8 ms·
MongoDB security notice
- Waterluvian 3y ago[flagged]
- deleted 3y ago[deleted]
- wg0 3y agoIrrelevant but curious if MongoDB is still being picked up for Greenfield projects given it's licensing.
- deleted 3y ago[deleted]
- dnndev 3y agoWhat’s wrong with licensing?
- sigzero 3y agohttps://www.mongodb.com/licensing/server-side-public-license/faq https://www.mongodb.com/licensing/server-side-public-license... I am not sure really. "It should be noted that the new license maintains all of the same freedoms the community has always had with MongoDB under AGPL - they are free to use, review, modify, and redistribute the source code. The only changes are additional terms that make explicit the conditions for offering a publicly available MongoDB as a service. Obviously, this new license helps our business, but it is also important for the MongoDB community. MongoDB has invested over $300M in R&D over the past decade to offer an open database for everyone, and with this change, MongoDB will continue to be able to aggressively invest in R&D to drive further innovation and value for the community."
- bdcravens 3y agohttps://thenewstack.io/the-case-against-the-server-side-public-license-sspl/ https://thenewstack.io/the-case-against-the-server-side-publ...
- forwardemail 3y agoEncryption at rest is not supported in the community/free version of MongoDB. We built an email service (IMAP support added a month ago) and wrote a WebSocket to SQLite layer to solve our encryption at rest needs for storage. See our deep dive at https://forwardemail.net/blog/docs/best-quantum-safe-encrypted-email-service https://forwardemail.net/blog/docs/best-quantum-safe-encrypt... for insight.
- dnndev 3y agoReally? How many open source databases do you offer? Some may say it’s not right for randos to complain when you give something away and they complain that it’s missing basics. I just happy someone else wrote most of what I need and I can extend it if needed.
- Nextgrid 3y agoI wonder, why would you want DB-managed encryption instead of just putting its storage directory in a LUKS-encrypted volume?
- forwardemail 3y ago[dead]
- PeterZaitsev 3y agoNote Percona Server for MongoDB is drop-in replacement for MongoDB and supports Data at Rest Encryption, on SSPL version https://docs.percona.com/percona-server-for-mongodb/5.0/data-at-rest-encryption.html https://docs.percona.com/percona-server-for-mongodb/5.0/data...
- mananaysiempre 3y agoMongoDB’s SSPL is neither an open source license[1] nor, most likely, a free software one[2]. Its definition of offering the licensed software as a service is so broad most Linux distributions[3–6] flat out refuse to ship MongoDB (not even in a nonfree repository or the equivalent) so as to (among other things) avoid placing the operators of their package mirrors in legal jeopardy. [1] https://blog.opensource.org/the-sspl-is-not-an-open-source-license/ https://blog.opensource.org/the-sspl-is-not-an-open-source-l... [2] https://opensource.stackexchange.com/q/13888 https://opensource.stackexchange.com/q/13888 [3] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=915537 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=915537 [4] https://fedoraproject.org/wiki/Changes/MongoDB_Removal https://fedoraproject.org/wiki/Changes/MongoDB_Removal [5] https://bugzilla.opensuse.org/show_bug.cgi?id=1122267 https://bugzilla.opensuse.org/show_bug.cgi?id=1122267 [6] https://lists.archlinux.org/archives/list/arch-dev-public@lists.archlinux.org/thread/OY2DLNWTZOBPAHFE5FSV4Q6AIWGZO6KV/ https://lists.archlinux.org/archives/list/arch-dev-public@li...
- ranting-moth 3y agoTheir license "is to require that enhancements to MongoDB be released to the community." I think it only hurts people who want to freeride the project and extend it for selfish personal gains. That's OK by me.
- varelaz 3y agoThat's reply to Amazon abuse of MongoDB (DocumentDB)
- PeterZaitsev 3y agoIt is the opposite. Amazon would have released MongoDB as a service, same as they do for PostgreSQL or MySQL. As MongoDB changed license they implemented DocumentDB instead. Note AWS significantly contributes to PostgreSQL and MySQL communities (though you could always want even more) but of course does not to MongoDB. While this is fine for MongoDB Inc I think it is not great for MongoDB community at large
- PeterZaitsev 3y agoNot really. It really designed to prevent anyone else having MongoDB DBaaS without having license from MongoDB, which it does rather successfully.
