in logs.
in logs.
create_user('Bob', 'BobPassword123')
assert "BobPassword123" not in logfileI don't think it's trivial to guarantee non-existence.
I disagree in this case. Log messages don't spontaneously appear in arbitrary places. If the developers understand what their software is doing and how their systems are configured then they should know where to check for the logging messages.
That said, someone should have been watching for this stuff and failed to do so (or to exist), so I'm not excusing them - but this is not a trivial thing to protect against.
With billions of dollars and some the best software developers in the world (supposedly), Facebook should be able to figure this out.
Subject: Change Request
Body: I would like to log the body of authentication requests in production.
Subject Re: Change Request
Body: How will you ensure personal data is not stored that shouldn't be?
Subject: Re: Re: Change Request
Body: I will add configuration Y to logging system X.
You assert that it's trivial, yet you're adding more layers to protect against something like that from happening. It's the naivety that all problems are trivial is what gets people and companies into trouble in the first place
Reviewer: Does this have privacy implications?
Change1: No, Service X marks all PII before this point. Code X drops everything marked in this way.
Two years later.
Change N: Modify request structure for more optimal blah blah blah.
Now suddenly the changed request structure causes a regression in the PII detection which causes some logging of PII.
This shit is way more complex than "just stop people when they ask to log passwords".
What if there is a bug and some other function logs "[...]word123"?
Of course we (and they) should do it anyway, but it does often take an investment in making things testable.
This is the sort of thing that leads the HN crowd to sneer at the old, slow ways of the enterprise world.
What's to stop a malicious ex-lover from grabbing a FB password and reading that person's private messages? If FB didn't even know there were passwords in plaintext, they very likely weren't auditing log access as much as was needed.
[1] https://www.theverge.com/2019/3/21/18275837/facebook-plain-t...
I can't f'in believe I have to explicate such simple things to supposedly intelligent and thoughtful people
I think it would be way worse if we found out they were storing passwords were plaintext in the database in 2019. Even if the security implications are the same/worse, the policy/decision making of such a revelation would be beyond terrible.
edit: To put it another way, remote code execution flaws are terrible but they can happen. However it would be way worse if someone put in a static username/password backdoor. The security outcome may be the same but one is beyond terrible policy/decision making.
If Facebook devops engineers, who are probably among the best trained and highest paid on the planet, lack the same common sense for their users passwords... I can't even come up with an ending to this sentence that would properly express my emotions right now.
Sorry, but it is like saying "there is no SQL injection, only bad input validation".
... for seven years.