

It would depend on having access to misconfigured permissions or docker.sock like when you chain containers to manage other containers. Because you have access to docker.sock and that socket can send API calls to the docker daemon (which is run from root) those commands would inherit the same level of access. An attacker could make the API call to mount /:/root and then access the host filesystem.
It’s just an example of how even though the container might not have anything worthwhile, it can be used to laterally move and open another door.


The way I view Steam Machines is just as a delivery system for SteamOS. I don’t know if Valve even thinks Steam Machines will themselves be successful. I’m thinking they are betting on enough users adopting Steam Machines that they will get a foothold with their OS and start pushing Microsoft out.
And that kinda makes sense as Microsoft is going the “AI first” route and focusing on productivity. That leaves an opening (if albeit a small one currently) for companies like Valve to pull users into their “Gamers first” SteamOS.