Skip to content

A failed breach lookup logs the password-hash prefix next to the user #707

Description

@rubenvdlinde

lib/Controller/BreachProxyController.php line 195 logs 'Keepiq: HIBP range lookup failed: ' . $e->getMessage(). When the HTTP client throws, its message carries the request URL, https://api.pwnedpasswords.com/range/<prefix>. Nextcloud stamps every log line with the requesting user, so nextcloud.log ends up holding a user id beside the first five hex characters of a SHA-1 of a password they typed. The comment one line above says that pairing must never happen.

The prefix alone is k-anonymous. Paired with a user and a time, it narrows that user's password to one of a few hundred hashes in the range. Anyone who can read the log gets that.

Found while adopting the connection registry (#706). That PR does not change the log line, and its connection report only ever carries the HTTP status.

What to do

  • Log the exception class and, when there is one, the HTTP status. Never getMessage().
  • Add a test that throws an exception whose message contains a prefix and asserts the logged message does not.

Done when no log line written by the breach proxy can contain the prefix.

🤖 Generated with Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

triageAwaiting triage

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions