Sensitive info in dump #3892
-
can memory dump contain sensitive information? like secrets? our company policy doesn't allow developers to have access to sensitive data (like secrets) that can be gathered in dump? |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
Yes. It contains the memory of the application; whatever information is loaded by the application may be contained in the dump.
No, it cannot.
If the policy is that you cannot have access to sensitive information, then you cannot have access to the dumps, regardless of what tool (dotnet-monitor, dotnet-dump, WER, etc) or technology you are using. The dotnet-monitor tool does have a One caveat is that the If above is still not acceptable, you'll need to request a feature that allows blocking access to certain aspects of the HTTP API or allow/disallow certain actions to be taken depending on the user; this is typically known as authorization. We have enabled Azure AD authentication starting with 7.1, but it does not allow for custom roles/scopes (authorization) at this time. |
Beta Was this translation helpful? Give feedback.
Yes. It contains the memory of the application; whatever information is loaded by the application may be contained in the dump.
No, it cannot.
If the policy is that you cannot have access to sensitive information, then you cannot have access to the dumps, regardless of what tool (dotnet-monitor, dotnet-dump, WER, etc) or technology you are using.
The dotnet-monitor tool does have a
--no-http-egress
command line switch which prevents the HTTP API from ret…