~/wiki

Sensitive Data Logging

Mis à jour le 2025-01-04Confiance : high
sensitive-data-loggingdata-protectionsecurity-vulnerabilitycsv-loggingunencrypted-dataproduction-riskshr-dataconversation-logs

Security anti-pattern where applications log sensitive information without proper protection, creating data exposure risks through log files, backup systems, and monitoring infrastructure. Particularly critical in systems handling personal, financial, or confidential business data.

Common Sensitive Data Types

Personal Information

  • User conversations and queries
  • Authentication credentials
  • Personal identifiers and contact information
  • Behavioral patterns and preferences

Business Confidential Data

  • Internal system prompts and configurations
  • Proprietary algorithms and decision logic
  • Customer service interactions
  • HR-related queries and advice

Technical Secrets

  • API keys and authentication tokens
  • Database connection strings
  • Encryption keys and certificates
  • Internal system architecture details

Risk Scenarios

Backup Exposure

Unencrypted log files included in system backups create long-term exposure risks if backups are compromised or improperly stored.

Log Shipping Vulnerabilities

Centralized logging systems may transmit sensitive data over insecure channels or store it in systems with different security controls.

Disk Access Compromise

Direct filesystem access by unauthorized users can expose sensitive log contents, especially in shared hosting or compromised systems.

Compliance Violations

Logging personal data without proper protection violates GDPR, HIPAA, and other regulatory frameworks requiring data minimization and protection.

Case Study: Assistant-RH

The cursor-security-audit identified critical sensitive data logging in the assistant-rh system:

Data Exposure Scope

  • Complete user questions and AI responses
  • Full system prompts (up to 50,000 characters)
  • HR-sensitive legal queries and advice
  • Internal generation parameters and configurations

Storage Vulnerabilities

  • Unencrypted CSV files on local filesystem
  • No access control on log directory
  • Full conversation history retained indefinitely
  • No data classification or retention policies

Production Impact

HR professionals' sensitive queries about employment law, personnel issues, and compliance matters stored in plaintext, creating liability for data breaches.

Mitigation Strategies

Data Minimization

  • Log only necessary information for debugging and monitoring
  • Redact or hash sensitive fields before logging
  • Implement structured logging with configurable verbosity levels

Encryption and Access Control

  • Encrypt log files at rest and in transit
  • Implement proper access controls on log directories
  • Use dedicated logging infrastructure with security controls

Retention and Cleanup

  • Establish data retention policies for different log types
  • Implement automated cleanup of expired sensitive logs
  • Regular audit of log contents and access patterns

Alternative Approaches

  • Use sampling for detailed logging instead of full capture
  • Implement separate audit trails for compliance vs. debugging
  • Consider client-side logging reduction for sensitive interactions

Detection and Prevention

Code Review Practices

  • Review all logging statements for sensitive data exposure
  • Implement logging guidelines in development standards
  • Use static analysis tools to detect sensitive data in logs

Runtime Monitoring

  • Monitor log files for sensitive pattern detection
  • Implement alerts for unexpected sensitive data logging
  • Regular security audits of logging infrastructure

Development Controls

  • Use structured logging frameworks with filtering capabilities
  • Implement logging levels with production-appropriate defaults
  • Test logging output in security review processes

See also

  • authentication-bypass - Often combined with logging vulnerabilities
  • production-security - Broader security considerations including logging
  • data-protection - Legal and regulatory requirements for sensitive data