Sensitive data logging

Logging sensitive data in C#

Description

Logging passwords, tokens, API keys or session identifiers can expose secrets through log collectors and operational dashboards.

Potential impact

  • Account takeover, session hijacking or disclosure of keys for external services.

Remediation

Do not log sensitive values. If a record is needed, use a fixed redaction marker or a non-sensitive correlation identifier.

Examples

Before

csharp
logger.LogInformation("Password {Password}", account.Password);

After

csharp
logger.LogInformation("Password [redacted]");

The first example exposes the password through log storage and monitoring systems. The revised example records a fixed marker without the secret value.

References