4 ms·
Redis and Postgre are meant to play different roles. If you don't like what Redis does, you're welcome not to use it.
by theGimp 10y ago
Redis and Postgre are meant to play different roles.
If you don't like what Redis does, you're welcome not to use it.
- kogepathic 10y ago> If you don't like what Redis does, you're welcome not to use it. I like what Redis does, and it's also heavily used in industry. What I am saying, not incorrectly, is that their approach to security is harmful to their users. Most of whom won't know, care, or implement additional security which they should. It's the same argument with HTTPS. Of course HTTPS is optional in a web server, but all major web servers support HTTPS, and there has been a concentrated push to have more people using SSL. e.g. LetsEncrypt We should be making it easier for people to deploy secure services. Redis' approach to security makes it extremely difficult for developers to deploy secure services. I'll say it again: It's irresponsible in 2016/2017 to assume you have impenetrable perimeter security.
- jrudolph 10y agoI don't get why it would be that way? It's built to be deployed in a DMZ on a private network and that's how 99% of users (typically professionals) use it.
- deleted 10y ago[deleted]
- 1_2__3 10y agoThe idea of a hardened perimeter around a soft squishy interior has been proven repeatedly not to work.
- sgift 10y ago> I like what Redis does, and it's also heavily used in industry. What I am saying, not incorrectly, is that their approach to security is harmful to their users. Most of whom won't know, care, or implement additional security which they should. Then a different security story within redis wouldn't save them anyway. Security is not magic fairy dust that you sprinkle on something and then hope for the best.
- eropple 10y agoThis isn't really true. Envision a system where all components are secured by default: TLS-encrypted connections in and out (which doesn't currently really exist unless you put in the work), a VPN for entry, individualized SSH keys (via SSSD or something) for machine access controlled via group policies and whatever directory services are up for grabs. These are pretty commoditized parts that should be easily deployed and should be easily bolted together. And in such a universe, you do get a pretty strong security story without having to break your back. My main beef with stuff like Redis is that in almost every case I can think of it's selected by developers. Security isn't on their radar. The systemic component parts we currently have don't value security and offload it to the literally (not pejoratively) incompetent.
- kogepathic 10y ago> My main beef with stuff like Redis is that in almost every case I can think of it's selected by developers. Security isn't on their radar. The systemic component parts we currently have don't value security and offload it to the literally (not pejoratively) incompetent. Yes, this is exactly the point I was trying to make.
- zzzcpan 10y ago> Redis' approach to security makes it extremely difficult for developers to deploy secure services. TLS proxy is not extremely difficult to deploy if you really need to talk to redis that way. But you shouldn't be using redis if you do.
- z3t4 10y agoAuthentication and encryption takes a lot of CPU, but turning security OFF for performance reasons should always be behind a configuration flag. It's illegal to break into something, but if you leave the door wide open the insurance company might not be so willing, and in some laws it's actually legal to walk into open rooms.