3 ms·
No mention of setting the :sensitive process flag to true. Been a while since I've done Elixir, but I think sensitive: true disables additional things, possibly
by latch 2y ago
No mention of setting the :sensitive process flag to true. Been a while since I've done Elixir, but I think sensitive: true disables additional things, possibly to the point of being a little too much in some cases.
- rdtsc 2y agoI was going to mention that, too, but the author does provide a link below to https://erlef.github.io/security-wg/secure_coding_and_deployment_hardening/sensitive_data.html https://erlef.github.io/security-wg/secure_coding_and_deploy... which does talk about the sensitive flag. It also talks about the using `private` ETS tables. However, in general terms, I would say, stuff that prevents data being dumped into the logs is very useful, but trying to protect it against inspection assuming an attacker has gained remote shell access is a bit of a fool's errand, and it has to be balanced against the inconvenience of trying to debug the system when things go wrong -- tracing that sensitive process, checking the contents of that private ets table, etc.