4 ms·
Erm, not opening up this fucking Elasticsearch instance to the entire internet would be a pretty easy way to get like 90% of the way there. I do operations. I c
by mmiller9 8y ago
Erm, not opening up this fucking Elasticsearch instance to the entire internet would be a pretty easy way to get like 90% of the way there. I do operations. I can tell you exactly how not to make rookie mistakes like this. But security isn’t sexy, and it isn’t profitable, so it falls by the wayside.
- aalleavitch 8y agoThe problem isn’t that these people are incompetent at network security (they are), the problem is that these people had your data to begin with. Data security is impossible because there is a massive shadow market for your entire life history and no amount of privacy setting theater will make up for the fact that your personal data is currently the target of an insatiable feeding frenzy.
- jonhendry18 8y agoPerhaps someone was paid to open the Elasticsearch to the entire internet so that the buyer could grab the data.
- flukus 8y ago> I do operations. I can tell you exactly how not to make rookie mistakes like this But you guys are expensive and management can't tell what you do, so we invented devops to make the developers do it. It worked perfectly until it didn't. Seriously though, as a dev with script kiddie levels of pen-testing skills it's amazing the amount of potential exploits out there. Even where I work with sensitive data it's assumed that the only attack vector is external.