|
|
|
|
|
by Twirrim
2647 days ago
|
|
Historically, MongoDB was unauthenticated and insecure by default. Because that's always a good idea. You should never assume anyone is going to use your product in a secure fashion, and make it so that they have to at least make _some_ effort towards security. Other than that, writing new features is fun, and you can get so many developers (that don't think about security) for the same amount of money as a good security professional, or a developer with even half an ounce of security sense, commands. Security is always inconvenient, takes extra effort, and is invisible. So many companies and managers deprioritise it over more visible feature work, forgetting that security in and of itself IS a feature. |
|
Security in depth is just not a thing a lot of people think about right now.
[1] http://antirez.com/news/96