4 ms·
> Do you know any publicly available recommendation from these regulators against MongoDB? If there isn't one, there should be. >Let's assume this is made the
by cookiecaper 7y ago
> Do you know any publicly available recommendation from these regulators against MongoDB?
If there isn't one, there should be.
>Let's assume this is made the top priority, in your opinion, what task immediately follows? Or what former priority does it replace?
Mongo jeopardizes the overall security and reliability of the system, thus exposing Stripe to serious liability, so I'd say replacing it is part of the basic expectation from any production-level computer system. Obviously I don't have a copy of "Important Stripe Person's Priority List", but I'd assume such basic functionality is part of an implicitly-assumed functional baseline, and that Stripe would expect said important people to escalate and develop a plan to handle such a fundamental flaw ASAP.
If we were just tracking people's favorite cat videos or something, it'd be one thing. Attacks targeting malicious data modification and exploitation of races wouldn't really be that much of a concern. It's not great to have that attack surface but not necessarily the end of the world if someone's favorite cat videos get added to their account 1000 times. But when we're dealing with money, this kind of thing needs to be taken seriously, and tacking on a big pile of crap in front of the datastore is not a serious way to address its fundamental shortcomings, at least not when there are many better, proven options on the market.
Just in case someone thinks I'm being an alarmist here, this has already happened; multiple bitcoin exchanges have been pwned due to their reliance on Mongo's flawed semantics. [1] I can only assume that systems like Stripe haven't been attacked similarly because it would provoke the ire of much bigger fish, and why do that when you can knock over smaller bitcoin exchanges?
[1] http://hackingdistributed.com/2014/04/06/another-one-bites-the-dust-flexcoin/ http://hackingdistributed.com/2014/04/06/another-one-bites-t...