4 ms·
I hope Amazon, Apple and Google are doing better. How can we know for sure? It's not unreasonable to ask because I would have thought it completely NUTS to th
by Mugwort 8y ago
I hope Amazon, Apple and Google are doing better. How can we know for sure? It's not unreasonable to ask because I would have thought it completely NUTS to think FB used clear text but apparently they did (or still do). What about everyone else? Does anyone know how to find out?
- javagram 8y ago> Does anyone know how to find out? Join the ops team at each of those companies, work your way to a position where you can analyze log files, then start analyzing them and see if you can find data that should have been obscured. I don’t see any way to find out otherwise, we are talking about querying TBs of internal, company specific private logs to see if someone made a mistake. The best anyone could tell you is “I work for company X and I don’t think we’ve had this problem.” Edit: just using a password manager with unique password for every site will solve most of the problems from a customer perspective. My Facebook password is unique to Facebook and I have 2FA so even an engineer with my password from a log couldn’t login to my account.
- puzzle 8y agoAt Google you don't get to read random log files, sometimes even from your own project. There are entire pipelines for raw and sanitized logs, with expiration dates and corresponding access controls. Unless you're on the security team, crawling randomly through logs for no good reason is a quick way to get in trouble.