5 ms·
We take security seriously at MongoDB. Here is a response on security best practices from the MongoDB CTO & Co-Founder: http://www.mongodb.com/blog/post/mongod
by meghan 12y ago
We take security seriously at MongoDB. Here is a response on security best practices from the MongoDB CTO & Co-Founder:
http://www.mongodb.com/blog/post/mongodb-security-best-practices http://www.mongodb.com/blog/post/mongodb-security-best-pract...
- aikah 12y agoAs I understand things based on the OP it seems however your documentation promotes the insecure way of setting up mongodb. It's even true that mongodb doesn't even ask to create db credentials during the installation,something it should do by default.
- maltheal 12y agothe real problem is lack of network protections. there are many things on the internet unprotected. this article is not news. dont put your database on the internet.
- mason55 12y agoSecurity is a matter of layers, like an onion, it's not just an either-or. Any sensible database or database-like software does not come with authentication disabled by default. Yes, your DB should be behind a firewall, but if RedHat installed out of the box without a root password you wouldn't say "well your server should be behind a firewall anyway."
- nailer 12y agoThe first point in your article is: > "The most popular installer for MongoDB (RPM) limits network access to localhost by default." The first download for Linux at https://www.mongodb.org/downloads https://www.mongodb.org/downloads is: > https://fastdl.mongodb.org/linux/mongodb-linux-x86_64-2.6.7.tgz https://fastdl.mongodb.org/linux/mongodb-linux-x86_64-2.6.7.... At the bottom of the page there are alternate links to packages. Here is the description: > "MongoDB is included in several different package managers. Generally speaking, it is easier to simply install the prebuilt binaries from above." If the properly packaged versions have secure defaults, maybe you should steer people towards them?