Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If memory serves, Postgres will only listen on 127.0.0.1 unless the admin password has been set.

All software should work like that.



MongoDB listens only on localhost by default since 3.6 (2017)


You are allowed to judge people for taking far, far too long to do the right thing.

It indicates a pattern of poor judgement, which speaks to trust. You know they are going to let you down each time a new issue comes up.

Faulting people for being cautious around such bad actors (which I'm not saying you're doing, but the response will) speaks to your judgement, not the vendor's.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: