Re: [Analytics] EventLogging's country column are logging unwanted (sensitive) chunks of cookie

2014-06-25 Thread Christian Aistleitner
Hi, On Wed, Jun 11, 2014 at 05:09:45PM +0200, Christian Aistleitner wrote: > Columns for country data in EventLogging tables sometimes not only > contain the country code, but also larger chunks of the client > cookies, which may put sensitive data into the tables. > > The corresponding bug is >

Re: [Analytics] EventLogging's country column are logging unwanted (sensitive) chunks of cookie

2014-06-11 Thread Christian Aistleitner
Hi, On Wed, Jun 11, 2014 at 10:25:24AM -0500, Aaron Halfaker wrote: > Props to Oliver Keyes for discovering this issue and bringing it to > people's attention. Yikes ... I didn't link the original report :-( Thanks Aaron for speaking up. Thanks Oliver for discovering the issue! Initial report is

Re: [Analytics] EventLogging's country column are logging unwanted (sensitive) chunks of cookie

2014-06-11 Thread Aaron Halfaker
Props to Oliver Keyes for discovering this issue and bringing it to people's attention. On Wed, Jun 11, 2014 at 10:09 AM, Christian Aistleitner < christ...@quelltextlich.at> wrote: > Hi, > > Columns for country data in EventLogging tables sometimes not only > contain the country code, but also l

[Analytics] EventLogging's country column are logging unwanted (sensitive) chunks of cookie

2014-06-11 Thread Christian Aistleitner
Hi, Columns for country data in EventLogging tables sometimes not only contain the country code, but also larger chunks of the client cookies, which may put sensitive data into the tables. The corresponding bug is https://bugzilla.wikimedia.org/show_bug.cgi?id=66478 At least NavigationTiming