So as another comment pointed out you don’t need to give your user account access to docker in this way, it’s an optional step, but one that I suspect many people do (since it’s part of the official docs).
What the LLM has done is silly, but completely possible. It climbed through the window that you left open.
But let’s jump to a different scenario, the ping command (on Linux). That’s a perfectly harmless command, right? You just want to say hello to another computer and see if they say hello back.
Except that historically the ping command was something called “setuid” which means when it ran it ran as root. It ran as root because in order for ping to work it has to create a special type of network packet that only root can create. But if you’re root you can run anything! So in theory ping opens a huge attack surface. If you have to worry about ping then is everything too complex to be manageable?
Luckily, as I said, this is a historical problem. The permissions ping needs have been moved to a specific capability and the command changed to utilize it and now ping can just run as a regular user without root privileges. But you can’t just make that change overnight. It takes a lot of time and effort.
So could the same be done for docker? Maybe. A rootless version of docker already exists. If you actually wanted to do what the LLM suggested, that wouldn’t work with a rootless docker, at least not without a bunch more configuration (and even then maybe).
So is security hard? Yes. Is it impossible? No.



So I can’t find a great answer, but as best I can tell StatCounter uses user agents to determine this data, the web browser being the most obvious source but not the only source.
The user agent for most web browsers on “macOS” the operating system generally report as “Mac OS X”. So other user agents, which report things like “Macintosh” but rarely actually “macOS”, are reported as “macOS”.
This also explains why “OS X” has a larger share than “macOS”. Web browsers on the macOS operating system are used more than “other”.
At first glance you’d think “OS X” and “macOS” should just be combined. But chances are if someone is using a web browser on macOS, they’re probably also using “other”.
Another problem is that we don’t know how StatCounter is handling duplicate/fake data. If I constantly hit refresh or send analytics from a single device, how is that counted? What if I send “OS X” and “macOS” data?
Luckily we also have the Cloudflare data, which shows Linux between 9% and 15%. So StatCounter using 10% is probably on the lower side, but within the margins.