chroot'd environments only isolate at the filesystem level - ps will still list every process running on the system. Namespaces isolate at all levels; you have a brand-new process tree, your networking interfaces may be entirely different, you can wreak havoc as root inside while other processes outside observe and laugh.