Wouldn’t it be pretty simple (for FB) to create accounts with super unique password as part of their test process? Then they scan all their storeage for the super unique password? Or am I missing something?
They also would have to run it in such a way after every code update. Since every code update may introduce a new nook or cranny, that would slow down development too much.
I wouldn’t even try doing that, but instead have a two-pronged defense:
- code review of every single log statement in the code base by individuals whose _only_ job it is to prevent such problems.
- permanent checking of every single line logged for a thousand or so common passwords.
At Facebook’s scale, the second probably has lots of false positives, so I would do that at time of logging, when the location doing that logging is known, so that an alarm only gets triggered if a single log statement repeatedly logs passwords.