Hacker News new | ask | show | jobs
by Cthulhu_ 1806 days ago
I don't think it actually matters much; your database is your core business and access to it should be restricted. Same as your machines. To the point where, if you have everything set up right (which is a big if, granted), NOBODY should need physical access to ANY machine or database. All access through the application's management interface, where access can be finely tuned and access logs can be used to hold people accountable.
1 comments

it was mostly a question of scale, that a business mishandle 500 customers data is one thing, but 100k feels different to me.