TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

MongoDB security notice

269 pointsby ciudiloover 1 year ago

14 comments

iareseeover 1 year ago
We are completely locked out of our Atlas account and the support portal right now. We Okta-auth with Mongo and all attempts to auth right now are failing with &quot;The request contained invalid data.&quot; displayed on their login screen.<p>Of course, the support portal requires you to auth to use it...to get help with auth failing.<p>Anyone else seeing issues getting in to their dashboard?<p>Edit: Auth started working for us and dashboard access became available for us around 5:15 pm ET.
评论 #38668273 未加载
评论 #38668078 未加载
评论 #38668147 未加载
insanitybitover 1 year ago
Nice and to the point, makes it clear that this is early, explains the current scope, tells us to expect a follow up as the information makes its way to them.<p>I like this tbh and I hope people won&#x27;t punish them for not including more info when this is clearly in the early days of investigation.
评论 #38668302 未加载
评论 #38668936 未加载
jhardy54over 1 year ago
&gt; […] regularly rotate their MongoDB Atlas passwords<p>Is there some context I’m missing, or is this a modern security team recommending password rotation?
评论 #38669436 未加载
tdhz77over 1 year ago
If we are impacted, how would you go about monitoring your systems for odd behaviors? Looking at the logs just doesn&#x27;t seem adequate.
PeterZaitsevover 1 year ago
This highlights risks of extreme consolidation - even if Atlas customers were not affected it is natural for them to be concerned after announcement overwhelming web site or support channels.<p>More independent MongoDB DBaaS providers is what would offer true redundancy in this case, though it is highly restricted due to SSPL license change.<p>Hopefully FerretDB will be successful building feasible alternative
评论 #38669084 未加载
webappguyover 1 year ago
Just got email alert
rompledorphover 1 year ago
Received this security notice today:<p>Hi Redacted,<p>MongoDB is investigating a security incident involving unauthorized access to certain MongoDB corporate systems. This includes exposure of customer account metadata and contact information. At this time, we are NOT aware of any exposure to the data that customers store in MongoDB Atlas.<p>We detected suspicious activity on Wednesday (Dec. 13th, 2023) evening US Eastern Standard Time and immediately activated our incident response process. We are still conducting an active investigation and believe that this unauthorized access has been going on for some period of time before discovery. We have also started notifying relevant authorities.<p>What should you do next? Since we are aware that some customer account metadata and contact information was accessed, please be vigilant for social engineering and phishing attacks. If not already implemented, we encourage all customers to activate phishing-resistant multi-factor authentication (MFA) and regularly rotate passwords. MongoDB will continue to update mongodb.com&#x2F;alerts with additional information as we continue to investigate the matter.<p>Sincerely, Lena Smart MongoDB CISO
评论 #38667991 未加载
评论 #38667951 未加载
0xblinqover 1 year ago
“Your data is safe, because we’ve never written it to disk.”
评论 #38668227 未加载
评论 #38668492 未加载
评论 #38668291 未加载
评论 #38668664 未加载
goenningover 1 year ago
I never used&#x2F;tried MongoDB, what are the reasons people choose MongoDB over other DBs?
评论 #38669207 未加载
评论 #38668321 未加载
评论 #38668375 未加载
评论 #38668365 未加载
评论 #38668306 未加载
评论 #38668364 未加载
评论 #38671956 未加载
评论 #38668311 未加载
评论 #38668587 未加载
评论 #38668666 未加载
评论 #38668361 未加载
cpursleyover 1 year ago
Why are people still choosing Mongo over Postgres these days? If there&#x27;s something I&#x27;m missing, I&#x27;m genuinely curious as I&#x27;m not against json data and frequency use jsonb tables in Postgres.
评论 #38669430 未加载
评论 #38669063 未加载
superdupererover 1 year ago
Are they doing well? Seems like the hype has kind of died down.
评论 #38668266 未加载
评论 #38668172 未加载
评论 #38668717 未加载
评论 #38668128 未加载
评论 #38668686 未加载
wg0over 1 year ago
Irrelevant but curious if MongoDB is still being picked up for Greenfield projects given it&#x27;s licensing.
评论 #38667984 未加载
评论 #38668236 未加载
评论 #38668867 未加载
评论 #38667883 未加载
评论 #38667864 未加载
yawnxyzover 1 year ago
Wow lucky I moved our data out not too long ago. Trying to login to MongoDB, I&#x27;m just getting &quot;server error&quot; now.
评论 #38668784 未加载
toasted-subsover 1 year ago
Almost decided to use MongoDB in a project for the first time.<p>Kind of makes me unsure if it’s going to be the right choice.
评论 #38669752 未加载
评论 #38669057 未加载
评论 #38668762 未加载
评论 #38669132 未加载