3 ms·
While getting rid of passwords is admirable and advisable, I don't think it is the answer here. What happens when `JSON.stringfy` posts your fancy magic link to
by werrett 4y ago
While getting rid of passwords is admirable and advisable, I don't think it is the answer here. What happens when `JSON.stringfy` posts your fancy magic link token somewhere undesirable?
Applications will always need to generate, process, and transmit sensitive data. They 'just' need transit it to trusted places. Easy! ;)
Filtering data before it gets to untrusted sinks, or at least warning when it does, seems like a more generalizable pattern. The downside is you both need to know what's sensitive and go out of your way to handle it as such in basically any language or framework.
Cases in point:
* https://www.google.com/search?q=java+avoiding+logging+sensitive+data https://www.google.com/search?q=java+avoiding+logging+sensit...
* https://www.google.com/search?q=golang+avoiding+logging+sensitive+data https://www.google.com/search?q=golang+avoiding+logging+sens...
* https://www.google.com/search?q=python+avoiding+logging+sensitive+data https://www.google.com/search?q=python+avoiding+logging+sens...