Sensitive Data Logging
Security anti-pattern where applications log sensitive information without proper protection, creating data exposure risks through log files, backup systems, and monitoring infrastructure. Particularly critical in systems handling personal, financial, or confidential business data.
Common Sensitive Data Types
Personal Information
- User conversations and queries
- Authentication credentials
- Personal identifiers and contact information
- Behavioral patterns and preferences
Business Confidential Data
- Internal system prompts and configurations
- Proprietary algorithms and decision logic
- Customer service interactions
- HR-related queries and advice
Technical Secrets
- API keys and authentication tokens
- Database connection strings
- Encryption keys and certificates
- Internal system architecture details
Risk Scenarios
Backup Exposure
Unencrypted log files included in system backups create long-term exposure risks if backups are compromised or improperly stored.
Log Shipping Vulnerabilities
Centralized logging systems may transmit sensitive data over insecure channels or store it in systems with different security controls.
Disk Access Compromise
Direct filesystem access by unauthorized users can expose sensitive log contents, especially in shared hosting or compromised systems.
Compliance Violations
Logging personal data without proper protection violates GDPR, HIPAA, and other regulatory frameworks requiring data minimization and protection.
Case Study: Assistant-RH
The cursor-security-audit identified critical sensitive data logging in the assistant-rh system:
Data Exposure Scope
- Complete user questions and AI responses
- Full system prompts (up to 50,000 characters)
- HR-sensitive legal queries and advice
- Internal generation parameters and configurations
Storage Vulnerabilities
- Unencrypted CSV files on local filesystem
- No access control on log directory
- Full conversation history retained indefinitely
- No data classification or retention policies
Production Impact
HR professionals' sensitive queries about employment law, personnel issues, and compliance matters stored in plaintext, creating liability for data breaches.
Mitigation Strategies
Data Minimization
- Log only necessary information for debugging and monitoring
- Redact or hash sensitive fields before logging
- Implement structured logging with configurable verbosity levels
Encryption and Access Control
- Encrypt log files at rest and in transit
- Implement proper access controls on log directories
- Use dedicated logging infrastructure with security controls
Retention and Cleanup
- Establish data retention policies for different log types
- Implement automated cleanup of expired sensitive logs
- Regular audit of log contents and access patterns
Alternative Approaches
- Use sampling for detailed logging instead of full capture
- Implement separate audit trails for compliance vs. debugging
- Consider client-side logging reduction for sensitive interactions
Detection and Prevention
Code Review Practices
- Review all logging statements for sensitive data exposure
- Implement logging guidelines in development standards
- Use static analysis tools to detect sensitive data in logs
Runtime Monitoring
- Monitor log files for sensitive pattern detection
- Implement alerts for unexpected sensitive data logging
- Regular security audits of logging infrastructure
Development Controls
- Use structured logging frameworks with filtering capabilities
- Implement logging levels with production-appropriate defaults
- Test logging output in security review processes
See also
- authentication-bypass - Often combined with logging vulnerabilities
- production-security - Broader security considerations including logging
- data-protection - Legal and regulatory requirements for sensitive data