3 ms·
What if someone gets into your app logic and make a POST trigger that gets the passwords out. What if you log all POST requests for debugging purposes and forg
by trustno2 2y ago
What if someone gets into your app logic and make a POST trigger that gets the passwords out.
What if you log all POST requests for debugging purposes and forget to sanitize the logs.
What if you have XSS in your web app that sends the password to a third party.
What if your mobile phone app has a dependency that includes a keylogger.
The likelihood of this increases the more layers you have in your organization (for example, the log pipeline team assumes the logs are already sanitized; the login form team assumes the log team is sanitizing them; it all goes through some A/B testing team that just dumps all data to "data lake" somewhere unsafe; the FE team puts in random node.js dependencies as it's "just a frontend"; etc).
Passwords can leak from more places than just from the DB...
- figassis 2y agoGetting into the app's running process is an effective way to exfiltrate everything, and likely they'd have a lot more to worry about there. I don't however think that piggybacking on a live app does not give you the size of these leaks. I mean, does every user of a service access the service in these periods? More likely they steal the app's credentials (db, cloud provider, etc) and then go to town on data at rest. You're right on logs and things like fullstory, but no one on any team should assume things are sanitized. You do your job independently. If you're an infra, devops, sre, does it make sense to say I thought they had it handled? Was that what you marketed on your resume? Not saying there aren't complexities involved, but in many of these cases I see a lot of low hanging fruit, likely due to moving too quickly. We really need to own up to the fact that we've grown too comfortable with not giving any thought to other people's data. Why is it that there are the PCI audits when you handle card data, but not when you handle PII? Because card fraud hits the banks and they don't want to pay for any of that. So an entire industry was spawned, it's not perfect, but it helps a lot. You do not see a lot of credit card leaks.