--userns=auto asign a different namespace for each container, so if you escape it you get a random uid far far away from root
it also protects other containers from the compromise since they each have their own namespace and uid/gid range, the drawback though is that you can't mount shared volume unless you use a pod, since you would see files from outside your uid/gid range as owned by nobody and inaccessible.
Since in --userns=auto, root inside the container gets assigned to the first uid of the uid range assigned by podman, copyfail would succeed but you'd get uid 647831 and be able to do nothing with it
Is this supposed to be ... a gotcha? If slavery is involved, it's not capitalism, by definition. Distance attenuates all signals, so each transaction step may somewhat smear or smudge such a stain. Really not clear at all what you're getting at.
I am pretty sure they know our identity pretty accurately already, through browser fingerprinting and google's gmail data, my real concern is the half-assed security measure with our id cards.
The persona breach just recently proved they cannot be trusted and this expose us to identity fraud/theft.
I read that during the irish occupation, irish policemen (so, working for the british governement) were rejected and isolated socially, treated as traitors to their people.
Which led them to eventually refuse to continue oppressing their people for money, the revolution, independance, all that.
Did you know the early nazis where actually impressed by america's segregation and racism and lamented they couldn't easily do the same? Well, they kinda did in the end.
White men are the most privileged and protected class oh prople in the accident, all this is bullshit.
You have no idea what people outside of it are saying because you don't talk to them, you've just been endoctrined by the media playing on your fears of the unknown and of losing some of those privileges.
But the thing is, the most privilegied losing privileges isn't something horrible, it's simple justice, restoring the balance.
reply