 20:41:13 GMT]]></title><description><![CDATA[<p><span><a href="/user/haroonmeer%40infosec.exchange">@<span>haroonmeer</span></a></span> <span><a href="/user/tindrasgrove%40infosec.exchange">@<span>TindrasGrove</span></a></span> </p><p>I am so glad I’m no longer in the operational security world anymore ….. these problems are going to grow exponentially* and so will the corresponding burnout.</p><p>* on top of the ongoing usual problems that should’ve been fixed / addressed 20 years ago but still haven’t.</p>]]></description><link>https://board.circlewithadot.net/post/https://indieweb.social/users/rickf/statuses/116671124149419981</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://indieweb.social/users/rickf/statuses/116671124149419981</guid><dc:creator><![CDATA[rickf@indieweb.social]]></dc:creator><pubDate>Sun, 31 May 2026 20:41:13 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve mentioned this before: this is one of the oncoming trains for corp-security. on Sun, 31 May 2026 20:26:27 GMT]]></title><description><![CDATA[<p><span><a href="/user/haroonmeer%40infosec.exchange">@<span>haroonmeer</span></a></span> <span><a href="/user/temptoetiam%40eldritch.cafe">@<span>temptoetiam</span></a></span> that’s also the end of parental control, I guess.</p>]]></description><link>https://board.circlewithadot.net/post/https://piaille.fr/users/nholzschuch/statuses/116671066104291696</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://piaille.fr/users/nholzschuch/statuses/116671066104291696</guid><dc:creator><![CDATA[nholzschuch@piaille.fr]]></dc:creator><pubDate>Sun, 31 May 2026 20:26:27 GMT</pubDate></item><item><title><![CDATA[Reply to I’ve mentioned this before: this is one of the oncoming trains for corp-security. on Sun, 31 May 2026 20:14:22 GMT]]></title><description><![CDATA[<p><span><a href="/user/haroonmeer%40infosec.exchange">@<span>haroonmeer</span></a></span> they need to add: "Don't hack stuff" to the prompt, that will protect them</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/webhat/statuses/116671018630617370</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/webhat/statuses/116671018630617370</guid><dc:creator><![CDATA[webhat@infosec.exchange]]></dc:creator><pubDate>Sun, 31 May 2026 20:14:22 GMT</pubDate></item></channel></rss>