'I’ve met a bunch of hardware engineers and I’ve made a point about asking each of them how they feel about using a single chip for multiple users. This is, of course, the use case of the cloud. All of the hardware engineers either laugh or are horrified and the resounding reaction is “you’d be crazy to think hardware was ever intended to be used for isolating multiple users safely.”'

I have talked with a whole lot of people who told me basically: "I do not need to think about all this security. I will put my app into a container anyways." Sometimes it is pure neglect, but most of the time they are pressured into it by the team leads who will do everything to ship fast.

A reminder why blindly trusting technology is a bad thing:

Isolating your processes by using docker (or similar techologies) is a neat thing but it does not exonerate you from implementing a solid security concept.

Understanding Docker container escapes

What is all this comodity with FaceApp?

Let's summarize the whole thing bluntly:

  • You gave a company access to your facial data and your name
  • The company behind FaceApp is russian and thus per (american) definition evil
  • You never read the Terms of Use
  • Now your facial data and name is not only stored in "THE CLOUD" but you also gave the company behind FaceApp the rights to use this data for everything they want

Let me ask you: Why are you upset?

