New issue
Advanced search Search tips

Issue 905262 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Closed: Nov 14
Components:
EstimatedDays: ----
NextAction: ----
OS: Android
Pri: 1
Type: Bug



Sign in to add a comment

PII in Android system logs -- domain reliability

Project Member Reported by tnagel@chromium.org, Nov 14

Issue description

Chrome Version: 70.0.3538.80 (Official Build) (32-bit)
OS: Android Pie

What steps will reproduce the problem?
(1) $ adb logcat chromium:V "*:S"
(2) Surf the web (maybe most likely to repro on Google properties?)

What is the expected result?
There should be no PII in system logs per [1].

What happens instead?
URLs show up in system logs:

11-14 11:51:23.441 22840 22905 W chromium: [WARNING:monitor.cc(413)] Request to https://www.google.de/domainreliability/upload had (at least) two NEL headers: "{"failure_fraction":1" and ""include_subdomains":false".
11-14 11:51:23.983 22840 22905 W chromium: [WARNING:monitor.cc(413)] Request to https://beacons5.gvt3.com/domainreliability/upload-redirected had (at least) two NEL headers: "{"failure_fraction":1" and ""include_subdomains":false".
11-14 11:51:28.991 22840 22905 W chromium: [WARNING:monitor.cc(413)] Request to https://beacons3.gvt2.com/domainreliability/upload-nel had (at least) two NEL headers: "{"failure_fraction":1" and ""include_subdomains":false".
11-14 11:52:29.084 22840 22905 W chromium: [WARNING:monitor.cc(413)] Request to https://www.google.de/domainreliability/upload had (at least) two NEL headers: "{"failure_fraction":1" and ""include_subdomains":false".
11-14 11:52:29.091 22840 22905 W chromium: [WARNING:monitor.cc(413)] Request to https://beacons2.gvt2.com/domainreliability/upload-nel had (at least) two NEL headers: "{"failure_fraction":1" and ""include_subdomains":false".

[1] https://chromium.googlesource.com/chromium/src/+/master/docs/android_logging.md#Rule-1_Never-log-PII-Personal-Identification-Information
 
Owner: rch@chromium.org
Ryan, could you please find an owner for this?
Sorry, can I get more context here? What logging are we talking about? Is this LOG(INFO) style logging? Is this Chrome net-internals? Is the PII here the two headers, "failure_fraction" and "include_subdomains"? That doesn't look like PII to me, but maybe I'm not understanding.
Thanks for looking into this!

It's LOG(WARNING) in [1]. The PII is in the URL which may be indicative of the URL that the user has been browsing.

[1] https://cs.chromium.org/chromium/src/components/domain_reliability/monitor.cc?q=monitor.cc&sq=package:chromium&dr&l=413
Owner: mef@chromium.org
Status: Fixed (was: Untriaged)
Many thanks for the quick turnaround!

Sign in to add a comment