Software & Secure Defaults 0 ▲ Connor Tumbleson 2 hours ago · Tech · hide · 0 comments Photo by Franck / UnsplashA long time ago somewhere in 2015 I remember hearing about a bunch of MongoDB databases were wiped with ransom notes left. At first I was so curious how an attacker did this, then I realized it was just public accessible databases with no authentication.When you think about that - it's hardly a hack. Just a misconfiguration of a system in a highly insecure way. So what did MongoDB do? They changed the defaults to produce a more secure system by default (authentication and only binding to 127.0.0.1).As folks installed or upgraded their system the default setup was now way more secure than prior. The little downside however if you wanted to just work locally and test - you might have to configure stuff to make that easier.This became the term "Secure by default" which effectively means a product is resilient against popular attacks without any additional changes. A popular form of this gaining steam is a technique that a program refuses to execute if given too… No comments yet. Log in to reply on the Fediverse. Comments will appear here.