4 ms·
In the words of Phineas Fisher: "NoSQL, or rather NoAuthentication, has been a huge gift to the hacker community. Just when I was worried that they'd finally p
by opaque 10y ago
In the words of Phineas Fisher:
"NoSQL, or rather NoAuthentication, has been a huge gift to the hacker community. Just when I was worried that they'd finally patched all of the authentication bypass bugs in MySQL, new databases came into style that lack authentication by design."
From his account of the Hacking Team Hack, worth a read if you missed it.
http://pastebin.com/raw/0SNSvyjJ http://pastebin.com/raw/0SNSvyjJ
- ethbro 10y agoStep 1) Bemoan how {OldSoftwarePackage} doesn't do X, Y, Z Step 2) Write {NewSoftwarePackage} that does most of what {OldSoftwarePackage} did + X Step 3) Spend an order of magnitude more time than expected finishing Y, which turns out to actually be rather hard because {Messy Real World Engineering Details} Step 4) Never get to Z & eventually come up with a narrative about how Z was stupid anyway
- Karunamon 10y agoHeh, sounds like how software is improved. Then when the next guy who wants Z comes along...
- monksy 10y agoDon't worry .. it's Agile! We'll just keep pushing that feature back until we loose business. Later: "Remember people that was an MVP"
- MichaelGG 10y agoNot sure what exactly you mean wrt NoAuth DBs, but having a simple on-connect password would be an improvement to all those databases. Things like Elasticsearch not having even a basic password (esp since it's HTTP so it's trivial) is simply silly. And it's probably not a good idea to support no-auth connections at all - if it's really a hassle, just set the user/pass to the host name.
- pyre 10y ago> Elasticsearch Yea. I found that surprising when it came time to use ElasticSearch for my own purposes. If you want security, you need to setup something between the ElasticSearch server and the clients to moderate.
- jrgnsd 10y agoSetting up nginx to proxy to Elasticsearch with HTTP auth on top is fairly trivial. There's a couple of good articles on the web if you google for it. Also, should you have an Elasticsearch support contract, you get access to the Shield plugin which has extensive access control. But yes, the fact that it is open OOTB is frustrating.
- pyre 10y agoThis is exactly what I do, but the fact that it's wide open and relies on you to use a different (and de-coupled) service for permissions was surprising to me (at the time).