Live data from Hacker News

MongoDB security notice

mongodb.com

61–70 of 198 posts

Re: MongoDB security notice

#61

Earlier quoted context omitted.

Encryption at rest is not supported in the community/free version of MongoDB. We built an email service (IMAP support added a month ago) and wrote a WebSocket to SQLite layer to solve our encryption at rest needs for storage. See our deep dive at https://forwardemail.net/blog/docs/best-quantum-safe-encrypt... for insight.

I wonder, why would you want DB-managed encryption instead of just putting its storage directory in a LUKS-encrypted volume?

[dead]

Re: MongoDB security notice

#62
post #45

Earlier quoted context omitted.

You really aren't following along closely enough: all other options were failing for me.

But you have setup SMS 2FA enabled, which is convenient this time but a big security hole. You should consider disabling it once the situation comes back to normal.

> But you have setup SMS 2FA enabled

No. I did not. Nor do I now.

I had a TOTP setup in 1Password and Mongo was telling me MFA _wasn't_ set up and sending me through the MFA setup flow again.

All options, SMS included, were failing in that MFA setup flow they pushed me in to.

They're back now and my existing TOTP token is generating one time use passwords that work now.

Re: MongoDB security notice

#63

Nice and to the point, makes it clear that this is early, explains the current scope, tells us to expect a follow up as the information makes its way to them. I like this tbh and I hope people won't punish them for not including more info when this is clearly in the early days of investigation.

It was only DETECTED on the 13th, and they suspect had been going on 'for some time'. And basically not sure if user data was touched but they suspect or haven't provided it yet buly saying'NOT'. I want answers.

Yes, usually breaches take time to detect, and usually the attackers are around for a while first.

I'm sure they want answers too, but they're working on it, and this is what they have right now.

Re: MongoDB security notice

#65
post #51

Earlier quoted context omitted.

[flagged]

I see this Jepsen link posted all the time. People: PLEASE don't use outdated software. MongoDB has made mistakes and they are public about their data issues on https://www.mongodb.com/alerts . MongoDB 4.2.6 is old and I believe it's approaching EoL based on https://www.mongodb.com/support-policy/lifecycles I'm not going to push for you to use MongoDB but am merely trying to provide some context around that Jepsen an…

Based on that lifecycle doc, the 4.2 line is already EOL, and 4.4 will be soon.

Re: MongoDB security notice

#68

I never used/tried MongoDB, what are the reasons people choose MongoDB over other DBs?

It was an early player when everyone thought NoSQL document databases solved every problem.

They did solve many problems, and then they caused many more problems...

At first at least, haven't checked in on that in awhile

Re: MongoDB security notice

#69
post #25
post #17

We are completely locked out of our Atlas account and the support portal right now. We Okta-auth with Mongo and all attempts to auth right now are failing with "The request contained invalid data." displayed on their login screen. Of course, the support portal requires you to auth to use it...to get help with auth failing. Anyone else seeing issues getting in to their dashboard? Edit: Auth started working for us and…

Same here with Google SSO

We regained dashboard access around 5:15 pm ET.

Re: MongoDB security notice

#70

Earlier quoted context omitted.

[flagged]

Why come ask a question if you apparently have inside information that contradicts the answers you get?

My “inside information” is just basic knowledge of the software industry. If MongoDB is growing is like claiming Morbius is a good movie. It’s just silly. Go ahead disagree with be, but it’s kinda silly.
Post reply on HN