3 ms·
I disagree that they are both terrible security designs. We expect every company to not use plaintext for auth. We do not expect every company to have infra/ops
by EnFinlay 8y ago
I disagree that they are both terrible security designs. We expect every company to not use plaintext for auth. We do not expect every company to have infra/ops setup to prevent logging on login requests.
- dcow 8y agoThat’s certifiably depressing.
- aequitas 8y agoBy extending this logic, a car manufacturer should be blamed for not designing proper brakes for their car. But if a worker then accidentally installs the breaks wrong they are not responsible? Imho, a company (especially as big as facebook) should have the right process and procedures to prevent these kind of problems and ensure developers have proper training to make them aware of the consequences of their actions.
- EnFinlay 8y agoInteresting analogy and I see your point. If a car manufacturer's process made it easy to install the brakes wrong they would be held responsible (probably with a recall or damages for lives lost due to faulty brakes). I guess part of this is that passwords aren't considered that important to many people :(
- EpicEng 8y agoWho is "we" in this scenario? Governing bodies do. Engineers I've worked with in health care do, as do our PM's, security officers, etc. I designed a clinical testing platform a couple of years ago. Our initial requirements stated very clearly that PHI and PII were not to appear in logs. This is basic stuff for anyone who actually works at this scale / level of sensitivity.
- code_duck 8y agoI would expect FB to have that, though.
- deleted 8y ago[deleted]
- nck4222 8y ago>We do not expect every company to have infra/ops setup to prevent logging on login requests. What? I absolutely expect every company to not log my password in plain text. In my 15 years as a developer across several companies and industries, I have never seen anybody log passwords, or advocate for logging passwords. I'm struggling to think why any employee of any company should be able to view a plain text password in any form. Why would there not be an expectation here?
- viraptor 8y agoYou're taking about expectation not to log the password. That's fine. The parent was taking about expectation about infrastructure that validates this. This is both very uncommon and impossible to do 100% correctly. You can scan logs for a prefix (password=), you can do entropy counting, you can try to decode hex values in text. But if you find a base64 encoded hex string representing "foobar" - how do you even know it's a password? Short of trying all possible decodings of all possible substrings against your full password database, this is an impossible task. (You can do best-effort things though)
- nck4222 8y agoAh ok thanks, I misunderstood.