6 ms·
Still no SSL, so using redis-client still just spews your password out all over the internet.
by xai3luGi 12y ago
Still no SSL, so using redis-client still just spews your password out all over the internet.
- untog 12y agoWhy are you connecting to a Redis box across the internet? There's a great (and after Heartbleed, prophetic) post on the Varnish web site about why they don't implement SSL, I imagine Redis would be similar: https://www.varnish-cache.org/docs/trunk/phk/ssl.html https://www.varnish-cache.org/docs/trunk/phk/ssl.html
- andrewguenther 12y agoI love this post. Not every single piece of software needs to include SSL support out of the box. Sometimes, for the exact reasons Varnish explains, it just doesn't make sense.
- EugeneOZ 12y agoVarnish is other thing. For cross-datacenter replication you will want SSL. So for Redis Cluster it's a necessary thing.
- danudey 12y agoFor cross-datacenter replication you should be using a secured VPN anyway.
- EugeneOZ 12y agoNo, if your db can use SSL, then additional layer of complexity is not required. upd.: don't get me wrong, Redis is my favorite DB, really. But better to be objective.
- thedufer 12y agoIt's hard to imagine every service in your infrastructure implementing SSL would be more secure than a single VPN tool. You are very optimistic about the difficulties of getting security right.
- EugeneOZ 12y agoIt's really simple to imagine and I even have implemented it :) "One single VPN" may (and will) fail sometimes, so count your complexity and stability with and without one extra service.
- thedufer 12y agoI'm sorry to be skeptical, but when a random person on the internet claims to have implemented SSL more securely than open source tools that are completely built around security, I tend to not believe it. Implementing SSL is easy. Implementing SSL correctly is very difficult, and you probably won't find out you did it wrong for a long time, if ever.
- EugeneOZ 12y agoI'm not implementing SSL, I just use it. With MySQL you can just use it. With Redis you have to use VPN with all costs of VPN. Please calm down and stop forcing your preference of VPN as the only right way.
- poooogles 12y agoSurely you would keep this in a private network? Layer 2/Encrypted VPNs?
- EugeneOZ 12y agoFor Redis - yes. But VPN is additional latency and additional service you have to monitor/restart/duplicate.
- thezilch 12y agoThere are plenty of alternatives to every library having to have yet another probably broken security layer. Probably better to focus on this layer being separate from everyone having to implement it. Like, stunnel: https://www.stunnel.org/index.html https://www.stunnel.org/index.html and how to setup (Re: MySQL over stunnel) http://linuxgazette.net/107/odonovan.html http://linuxgazette.net/107/odonovan.html
- sandstrom 12y agoTransport security is mostly better implemented via ipsec (a VPN tunnel). I'm happy that redis doesn't implement SSL, it just shows that they are prioritizing relevant features.
- edgan 12y agoAs a operations person, this is the wrong way to go. The VPN becomes a single point of failure. Attempts at HA fail in my experience. Also solutions like stunnel create a separate process that has to be managed. If I have one for redis, and then one for something else it is harder to tell them apart, because both will be named stunnel.