- peterfarkas 3y agoAnyone can provide Postgres, MySQL or other open source databases as a service. For this reason, there are many providers to choose from, and there is a healthy amount of innovation and competition in the space. Prices are set by market and demand, as it should be. And then there is MongoDB where only a handful of providers could negotiate a license, and the price is set by MongoDB Inc. In my opinion this is by no means "fine" from a user perspective as we are talking about database software. If anyone did freeriding, it is MongoDB Inc. who chose to freeride on the open source community for marketing purposes, before switching to SSPL.
- pleoxy 3y agoNothing wrong with picking mongo if it's a good fit for your use case.
- PeterZaitsev 3y agoOh yes. By people who do not or does not care about Open Source... and these are many
- deleted 3y ago[deleted]
- insanitybit 3y agoNice and to the point, makes it clear that this is early, explains the current scope, tells us to expect a follow up as the information makes its way to them. I like this tbh and I hope people won't punish them for not including more info when this is clearly in the early days of investigation.
- webappguy 3y agoIt was only DETECTED on the 13th, and they suspect had been going on 'for some time'. And basically not sure if user data was touched but they suspect or haven't provided it yet buly saying'NOT'. I want answers.
- insanitybit 3y agoYes, usually breaches take time to detect, and usually the attackers are around for a while first. I'm sure they want answers too, but they're working on it, and this is what they have right now.
- sigzero 3y agoHow does it feel to want? They are doing their due diligence currently.
- rezonant 3y agoYour options are: (A) Vendor waits until all the facts are in place and the investigation is finished or (B) Vendor tells customers as early as practical so they can take their own mitigation steps. You do not have the option of (C) Vendor should tell me about a breach they don't yet know about.
- abrookewood 3y agoGive them some time.
- infamouscow 3y agoAgreed. For all the shit MongoDB gets, this is something that people should take a step back and recognize as very high in integrity, transparency, and trust. Other businesses should follow their lead here. I'm more inclined to do business with MongoDB because they've demonstrated these principles first-hand.
- richwater 3y ago[flagged]
- rompledorph 3y agoReceived this security notice today: Hi Redacted, MongoDB is investigating a security incident involving unauthorized access to certain MongoDB corporate systems. This includes exposure of customer account metadata and contact information. At this time, we are NOT aware of any exposure to the data that customers store in MongoDB Atlas. We detected suspicious activity on Wednesday (Dec. 13th, 2023) evening US Eastern Standard Time and immediately activated our incident response process. We are still conducting an active investigation and believe that this unauthorized access has been going on for some period of time before discovery. We have also started notifying relevant authorities. What should you do next? Since we are aware that some customer account metadata and contact information was accessed, please be vigilant for social engineering and phishing attacks. If not already implemented, we encourage all customers to activate phishing-resistant multi-factor authentication (MFA) and regularly rotate passwords. MongoDB will continue to update mongodb.com/alerts with additional information as we continue to investigate the matter. Sincerely, Lena Smart MongoDB CISO
- deleted 3y ago[deleted]
- sampli 3y agoYeah I received the same email. Luckily I don’t actually use mongodb atlas
- 0xblinq 3y ago“Your data is safe, because we’ve never written it to disk.”
- satvikpendem 3y ago/dev/null is web scale https://youtube.com/watch?v=b2F-DItXtZs https://youtube.com/watch?v=b2F-DItXtZs
- hybridtupel 3y agoLuckily already using https://devnull-as-a-service.com/ https://devnull-as-a-service.com/
- parkerduckworth 3y agoDoes /dev/null support sharding?
- webappguy 3y agoMongo has made huge improvements tbf, but this is funny
- belter 3y agoAsked 11 years ago and still going strong... "To what extent are 'lost data' criticisms still valid of MongoDB?" - https://stackoverflow.com/questions/10560834/to-what-extent-are-lost-data-criticisms-still-valid-of-mongodb https://stackoverflow.com/questions/10560834/to-what-extent-...
- insanitybit 3y agoHN users would rather meme than read.
- dgellow 3y agoIsn’t mongodb data losses commonly referred related to their use of fsync()? From what I vaguely remember they call fsync() every 100ms or so and just assume everything went fine, resulting in potential data loss.
