Infosecurity.US

Information Security & Occasional Forays Into Adjacent Realms

  • Web Log

Docker Hub, The Backdoor

July 01, 2018 by Marc Handelman in Security Hygiene, Information Security, Container Security, Containerization

Dan Goodin, writing at Ars Technica, reported. last week of the backdooring of the Docker Hub by compromised Docker images placed on the site. Apparently, all is well now, as the backdoored image has been removed (after five solid months of public complaints)... The takeaway? Timely Security Hygiene Is A Crucial Attribute For Success Docker Hub Admins!

"Neither the Docker Hub account nor the malicious images it submitted were taken down. Over the coming months, the account went on to submit 14 more malicious images. The submissions were publicly called out two more times, once in January by security firm Sysdig and again in May by security company Fortinet. Eight days after last month's report, Docker Hub finally removed the images." - via Dan Goodin, writing at everyone's beloved Ars Technica

July 01, 2018 /Marc Handelman
Security Hygiene, Information Security, Container Security, Containerization

Daniel Stori's 'The CHROOT Case' →

January 14, 2018 by Marc Handelman in Sarcasm, Satire, Security Humor, Containerization, Container Security

via the non-containerized world-view of Daniel Stori at Turnoff.us!

January 14, 2018 /Marc Handelman
Sarcasm, Satire, Security Humor, Containerization, Container Security

Security, Containered →

January 02, 2018 by Marc Handelman in Containerization, Container Security

via author Tom Mackey, writing at Container Journal, comes this well-wrought piece targeting security challenges with container deployments. Today's Must Read.

January 02, 2018 /Marc Handelman
Containerization, Container Security

Alex Williams, Joe Beda, Sarah Novotny & Michael Rubin - 'SIGs and the Kubernetes Community' →

December 31, 2017 by Marc Handelman in Code, Containerization, Kubernetes, Microservices

Precious little about security, but interesting, nonetheless.

December 31, 2017 /Marc Handelman
Code, Containerization, Kubernetes, Microservices