3 ms·
While I love travis for what it is, this is a foreseeable result here. At the very least they need to add a failsafe that checks all outgoing logs for any secu
by andrewvc 9y ago
While I love travis for what it is, this is a foreseeable result here.
At the very least they need to add a failsafe that checks all outgoing logs for any secure tokens and replaces them with '*' or something.
If you sign up to play a game of whack-a-mole you will lose eventually.
- wwwigham 9y agoThat's actually exactly what the stated mitigation they've implemented is, if I've read it correctly. Though they're working on building it into their VM images in order to reduce the memory overhead of the filter.
- tehlike 9y agoWhat if the token was encrypted or altered in a way simple find replace wouldnt work?
- ReverseCold 9y agoEven just encoding it differently (base64, bin, hex, etc) would work against that.