- iaresee 3y agoWe are completely locked out of our Atlas account and the support portal right now. We Okta-auth with Mongo and all attempts to auth right now are failing with "The request contained invalid data." displayed on their login screen. Of course, the support portal requires you to auth to use it...to get help with auth failing. Anyone else seeing issues getting in to their dashboard? Edit: Auth started working for us and dashboard access became available for us around 5:15 pm ET.
- alexzeitler 3y agoupstream request timeout when trying to sign in
- iaresee 3y agoOn our side, Okta is saying the auth is good. I'm trying my personal account as well and it's telling me MFA isn't set up (it is) and it's making me go through the MFA setup flow again. All attempts to setup another 2FA code in 1Password or to get even an SMS code sent to my phone are failing. Edit: Personal account with a TOTP 2FA is working again now as well. This is feeling worse than they're letting on to.
- alexzeitler 3y agoSign in now worked once and sent me into the MFA setup loop but it failed.
- deleted 3y ago[deleted]
- ThePowerOfFuet 3y agoYou really should not be using SMS for 2FA.
- iaresee 3y ago
- superduperer 3y agoAre they doing well? Seems like the hype has kind of died down.
- WJW 3y agoThey're apparently still growing quite rapidly, though the company is not yet profitable.
- superduperer 3y ago[flagged]
- lolinder 3y agoWhy come ask a question if you apparently have inside information that contradicts the answers you get?
- superduperer 3y agoMy “inside information” is just basic knowledge of the software industry. If MongoDB is growing is like claiming Morbius is a good movie. It’s just silly. Go ahead disagree with be, but it’s kinda silly.
- insanitybit 3y agoFeel free to contact the SEC.
- WJW 3y agoThey state these things in their quarterly filings with the SEC, in which to my knowledge it is not legal to knowingly misrepresent facts. If you have actual proof that MongoDBs auditors are lying to the SEC, you can probably get a pretty good whistleblower reward or at the very least make a ton of money selling this money to hedge funds specializing in shorting failing companies.
- cianigga 3y ago[flagged]
- ceejayoz 3y agoHe’s been selling consistently for years. https://finance.yahoo.com/news/insider-sell-mongodb-incs-president-030101984.html https://finance.yahoo.com/news/insider-sell-mongodb-incs-pre...
- stockocean 3y agoHas consistently been selling, but yeah quite a big unload https://archive.is/aPcRF https://archive.is/aPcRF
- mtremsal 3y agoThis is almost certainly normal activity under a 10b-5 plan, meant to protect specifically against suspicion of insider trading, which is what you’re implying.
- deleted 3y ago[deleted]
- zulubab 3y ago[dead]
- goenning 3y agoI never used/tried MongoDB, what are the reasons people choose MongoDB over other DBs?
- webappguy 3y agoEasy, flexible scheme nosql, plenty of baked in features. Has it's place, and many times when it would not be a good choice too.
- salil999 3y agoIt's pretty easy to start with. MQL is also pretty easy to understand + MongoDB kinda makes it fun. Note: I work at MongoDB
- 010101010101 3y agoIt was an early player when everyone thought NoSQL document databases solved every problem.
- jtriangle 3y agoThey did solve many problems, and then they caused many more problems... At first at least, haven't checked in on that in awhile
- throwawaaarrgh 3y agoAnd now everyone knows RDBMS solves every problem. Especially when it's SQLite.
- webappguy 3y agoJust got email alert
- yawnxyz 3y agoWow lucky I moved our data out not too long ago. Trying to login to MongoDB, I'm just getting "server error" now.
- KomoD 3y ago"The login issues are unrelated to the security incident."
- escape_goat 3y ago[flagged]
- deleted 3y ago[deleted]
- jhardy54 3y ago> […] regularly rotate their MongoDB Atlas passwords Is there some context I’m missing, or is this a modern security team recommending password rotation?
- richbell 3y agoRegularly rotating secrets for applications is good. Forcing users to regularly rotate their passwords is not so good.
