Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm late to this party, but one thing I take minor issue with in this article, is the "log everything" section. I agree that logging is good, and don't want to give a wrong impression on that, but, logging everything can have some problems. Users regularly clicko the username/password fields and you'll get exploitable logs of: odd username from IP followed shortly by real user name from same ip with successful log-in. If you don't secure your logs well, you now have a potential security breach, and those log systems can be vulnerable to all the stuff you went through that password securing rigamorole to avoid (bad software, sql injection, etc, etc.) I bring it up, because a lot of times people don't think to secure the logging system as much as the other stuff, partly because it is regularly behind the dmz, and partly because it is just off the standard security map for user security issues.

Just $.02 for this conversation :)



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: