4 ms·
They offer security as a paid feature.
by ibirman 7y ago
They offer security as a paid feature.
- jillesvangurp 7y agoActually it comes for free now with the standard ES distribution. https://www.elastic.co/blog/security-for-elasticsearch-is-now-free https://www.elastic.co/blog/security-for-elasticsearch-is-no...
- ThePowerOfFuet 7y ago>Security for Elasticsearch is now free What a horrific title. Even simply typing that should have been a blinking neon sign to them that they had their priorities in the wrong order.
- lmilcin 7y agoThat's incorrect. The usual way of using this service is to have backend network configured that connects your services that is not available from outside (ie you have to traverse through services to reach it). The so called "security" is just a paid feature for companies that want to use ElasticSearch but want to use it in "legacy" way because, presumably, they don't have people to design it correctly.
- dtech 7y agoThat's still really insecure, because it means that as soon as someone manages to gain any access to that network or any of the services on that network has a security issue your database is wide open. That means that if someone manages to get access to the. I'd say public internet with proper (encrypted) password auth is more secure than that.
- m00x 7y agoIf an attacker gets a hold of your app server, they will be able to get the connection details for that DB, including the username/password. Having a password adds a small layer of protection to databases that the affected app wasn't meant to connect to. It adds some protection in that case, but the user should use best judgement if it's worth doing.
- lmilcin 7y agoIf attacker has access to app server it is already game over. App server typically already has access to all of the data. The pods are akin to localhost networking where there is only one externally available application with multiple networked components.
- rbanffy 7y agoThat's true, but there are usually multiple ways to compromise protected networks. You still need to protect the database against attacks that don't go through the app server.