Help - Search - Members - Calendar
Full Version: Userdata & log files
ALM Works Forums > Deskzilla > Features   —   Deskzilla
whitehorse
Ver 1.0beta2 build 1081.
I noticed log files e.g. 'tracker0.log' currently include userdata used for accessing the bugzilla server e.g
20050822-morenumbers INFO POST http://example.bugzilla.org
20050822-morenumbers INFO Bugzilla_login = example@mail.com
20050822-morenumbers INFO Bugzilla_password = ishere
20050822-morenumbers INFO GoAheadAndLogIn = 1
20050822-morenumbers INFO GoAheadAndLogIn = Login

Admittedly this probably wouldn't be seen as an issue by everyone since Deskzilla log files're on the local machine and... the workstation should ideally be secure anyway. smile.gif

I can see how some users more familiar with only seeing asterisks or other characters/hashes instead of login details, within application log/settings files might be uncomfortable though. Less visible userdata might be preferable.
Igor Sereda
Thank you for noticing this problem - we also noted this mishap soon after delivery. This already has been fixed - passwords are hidden behind *** in the new version that will be available soon.

Do you think it's needed to hide e-mail address or other data?

Regards,
Igor
whitehorse
QUOTE
20050822-morenumbers INFO Bugzilla_login = example@mail.com
---
Do you think it's needed to hide e-mail address or other data?

Wellll I don't know if it's needed as such. biggrin.gif
But I can see how end-users might be spooked by seeing their email address in there. I would agree that whether or not there's any real, valid reason for them to be worried about it is quite another matter! smile.gif

But... user's get used to certain things and so may think their email address being in there is likely to result in more spam email, even though because the local log file of course isn't included with every bug they submit or something, that is not going to happen.

I think replacing the first part of the email address with asterisks/periods could be worthwhile, leaving the domain name seems fine:
Example: John Smith ********@yahoomail.com
Or: *****@yahoomail.com
I can't see anyone being concerned about the other logfile information such as the bugzilla installation they connect to being in there, unmasked.
Igor Sereda
I agree. We'll get that done in 1.0.

Regards,
Igor
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2012 Invision Power Services, Inc.