Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That was a problem I always had with replicating directly to CouchDB. They have added more authentication methods now, like proxy auth and JWT, so authorizing on a per-database basis isn't too bad.

However, I gave up on CouchDB after my server kept getting hacked by crypto miners. I'm sure whatever exploit they were using has been patched, but I'm hesitant now to use a DB that's open to the world.



If your CouchDB was open to the world, then that's definitely a configuration problem.

Sure, earlier versions shipped with "admin party" enabled by default but the docs made it very clear to not do that in public.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: