Live data from Hacker News

MongoDB security notice

mongodb.com

81–90 of 198 posts

Re: MongoDB security notice

#81

Earlier quoted context omitted.

Why come ask a question if you apparently have inside information that contradicts the answers you get?

My “inside information” is just basic knowledge of the software industry. If MongoDB is growing is like claiming Morbius is a good movie. It’s just silly. Go ahead disagree with be, but it’s kinda silly.

Feel free to contact the SEC.

Re: MongoDB security notice

#82

I never used/tried MongoDB, what are the reasons people choose MongoDB over other DBs?

It's pretty easy to start with. MQL is also pretty easy to understand + MongoDB kinda makes it fun. Note: I work at MongoDB

And Atlas has a free tier! It's been powering my site (https://bongo.to) for years for a total price of $0. Incredible!

Re: MongoDB security notice

#83
post #67
post #13

“Your data is safe, because we’ve never written it to disk.”

Asked 11 years ago and still going strong... "To what extent are 'lost data' criticisms still valid of MongoDB?" - https://stackoverflow.com/questions/10560834/to-what-extent-...

Yep, Jepsen has not only confirmed but later reconfirmed that MongoDB has for many years been on par with other NoSQL databases when it comes to transaction guarantees and data consistency.

Re: MongoDB security notice

#84

Earlier quoted context omitted.

For my own knowledge, if the options were between using SMS for 2FA or not having 2FA at all then what is better? I've heard mixed things about this.

SMS 2FA is better than no MFA at all, despite the very valid concerns about SMS. It at least protects against credential stuffing and similar automated attacks.

I guess I've always cynically assumed that companies want my phone number to make the data they gather more valuable by making it easier to link with a unique index like a phone number.

Re: MongoDB security notice

#85
post #51

Earlier quoted context omitted.

[flagged]

I see this Jepsen link posted all the time. People: PLEASE don't use outdated software. MongoDB has made mistakes and they are public about their data issues on https://www.mongodb.com/alerts . MongoDB 4.2.6 is old and I believe it's approaching EoL based on https://www.mongodb.com/support-policy/lifecycles I'm not going to push for you to use MongoDB but am merely trying to provide some context around that Jepsen an…

That's why I've added the last part. Mongodb highlights old Jepsen analysis' on their page (https://www.mongodb.com/jepsen), but they never got around to ask them for another analysis to show things are so much better with MongoDB 5 or 6? Yeah. Sure. People are free to believe whatever they want, I'll continue to highlight the best info available.

Re: MongoDB security notice

#86
post #22

Earlier quoted context omitted.

They're apparently still growing quite rapidly, though the company is not yet profitable.

[flagged]

Just because you don't like something or it isn't favored in the HN diaspora does not mean it is an unsuccessful product. There is a great big world outside of your bubble.

Re: MongoDB security notice

#87
post #72
post #55

Earlier quoted context omitted.

So nothing has changed in the 3 years since that article?

I am not sure what's going on with Jepsen any more. https://jepsen.io/analyses there were zero done in 2021, two in early 2022 and even the footer copyright say 2022.

aphyr seems to still work on it, so probably just not that many companies who want to pay to get told the truth anymore: https://github.com/jepsen-io/jepsen
Post reply on HN