You are viewing the 2025 edition of FOSDEM. Click here to view the 2026 edition
Dangerzone: Containers that contain containers that contain attackers
UD2.218A | Day 1 | 17:40 - 18:10 | Speakers: Alex Pyrgiotis
Dangerzone: Containers that contain containers that contain attackers
Abstract
Dangerzone is a multi-platform project that performs a simple task; give it an untrusted document, and get back a sanitized one. Qubes did it first with disposable Xen VMs (see TrustedPDF), but Dangerzone is doing it with containers across all major platforms. How secure are containers though, and can you achieve VM-level parity with them?
In this talk we’ll discuss the attack surface of Linux containers, and how Dangezone uses gVisor to contain RCEs in document viewers. Even if you don’t use gVisor or are not interested in it, we’ll show some easy ways to harden your security-sensitive containers right now, for harm reduction purposes.
Speakers
Alex Pyrgiotis
Links
External Links
Notice: The placeholder video image is licensed under CC BY-SA 4.0. The original image can be found hereChanges made to the image are: Cropped the image to a new ratio, part of the image was cut off.
