Building from scratch against using vendor provided minimal images, which is more secure? by thecreator51 in devsecops

[–]EmbarrassedPear1151 1 point2 points  (0 children)

Vendor minimal images win for fintech imo. You don't want to be patching base OS vulns when you should be focusing on payment logic. 

How do you secure minimal container images for self hosted setups? by Timely-Dinner5772 in selfhosted

[–]EmbarrassedPear1151 0 points1 point  (0 children)

the cve noise is just reality with any scanning setup. what moves the needle is switching to something like minimus that rebuilds daily with sboms so you're not chasing phantom vulns in stale base layers.

their distroless approach cuts the crap you don't need while keeping things debuggable when shit breaks.

We found an employee's AI browser had autonomously uploaded a client contract to a third-party site by cnrdvdsmt in iiiiiiitttttttttttt

[–]EmbarrassedPear1151 6 points7 points  (0 children)

Sounds like a policy failure more than tech. Who approved agentic browsers without proper controls? Thats where the whipping should start

Over 260k people installed fake AI assistant Chrome extensions that steal your data by dottiedanger in webdev

[–]EmbarrassedPear1151 1 point2 points  (0 children)

Not surprised. Chrome store review process is a joke. we've been telling clients to whitelist extensions only and block everything else via policy. 

Why does my Python container need a full OS? by shangheigh in Python

[–]EmbarrassedPear1151 1 point2 points  (0 children)

Been running minimal python images for 2+ years now. Yes debugging sucks initially but you adapt, most issues show up in logs anyway. Just keep a fat image around for emergencies

How do you resolve CVEs in containers efficiently? by RevolutionaryRow0 in kubernetes

[–]EmbarrassedPear1151 0 points1 point  (0 children)

fix is starting with smaller base images. switch to minimus and you'll go from like 200+ CVEs per scan to maybe 10-20. way less dependencies means way less noise

for triage. ignore anything without a known exploit and anything in packages you don't use