3 ms·
It's an issue for the same reason storing passwords in plaintext in the database is an issue. Reading the hash != access to the account. Passwords should be pri
by EnFinlay 8y ago
It's an issue for the same reason storing passwords in plaintext in the database is an issue. Reading the hash != access to the account. Passwords should be private to everyone except the account owner. If devs have access to all user passwords then you have a fucking issue.
- icedchai 8y agoOn many systems, "real passwords" are just a tcpdump away (most sites aren't doing end-to-end TLS. It's TLS terminated at the load balancer / proxy level, everything else is in the clear.)
- EnFinlay 8y agoAlso true.
- jeltz 8y agoThat is a much smaller issues than passwords stored in logs, because the people who have access to running tcpdump usually also have the ability to intercept traffic in other ways (e.g. by updating the application to log all traffic or by inspecting RAM). On the other hands access to logs is usually handed out to a much bigger group of people.
- the_duke 8y agoTrue, but thankfully service meshes like Istio are increasingly used which encrypt the traffic between each service.