Closed Bug 1774244 Opened 2 years ago Closed 2 years ago

Review logs for sensitive information leaks

Categories

(Toolkit :: Password Manager, task, P1)

task

Tracking

()

RESOLVED FIXED

People

(Reporter: serg, Assigned: issammani)

References

(Blocks 1 open bug)

Details

Attachments

(1 file)

Lets take another round of logging review and focus on removing logging of:

  • passwords
  • tokens
  • crypto keys
  • user input
  • addresses
  • credit card details
  • visited URLs (debatable, may be sometimes we need it, but we should strip path and query parameters)

There is rarely a need to log these things and if there is such need it should be done locally only. We can not afford user posting their log while seeking help and accidentally exposing their sensitive information.

P.S. also this is a good chance to remove unnecessary logs if we have any. The less we log the better.

Severity: -- → N/A
Priority: -- → P1
Assignee: nobody → imani
Status: NEW → ASSIGNED
Pushed by imani@mozilla.com: https://hg.mozilla.org/integration/autoland/rev/92e6d5d2672d Cleanup Password Manager Toolkit logs. r=sgalich
Status: ASSIGNED → RESOLVED
Closed: 2 years ago
Resolution: --- → FIXED

Backed out changeset 92e6d5d2672d (Bug 1774244) for causing bc failures on browser_username_select_dialog.js.
Backout link
Push with failures
Failure Log

Flags: needinfo?(imani)
Pushed by imani@mozilla.com: https://hg.mozilla.org/integration/autoland/rev/79d41dfeadc6 Cleanup Password Manager Toolkit logs. r=sgalich

(In reply to Marian-Vasile Laza from comment #3)

Backed out changeset 92e6d5d2672d (Bug 1774244) for causing bc failures on browser_username_select_dialog.js.
Backout link
Push with failures
Failure Log

It should be good now :)

Flags: needinfo?(imani)
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: