Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's better to have one place to look for diagnostic information. This sort of just-in-time masking seems optimal to me.


Diagnostic information shouldn't contain secrets. If you need access to that, there are mechanisms to access it.


This is overly general: whether or not secrets should be in diagnostic information depends on what you’re trying to diagnose. I’ve written PAM modules, for example, and logging TOTP secrets and passwords was absolutely essential for development purposes, even if I eventually deleted the relevant code for production.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: