3 ms·
I’m no expert, but isn’t having your entire DB as a single file on the same machine as the application a security risk for a web service?
by ABeeSea 5y ago
I’m no expert, but isn’t having your entire DB as a single file on the same machine as the application a security risk for a web service?
- dt3ft 5y agoIt makes things very convenient for hackers.
- rplnt 5y agoBut also for the ops, as it means securing one place instead of two.
- collyw 5y agoIf you have access to the application machine, you will likely have access to DB credentials, no? Actually if anyone has some more to add to this discussion, I would be interested to hear, in case I am missing something. I am currently using an SQLite database for a small internal Django app.
- fogihujy 5y agoYou will need to have the database accessible for the process serving the web page and there's no way around that. When using a database stored elsewhere, the config file will still contain the user name and password, but the user's permissions could be restricted in order to prevent access to parts of the data in the database. In the real world though, 99% of all web sites run with a user with full permissions anyway, so if the site gets compromised, you're screwed regardless.
- collyw 5y ago> In the real world though, 99% of all web sites run with a user with full permissions anyway, so if the site gets compromised, you're screwed regardless. Yeah, I was kind of working under that assumption.
- emj 5y ago> 99% of all web sites run with a user with full permissions In my professional career it's 0% for public facing apps, the simplest custom CMSs based systems I maintain has seperation between database users for a 100MB DB. Many of the newer ones have a sync to read only copies for most of the actions that the app needs to do. 99% sounds horrible, I can't even imagine how you could get to such a state! Sure considering how bad login is handled every where (even in SAML), it's not that surprising.
- fogihujy 5y ago> I can't even imagine how you could get to such a state! 1-click-installers for Joomla, WordPress, Drupal, etc. Most shared hosting providers give the database user full access to the entire database as default.
- borplk 5y agoThat doesn't seem very different to a client-server setup. If your DB is on a different server and your app is compromised the attacker has similar access to the DB as if it was on the same disk.