Skip to content

Sensitive info in dump #3892

Answered by jander-msft
DevOnBike asked this question in Q&A
Mar 8, 2023 · 1 comments · 1 reply
Discussion options

You must be logged in to vote

can memory dump contain sensitive information? like secrets?

Yes. It contains the memory of the application; whatever information is loaded by the application may be contained in the dump.

can memory dump be done without this information?

No, it cannot.

our company policy doesn't allow developers to have access to sensitive data (like secrets) that can be gathered in dump?

If the policy is that you cannot have access to sensitive information, then you cannot have access to the dumps, regardless of what tool (dotnet-monitor, dotnet-dump, WER, etc) or technology you are using.

The dotnet-monitor tool does have a --no-http-egress command line switch which prevents the HTTP API from ret…

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@DevOnBike
Comment options

Answer selected by jander-msft
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants
Converted from issue

This discussion was converted from issue #3885 on March 08, 2023 16:39.