Skip to content

LogDrop Taint v1.11.0

Choose a tag to compare

@burak-initialcode burak-initialcode released this 20 Aug 12:27
· 30 commits to main since this release
8f548db

Identity-document fields are read as personal data.

The source list stopped at email, phone and password. A customer logging
citizen.ssn or applicant.passportNumber got nothing back — the same leak
under a different field name. Now covered: ssn, socialSecurityNumber,
passportNumber, dateOfBirth, securityCode, postalCode, and for Turkey
tckn and vergiNo.

Measured before adding, on seven codebases (7,239 Swift files). These names
occur 479 times — nearly all of it inside Bitwarden, a password manager that
stores exactly this kind of identity record — and adding them produced zero
findings. Every codebase in the corpus reports the same count it did before.

Device identifiers were measured and rejected. identifierForVendor and
deviceToken caught two real leaks, and two lines of WordPress-iOS's launch
diagnostics, which prints device model, OS, language, UDID and push token on
purpose for its support team. Two findings in a healthy production codebase is
noise, not a rule. A customer who disagrees adds them in .logdrop.json.

Nothing else moved: same SARIF 2.1.0 shape, same exit-code contract
(0 clean · 1 findings · 2 licence · 3 config), same offline licence
verification, still no network access of any kind.