Bonum Certa Men Certa

Containers Often Worsen Security and Docker Wants to Sell Security (the Microsoft Modus Operandi) for $9 Per Image Repository Per Month

posted by Roy Schestowitz on Oct 16, 2023

VPN User

WHEN the founder of Debian killed himself he was an employee of Docker, a company whose founder was ousted and whose new management became cozy with Microsoft. Microsoft bought some key people; it's the "clown computing" strategy, wherein you absorb the competition and infiltrate it (if you cannot just outright buy it). Then you sell your clown (vertical integration as vendor lock-in).

I've seen my share of Docker critics online and offline (at work), but they typically focus on technical limitations. Aside from the security implications of having many instances of the same packages (not just a waste of space; VMs are no better!) - a trend that gets copied across some packaging "technologies" - there are also lurking (hidden) fees. I'm not ignorant of containers; I've used them for years and even did "courses" for that in my last job. I'm not a fan of containers and I know how "clown computing" peddlers use these to overcharge people/companies/governments. Red Hat is among the culprits, it's not just a GAFAM "clown" thing.

As per SJVN [1], Docker wants money and pricing "for Scout is $9 per image repository per month for 4+ repos," just like IBM's Red Hat with "insights". It's proprietary and creates dependence; there's similar crap from Canonical (like "long-term" patches).

They hold you hostage. Pay us for "security" or get cracked! Welcome to Microsoft's mindset inside the GNU/Linux sphere.

Be wary. Think ahead.

Apropos, Microsofters [2] has just mentioned "ransomware gangs" without bothering to mention Windows, citing the Microsoft-infiltrated CISA. What lovely media we have; nobody criticises anything, it's just puff pieces and marketing, with a special place for Linux FUD.

Related/contextual items from the news:

  1. Docker Scout Unveils Advanced Features to Bolster Software Supply Chain Integrity

    In a significant move to enhance the software supply chain, Docker has released Docker Scout. Scout is a unified container security solution. It's designed to help developers quickly identify and fix vulnerabilities in all repositories. The program does this by scanning all your locally stored images, Scout will also provide up-to-date vulnerability information as you build your images. In addition, it also analyzes image contents and generates a detailed report of packages and vulnerabilities that it detects.

  2. CISA shares vulnerabilities, misconfigs used by ransomware gangs

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has unveiled additional details regarding misconfigurations and security vulnerabilities exploited by ransomware gangs, aiming to help critical infrastructure organizations thwart their attacks.

    CISA released this information as part of its Ransomware Vulnerability Warning Pilot (RVWP) program, established in January of this year, when it announced that it would warn critical infrastructure orgs of ransomware-vulnerable devices discovered on their network.

Other Recent Techrights' Posts

Trips to London
London isn't a bad place, but it's a long journey and we'd rather stay in Manchester and write about technology
SLAPP Censorship - Part 80 Out of 200: Having Run Out of Time to Meet a Judge's Deadline, Microsoft's Graveley Had Garrett's Lawyers Argued My ~190-Page Defence and CounterClaim (DCC) Was Unclear About My Position
Nothing could be further from the truth
Working in the Shell (and Fish)
Yesterday we spent about 5 hours on the shells and fish
The Corrupt Lecture the Non-Corrupt - Part XXVI - Campinos Has Put Unfit-for-Employment Drug Addicts in Charge of the European Patent Office (EPO)
How many months has Campinos got left before the delegates show him the door?
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, May 17, 2026
IRC logs for Sunday, May 17, 2026
Gemini Links 18/05/2026: Poetry, Sauna, and GNU Taler
Links for the day
"The Society of Media Lawyers" (UK) is a Truly Malicious Anti-Media Lobby Which Helps Rich/Abusive Americans and Hostile Countries Attack Actual Media Workers in the UK
They typically source their money from aboard to besiege domestic actors (like honest journalists or independent outlets that document suppressed beats/topics)
Slop Still Waning, Its Momentum is Driven by Companies That Stand to Lose a Lot (or Everything) When the Bubble Pops
When it comes to LLM slop disguised as news, it's just not working out
Gemini Links 17/05/2026: arXiv Brings Down the Hammer, UnderPOWERed, and Slopping With Tcl/Tk
Links for the day
Links 17/05/2026: Amazon Employees Herded Into Slop, Taiwan Sold Down the River by Cheeto
Links for the day
Links 17/05/2026: Society of Media Lawyers (Brett Wilson LLP et al) Lobby for More SLAPPs in the UK, “Courage in Journalism Award” Given in Oppressive Country
Links for the day
Finland Needs to Dump Microsoft (Microslop) for National Security Reasons and the Same is True for Hundreds of Countries
"I don't see why Ryssäs would want Finns to use microslop products..."
Cyber Show UK is Already Available Over Gemini Protocol
This past week the total number of active Gemini capsules hit all-time records several times
Fight Til the End
This comes to show that persistence pays off
SLAPP Censorship - Part 79 Out of 200: They Will Soon Reach the 100 KG (Kilograms) Milestone; Wheelbarrows, Not Justice (Quantity of Legal Papers Sent to Us)
It's about the quality, not quantity (unless your sole aim is to drown out or "flood the zone")
The Corrupt Lecture the Non-Corrupt - Part XXV - Not Bringing Intelligence to the EPO, Not 'Artificial Intelligence' Either (But Intelligence-Eroding Drugs)
The EPO was meant to be about science and law. In practice, however, it's about breaking the law and being stoned.
The Cyber Show on Why Coding is Important and Slop Cannot Change or Replace That
Hand-crafting one's site has plenty of advantages
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, May 16, 2026
IRC logs for Saturday, May 16, 2026
Gemini Links 17/05/2026: Music Theory, Reticulum Git Repos, and Releasing Kiln
Links for the day
Links 16/05/2026: Cuba Plunges Into Darkness (Energy Wasted by Nonsense), Googlebooks as Slop Nonsense (Energy Waste and Time Wasted)
Links for the day
Links 16/05/2026: Climate Issues, Free Speech, and Monopolies/Monopsonies
Links for the day
Gemini Links 16/05/2026: Retreat and Devuan Manuals
Links for the day
SLAPP Censorship - Part 78 Out of 200: Slandering Me for Saying the Truth About Graveley and Garrett's Abuse of Processes, Stacking Dockets
These are the sorts of things British taxpayers ought to talk about
"AI" Became a New Name or Placeholder for Debt
Because they will only ever lose money for this thing with "tokens" or "potential"
"Microsoft Goodwill and Intangible Assets" Down Two Years in a Row, According to Microsoft
Microsoft cannot sell these, so what is their real relevance?
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, May 15, 2026
IRC logs for Friday, May 15, 2026
IBM: Shares Down 30%, Mass Layoffs, IBM Says "Goodwill" Grew by 10% to Over a Third of the Company's Total "Worth"
According to IBM
Microsoft LinkedIn Layoffs "Very Likely Higher" Than 1,000 People
Microsoft is bleeding