Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> 1. Don't leave your Postgres open to the public internet and

you need to do better than that, since attacks within the firewall can occur as well, and this is probably a more common vector for corporate espionage these days. A compromised laptop can get a wide open remote exploit onto a companies' production environment if the database itself is open within the firewall.



Yup. Your database (as well as the majority of ports for other hosts) shouldn't be available from your corporate network either. 99% of corporate users don't need network access beyond a few ports to most hosts.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: