
BSidesSF: Sandboxes, Seccomp, and Syscalls: Chasing Isolation in Kubernetes
BSidesSF talk on building RCEaaS in K8s environments and the pitfals of system-call based security
/dev/loop3 ro squashfs ---------------------------------------------------------~inode 0x4e21c8
uts:ns 4026532198 ----------------------------------------------------------#cap_sys_admin -eff
seccomp filt 0x1f ---------------------------------------------------------#rtt 12.4ms mtu 1500
::fe80::4a2c/64 ::::::::::::::::::::::::::::::::::::::::::::::::::::::::[vmalloc 0xffffc90000]
Containers, kubernetes, AI, sandboxes, security, Linux isolation
and whatever else looks interesting enough to take apart.

BSidesSF talk on building RCEaaS in K8s environments and the pitfals of system-call based security














3 talks
1 talk
2013Hover a talk
Select any tile above to see its details and links.