3 ms·
replace DB values with opaque, random string that can be exchanged as a token for the underlying sensitive PII value, such as name often you would restrict and
by ev1 4y ago
replace DB values with opaque, random string that can be exchanged as a token for the underlying sensitive PII value, such as name
often you would restrict and rate limit the tokenization service, so if your daily traffic was x token exchange requests and someone sql-injects your db and tries to exchange every token, it would get rate limited immediately (because you still have normal traffic volume consuming that quota) and they might get a few rows before alerts go off.
when i did a short stint in finance, we would kind of "add quota" to the rate limit bucket when a user performed an action that required it - if you had direct SQL access and access to the tokenization service, you wouldn't have enough quota to exchange a token unless you also had access to separate application code that would add quota as needed (user logs in, need to retrieve name and phone number and city to show on web page, application requests to add exactly 3x "allow an exchange" to the quota, then consumes that quota)