Description
Storing authentication secrets such as passwords, tokens or API keys in plaintext files or serialized data lets an attacker who gains access to the storage read those values directly.
Potential impact
- Attackers may take over accounts or sessions, or misuse API keys.
- Sensitive values may remain in logs, backups and temporary files for a long time.
- A breach may spread beyond the application's storage.
Remediation
- Store opaque references in files instead of the secrets themselves.
- If a secret must be stored, encrypt it with a trusted cryptographic library and manage the encryption keys separately.
- Store password hashes using Argon2id, bcrypt or PBKDF2 instead of the original passwords.
- Keep plaintext secrets out of logs, JSON/YAML configuration files and temporary files.
Examples
Before
python
from pathlib import Path
from flask import request
def bad_password_file():
password = request.args.get("password")
Path("/var/app/password.txt").write_text(password)
After
python
from argon2 import PasswordHasher
def safe_password_hash(password):
return PasswordHasher().hash(password)
Explanation:
- Before: Writes a user's password to a plaintext file.
- After: Uses a password-specific hash without persisting the original value.