3 ms·
> as soon as I see MQTT (or any other abstraction layer above UDP or TCP/IP) I know that doom follows. As someone who works on MQTT server technology, this opi
by jonquark 6y ago
> as soon as I see MQTT (or any other abstraction layer above UDP or TCP/IP) I know that doom follows.
As someone who works on MQTT server technology, this opinion surprised me - it's a lot easier to get the security right using an MQTT server - user credentials are part of the protocol where as you have to build it yourself if you start at the TCP/UDP layer.
The problem in this example wasn't that they were using MQTT it's that there was no authentication/authorisation checking done - normally achieved by configuration - that would be possible in TCP as well - by not implementing it ;)
- bsder 6y ago> As someone who works on MQTT server technology, this opinion surprised me Why? It's practically tautological. The technology is irrelevant--it's all about the users. The set of people using MQTT is: 1) The clueless (those who don't know better or the buzzword-driven) 2) The clueful with no power or cost constraints (to first, second and third approximation--a null set) because if you add constraints to someone with clue, they will dump everything above UDP or TCP/IP. Thus, MQTT == DOOM. (If I'm being less uncharitable, an MQTT broker is a service I don't control and have no visibility into. It only takes being on the receiving end of one bitchfest because an MQTT message didn't get delivered because "reasons" before you pull the plug on it and do it yourself. Given that I can predict with 100% certainty that this will happen, why even start with MQTT?)