
Secure System Design Principles for Enhanced Security
Discover key secure system design principles like defense in depth, least privilege, and fail secure defaults that enhance security.
What has been corrected on this page?
Every accepted correction to this page is recorded with the exact change, so readers can see how the page improved over time.
-
3 corrections applied: MongoDB 3.6 changed the default network binding to localhost; it did not make authentication required by default. | MongoDB 3.6 changed the default binding to localhost, not authentication-by-default. | The firewall/WAF-rule-misconfiguration Cloudflare outage was the July 2019 incident; the June 2022 outage was a network/BGP change, not a firewall rule. Dating it to 2019 matches the described cause.
BeforeMongoDB changed its defaults to require authentication and bind only to localhost in version 3.6 (2017) ... In 2022, a Cloudflare outage caused by a misconfigured firewall rule illustrated ...
AfterMongoDB changed its defaults to bind only to localhost by default (authentication still has to be explicitly enabled) in version 3.6 (2017) ... In 2019, a Cloudflare outage caused by a misconfigured firewall (WAF) rule illustrated ...
Why: Verified live: all 3 corrections (MongoDB auth-vs-binding claim x2, Cloudflare outage year) already present in article content. FAQ JSON-LD checked and contains no mention of either fabrication, so no secondary fabrication found.
View the full record →
Who checked this page?
1 contributor has checked "Secure System Design Principles for Enhanced Security" on When Notes Fly. Each name below links to that person's public CitePep profile, where every contribution they have made is listed with the exact change they proposed.