Skip to content

Topic

Secrets in logs

Credentials and sensitive values exposed through application logs, traces, proxies and debugging artefacts.

Current clusters

build1 publisher

Anyone who reads one STK Push request body can decode the M-Pesa passkey

Safaricom's Daraja STK Push builds its request password as reversible base64 of the passkey and two values that are public or sent in the same body. Any log, APM trace or proxy that captures that body holds a decodable copy of a credential with no documented way to revoke it.

Publishers:dev.to

Reality

Evidence58
Adoption
Insufficient
Hype gap+5
Incentives20
Confidence60