4 ms·
I cannot believe, that so many users install MongoDB, only using default settings and installed on servers, which are accessible via the internet. That is fund
by UlrichC 10y ago
I cannot believe, that so many users install MongoDB, only using default settings and installed on servers, which are accessible via the internet.
That is fundamentally wrong application design. The application connects to the database, so the database must not be public accessible via internet.
I mean, if you push something into a production environment, you must think a bit about the tools you are using and how they are configured for security.
On a development system, I don't want to setup users or auth-mechanisms.
There are so many resources from MongoDB, how you can secure your MongoDB database:
- Security Architecture White Paper: https://www.mongodb.com/collateral/mongodb-security-architecture https://www.mongodb.com/collateral/mongodb-security-architec...
- Security Best Practices blog post: https://www.mongodb.com/blog/post/how-to-avoid-a-malicious-attack-that-ransoms-your-data https://www.mongodb.com/blog/post/how-to-avoid-a-malicious-a...
There is even a checklist which you can work through:
https://docs.mongodb.com/manual/administration/security-checklist https://docs.mongodb.com/manual/administration/security-chec...
And for those, who don't want to read anything ;-), there is a comprehensive Video-Course on the MongoDB-university:
https://university.mongodb.com/courses/M310/about https://university.mongodb.com/courses/M310/about
If I enter a car and don't use the seat-belt or switch on the light at night (defaults are off), then I cannot blame the car-manufacturer. If I use something important (here the database in a production environment), then I have to learn the ropes and read the material specifically on security topics.