Live data from Hacker News

MongoDB security notice

mongodb.com

11–20 of 198 posts

Re: MongoDB security notice

#11

Received this security notice today: Hi Redacted, MongoDB is investigating a security incident involving unauthorized access to certain MongoDB corporate systems. This includes exposure of customer account metadata and contact information. At this time, we are NOT aware of any exposure to the data that customers store in MongoDB Atlas. We detected suspicious activity on Wednesday (Dec. 13th, 2023) evening US Eastern…

[deleted]

Re: MongoDB security notice

#12
post #7
post #4

Irrelevant but curious if MongoDB is still being picked up for Greenfield projects given it's licensing.

What’s wrong with licensing?

https://www.mongodb.com/licensing/server-side-public-license...

I am not sure really.

"It should be noted that the new license maintains all of the same freedoms the community has always had with MongoDB under AGPL - they are free to use, review, modify, and redistribute the source code. The only changes are additional terms that make explicit the conditions for offering a publicly available MongoDB as a service.

Obviously, this new license helps our business, but it is also important for the MongoDB community. MongoDB has invested over $300M in R&D over the past decade to offer an open database for everyone, and with this change, MongoDB will continue to be able to aggressively invest in R&D to drive further innovation and value for the community."

Re: MongoDB security notice

#15
post #4

Irrelevant but curious if MongoDB is still being picked up for Greenfield projects given it's licensing.

Their license "is to require that enhancements to MongoDB be released to the community."

I think it only hurts people who want to freeride the project and extend it for selfish personal gains. That's OK by me.

Re: MongoDB security notice

#16

Received this security notice today: Hi Redacted, MongoDB is investigating a security incident involving unauthorized access to certain MongoDB corporate systems. This includes exposure of customer account metadata and contact information. At this time, we are NOT aware of any exposure to the data that customers store in MongoDB Atlas. We detected suspicious activity on Wednesday (Dec. 13th, 2023) evening US Eastern…

Yeah I received the same email. Luckily I don’t actually use mongodb atlas

Re: MongoDB security notice

#17
We are completely locked out of our Atlas account and the support portal right now. We Okta-auth with Mongo and all attempts to auth right now are failing with "The request contained invalid data." displayed on their login screen.

Of course, the support portal requires you to auth to use it...to get help with auth failing.

Anyone else seeing issues getting in to their dashboard?

Edit: Auth started working for us and dashboard access became available for us around 5:15 pm ET.

Re: MongoDB security notice

#19
post #17

We are completely locked out of our Atlas account and the support portal right now. We Okta-auth with Mongo and all attempts to auth right now are failing with "The request contained invalid data." displayed on their login screen. Of course, the support portal requires you to auth to use it...to get help with auth failing. Anyone else seeing issues getting in to their dashboard? Edit: Auth started working for us and…

upstream request timeout when trying to sign in

Re: MongoDB security notice

#20
post #17

We are completely locked out of our Atlas account and the support portal right now. We Okta-auth with Mongo and all attempts to auth right now are failing with "The request contained invalid data." displayed on their login screen. Of course, the support portal requires you to auth to use it...to get help with auth failing. Anyone else seeing issues getting in to their dashboard? Edit: Auth started working for us and…

upstream request timeout when trying to sign in

On our side, Okta is saying the auth is good.

I'm trying my personal account as well and it's telling me MFA isn't set up (it is) and it's making me go through the MFA setup flow again. All attempts to setup another 2FA code in 1Password or to get even an SMS code sent to my phone are failing.

Edit: Personal account with a TOTP 2FA is working again now as well.

This is feeling worse than they're letting on to.

Post reply on HN