Skip to main content

Dangerzone: Containers that contain containers that contain attackers

UD2.218A | Day 1 | 17:40 - 18:10 | Speakers: Alex Pyrgiotis

Dangerzone: Containers that contain containers that contain attackers
A picture of a devroom at FOSDEM 2024
Open in browser

Notes

Abstract

Dangerzone is a multi-platform project that performs a simple task; give it an untrusted document, and get back a sanitized one. Qubes did it first with disposable Xen VMs (see TrustedPDF), but Dangerzone is doing it with containers across all major platforms. How secure are containers though, and can you achieve VM-level parity with them?

In this talk we’ll discuss the attack surface of Linux containers, and how Dangezone uses gVisor to contain RCEs in document viewers. Even if you don’t use gVisor or are not interested in it, we’ll show some easy ways to harden your security-sensitive containers right now, for harm reduction purposes.

Speakers

Alex Pyrgiotis

Notice: The placeholder video image is licensed under CC BY-SA 4.0. The original image can be found hereChanges made to the image are: Cropped the image to a new ratio, part of the image was cut off.