Recently, a post appeared on the Elastic blog , that the main security features of Elasticsearch, released into the open-source space more than a year ago, are now free for users.
The official blog entry contains the "right" words about the fact that open source should be free and that the project owners build their business on other additional features offered for enterprise solutions. Now, the following security features, previously available only with a gold subscription, are included in the basic builds of versions 6.8.0 and 7.1.0:
- TLS for encrypted communication.
- File and native realm for creating and managing user accounts.
- Role-based access management for users to the API and cluster; multi-user access to Kibana is allowed using Kibana Spaces.
However, the transition of security features to the free section is not a generous move but an attempt to create a distance between the commercial product and its major flaws.
And it has serious ones.
The query "Elastic Leaked" returns 13.3 million search results on Google. Impressive, isnāt it? After releasing the project's security features into open source, which once seemed like a good idea, Elastic began experiencing serious data leak issues. In fact, the basic version turned into a sieve, as no one effectively maintained these security features.
One of the most notorious data leaks from the elastic server was the case of 57 million U.S. citizens' data loss, which in December 2018 (later it turned out that actually 82 million records were leaked). At the same time, in December 2018, due to security issues, data of 32 million people was stolen in Brazil. In March 2019, 'only' 250,000 confidential documents, including legal ones, leaked from another elastic server. And that's just the first page of search results for the mentioned query.
In fact, hacks are still ongoing and began shortly after the developers themselves "retired" the security features and transferred them to open source.
The reader may notice: "So what? They have security issues, but who doesnāt?"
Now, pay attention.
The question is that until this Monday, Elastic had been taking money from clients for a sieve called security features, which it itself released to open source back in February 2018, about 15 months ago. Without incurring any significant expenses to support these features, the company regularly charged gold and premium subscribers from the enterprise segment.
At some point, the security issues became so toxic for the company and the complaints from clients so threatening that greed took a back seat. However, instead of resuming development and 'patching' the holes in their project that allowed millions of documents and personal data of ordinary people to be exposed, Elastic tossed the security features into the free version of Elasticsearch. And presents this as a great boon and contribution to open source.
In light of such 'effective' solutions, the second part of the blog post, which initially drew our attention to this story, looks quite strange. It talks about ā the official operator of Kubernetes for Elasticsearch and Kibana.
Developers, with rather serious expressions, claim that the removal of security features into the base free package of Elasticsearch will reduce the burden on administrators of these solutions. Overall, everything is great.
"We can guarantee that all clusters deployed and managed by ECK will be protected by default from the moment they are launched, without additional burden on administrators," says the official blog.
As a discarded and poorly supported solution by the original developers, which has turned into a universal punching bag over the past year, how it will ensure security for users is something the developers conveniently leave unsaid.
Source: habr.com