- twisteriffic 3y agoCorrect! NIST recommends against forcing password expiry unless the password is known to be compromised. https://pages.nist.gov/800-63-FAQ/#q-b05 https://pages.nist.gov/800-63-FAQ/#q-b05
- ronabop 3y agoThankfully all of my users are extreme statistical aberrations who do not re-use the same memorized password (or a variation on it) for more than one thing, ever, at all OR they diligently watch every single possible place they have ever re-used any of their memorized passwords, with the globally mandated and complied with reporting, so they can know if a password they once re-used at grandmas-cookies.blog.example.com has been compromised. The fact that all websites, servers, systems (etc.) check to see if passwords are known to be compromised (since NIST says verifiers will do that) makes things a lot easier, too.
- toasted-subs 3y agoAlmost decided to use MongoDB in a project for the first time. Kind of makes me unsure if it’s going to be the right choice.
- rglover 3y agoThe problem here is with the hosted service, not the database itself or its performance.
- jbverschoor 3y agoNo reason to use mongo imo
- donutpepperoni 3y agoAgreed. It's an over optimization and most problems can be solved by traditional relational databases.
- cpursley 3y agoMongo is never the right choice. Postgres is nearly always the right choice, however.
- merek 3y agoLegitimate question, please don't downvote. Are you basing this opinion on: - popular HN opinion - issues that Mongo experienced in its infancy - mis-modelling highly relational data on a non-relational DB, and blaming the DB for ensuing problems Or are you basing it on extensive experience with wide range of use cases?
- c0pium 3y agoMuch like saying “no offense” doesn’t make something not offensive, saying “honest question” doesn’t make a question not disingenuous. If you find yourself typing “don’t downvote” you should consider rephrasing your question to not be worthy of downvotes. This post could just be “can you explain your experiences that have lead you to this conclusion” and we’d all be better off.
- PeterZaitsev 3y agoThis highlights risks of extreme consolidation - even if Atlas customers were not affected it is natural for them to be concerned after announcement overwhelming web site or support channels. More independent MongoDB DBaaS providers is what would offer true redundancy in this case, though it is highly restricted due to SSPL license change. Hopefully FerretDB will be successful building feasible alternative
- nextworddev 3y ago“Extreme consolidation” - wait till us-East-1 goes down
- _sword 3y agoHappened in 2012 after a big thunderstorm and took most of the internet down
- PeterZaitsev 3y agoYep. Though to be fair AWS provides options for multi region availability. What did not happen (yet) is complete AWS meltdown
- rezonant 3y agoAmazon sells it cheap compared to other regions-- it's economically incentivized for us-east-1 to take out half of the Internet.
- didip 3y agoFriends don’t let friends run on us-east-1. Consolidate on us-west-1 or us-west-2 instead.
- bobnamob 3y agous-west-1 wouldn’t be my first choice either for <other_reasons>
- 3y ago
- deleted 3y ago[deleted]
- deleted 3y ago[deleted]
- throwawaaarrgh 3y ago[flagged]
- forwardemail 3y ago[dead]
- throwawaaarrgh 3y ago[flagged]
- exabrial 3y ago[flagged]
- cpursley 3y agoWhy are people still choosing Mongo over Postgres these days? If there's something I'm missing, I'm genuinely curious as I'm not against json data and frequency use jsonb tables in Postgres.
- deleted 3y ago[deleted]
- godzillabrennus 3y agoPeople use MongoDB because it’s easy to get started. It does “db stuff” and “authentication”. I’ve given up trying to fight the trend. I just recognize immediately when it is used early on that the devs are still operating with training wheels on.
- winrid 3y agoSometimes this is the case but not always... It's nice to just work with objects in some languages... for some projects. That's engineering - picking trade offs :)
- cpursley 3y agoExcept you can have objects in Postgres via jsonb; there's no trade off and you're both future and vendor proofed.
- winrid 3y agoYeah, there is. PG has its own warts that Mongo does not have. Also the JSONB query language sucks. See appending an array in PG [0] vs Mongo [1]. Also PG does not provide a way to atomically append to the array, you have to lock the row via SELECT ... FOR UPDATE. Mongo's $push, $set, etc, are atomic. [0] https://pastebin.com/v2MiV8PE https://pastebin.com/v2MiV8PE [1] https://pastebin.com/RmLuGzAY https://pastebin.com/RmLuGzAY
- 3y ago
- tdhz77 3y agoIf we are impacted, how would you go about monitoring your systems for odd behaviors? Looking at the logs just doesn't seem adequate.