3 ms·
Actually, I was trying to point out ways to not have to remove/prune your logs...
by smu 9y ago
Actually, I was trying to point out ways to not have to remove/prune your logs...
- cromwellian 9y agoRight but these days, if you rent a cloud hosted docker container with say, nginx or httpd, you'll get HTTP logs via fluentd with full IP address information, and a lot of people will push these into storage like S3 or GCP buckets for analysis later. If you say, use a point-and-click installation of Wordpress on AWS/GCP/Azure, you're going to get IP logs being held. I'm just pointing out that the regulations impose a lot of costs and expose people to huge risks. I mean, can I be held liable if I use an open source downstream dependency from npm or Maven, and it just so happens to have debug logs that are storing info, and I didn't know about this logging cause I didn't audit every line of code from a downstream dependency? For large companies, this isn't going to be a problem, but the entire open source ecosystem operates on a system that for the most part, you aren't exposed to legal liability by them, except in cases like patent violations or copyright infringement, but now there's a huge cognitive burden being levied on top by a massively complicated new regulatory framework.