frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

MongoBleed Explained Simply

https://bigdata.2minutestreaming.com/p/mongobleed-explained-simply
53•todsacerdoti•2h ago

Comments

maxrmk•2h ago
How often are mongo instances exposed to the internet? I'm more of an SQL person and for those I know it's pretty uncommon, but does happen.
wood_spirit•2h ago
The article links to a shodan scan reporting 213K exposed instances https://www.shodan.io/search?query=Product%3A%22MongoDB%22
hahahacorn•2h ago
A highly cited reason for using mongo is that people would rather not figure out a schema. (N=3/3 for “serious” orgs I know using mongo).

That sort of inclination to push off doing the right thing now to save yourself a headache down the line probably overlaps with “let’s just make the db publicly exposed” instead of doing the work of setting up an internal network to save yourself a headache down the line.

TZubiri•1h ago
I would have hoped that there would be no important data in mongoDB.

But now we can at least be rest assured that the important data in mongoDB is just very hard to read with the lack of schemas.

Probably all of that nasty "schema" work and tech debt will finally be done by hackers trying to make use of that information.

petcat•1h ago
From my experience, Mongo DB's entire raison d'etre is "laziness".

* Don't worry about a schema.

* Don't worry about persistence or durability.

* Don't worry about reads or writes.

* Don't worry about connectivity.

This is basically the entire philosophy, so it's not surprising at all that users would also not worry about basic security.

aragilar•38m ago
Not only that, but authentication is much harder than it needs to be to set up (and is off by default).
winrid•29m ago
Although interestingly, for all the mongo deployments I managed, the first time I saw a cluster publicly exposed without SSL was postgres :)
ok123456•45m ago
For a long time, the default install had it binding to all interfaces and with authentication disabled.
whynotmaybe•1h ago
I'm still thinking about the hypothetical optimism brought by OWASP top 10 hoping that major flaws will be solved and that buffer overflow has been there since the beginning... in 2003.
kentonv•47m ago
A few years back I patched the memory allocator used by the Cloudflare Workers runtime to overwrite all memory with a static byte pattern on free, so that uninitialized allocations contain nothing interesting.

We expected this to hurt performance, but we were unable to measure any impact in practice.

Everyone still working in memory-unsafe languages should really just do this IMO. It would have mitigated this Mongo bug.

tombert•7m ago
You know, I never even considered doing that but it makes sense; whatever overhead that's incurred by doing that static byte pattern is still almost certainly minuscule compared to the overhead of something like a garbage collector.
plorkyeran•35m ago
The author seems to be unaware that Mongo internally develops in a private repo and commits are published later to the public one with https://github.com/google/copybara. All of the confusion around dates is due to this.
computerfan494•34m ago
The author of this post is incorrect about the timeline. Our Atlas clusters were upgraded days before the CVE was announced.

What an unprocessed photo looks like

https://maurycyz.com/misc/raw_photo/
153•zdw•1h ago•29 comments

Stepping down as Mockito maintainer after 10 years

https://github.com/mockito/mockito/issues/3777
175•saikatsg•3h ago•82 comments

Unity's Mono problem: Why your C# code runs slower than it should

https://marekfiser.com/blog/mono-vs-dot-net-in-unity/
55•iliketrains•2h ago•23 comments

62 years in the making: NYC's newest water tunnel nears the finish line

https://ny1.com/nyc/all-boroughs/news/2025/11/09/water--dep--tunnels-
24•eatonphil•56m ago•5 comments

Spherical Cow

https://lib.rs/crates/spherical-cow
9•Natfan•50m ago•1 comments

PySDR: A Guide to SDR and DSP Using Python

https://pysdr.org/content/intro.html
70•kklisura•3h ago•4 comments

MongoBleed Explained Simply

https://bigdata.2minutestreaming.com/p/mongobleed-explained-simply
53•todsacerdoti•2h ago•13 comments

Researchers Discover Molecular Difference in Autistic Brains

https://medicine.yale.edu/news-article/molecular-difference-in-autistic-brains/
17•amichail•1h ago•3 comments

CEOs are hugely expensive. Why not automate them?

https://www.newstatesman.com/business/companies/2023/05/ceos-salaries-expensive-automate-robots
74•nis0s•45m ago•52 comments

Growing up in “404 Not Found”: China's nuclear city in the Gobi Desert

https://substack.com/inbox/post/182743659
669•Vincent_Yan404•17h ago•290 comments

Slaughtering Competition Problems with Quantifier Elimination

https://grossack.site/2021/12/22/qe-competition.html
6•todsacerdoti•51m ago•0 comments

Calendar

https://neatnik.net/calendar/?year=2026
942•twapi•18h ago•114 comments

Time in C++: Inter-Clock Conversions, Epochs, and Durations

https://www.sandordargo.com/blog/2025/12/24/clocks-part-5-conversions
11•ibobev•2d ago•0 comments

Remembering Lou Gerstner

https://newsroom.ibm.com/2025-12-28-Remembering-Lou-Gerstner
56•thm•5h ago•26 comments

Building a macOS app to know when my Mac is thermal throttling

https://stanislas.blog/2025/12/macos-thermal-throttling-app/
214•angristan•12h ago•96 comments

Software engineers should be a little bit cynical

https://www.seangoedecke.com/a-little-bit-cynical/
92•zdw•2h ago•71 comments

Doublespeak: In-Context Representation Hijacking

https://mentaleap.ai/doublespeak/
37•surprisetalk•6d ago•5 comments

Dolphin Progress Report: Release 2512

https://dolphin-emu.org/blog/2025/12/22/dolphin-progress-report-release-2512/
49•akyuu•2h ago•2 comments

Show HN: Pion SCTP with RACK is 70% faster with 30% less latency

https://pion.ly/blog/sctp-and-rack/
32•pch07•5h ago•4 comments

Replacing JavaScript with Just HTML

https://www.htmhell.dev/adventcalendar/2025/27/
678•soheilpro•22h ago•254 comments

Learn computer graphics from scratch and for free

https://www.scratchapixel.com
158•theusus•12h ago•19 comments

As AI gobbles up chips, prices for devices may rise

https://www.npr.org/2025/12/28/nx-s1-5656190/ai-chips-memory-prices-ram
20•geox•1h ago•9 comments

John Malone and the Invention of Liquid-Based Engines

https://permalink.lanl.gov/object/tr?what=info:lanl-repo/lareport/LA-UR-93-1350-25
12•akshatjiwan•4d ago•1 comments

Show HN: Phantas – A browser-based binaural strobe engine (Web Audio API)

https://phantas.io
12•AphantaZach•3h ago•5 comments

One year of keeping a tada list

https://www.ducktyped.org/p/one-year-of-keeping-a-tada-list
214•egonschiele•6d ago•60 comments

Why I Disappeared – My week with minimal internet in a remote island chain

https://www.kenklippenstein.com/p/why-i-disappeared
10•eh_why_not•2h ago•0 comments

Langfuse (YC W23) Is Hiring in Berlin, Germany

https://langfuse.com/careers
1•clemo_ra•12h ago

Show HN: LoongArch Userspace Emulator

https://github.com/libriscv/libloong
14•fwsgonzo•4d ago•3 comments

Designing Predictable LLM-Verifier Systems for Formal Method Guarantee

https://arxiv.org/abs/2512.02080
52•PaulHoule•9h ago•10 comments

2D Signed Distance Functions

https://iquilezles.org/articles/distfunctions2d/
80•nickswalker•4d ago•12 comments