3 ms·
> and the other is a very easy mistake to make which can go unnoticed for a long time (because you can be attempting to log things completely unrelated to login
by scriptkiddy 8y ago
> and the other is a very easy mistake to make which can go unnoticed for a long time (because you can be attempting to log things completely unrelated to logins).
This is not an excuse. If you're logging all request data, you need to strip or encrypt sensitive information in that request data. Handling Persistence of sensitive data is web development 101. Just because it's not in a database doesn't give you a pass to leave it unprotected.
This level of incompetency is unacceptable.