Hacker News new | ask | show | jobs
ChaosDB Explained: Azure's Cosmos DB Vulnerability Walkthrough (wiz.io)
10 points by timmclean 1682 days ago
2 comments

The whole thing is just astounding. C# host process as root, iptable network rules in the container instead of outside of it, servers not validating client certificates. My oh my.

How any of this made it past security and production review is beyond me. Unless there wasn’t any.

Wow.