Overview
The data is handled, but the protection around it is missing: HTTP instead of TLS, weak or no hashing for passwords, card numbers echoed in responses, API payloads full of fields the client never needs.\nBackups, error logs and Git history are common unintended stores of the same secrets.
Indicators of Compromise
Signals that suggest this is present on a system.
- Credentials sent over plain HTTP
- MD5 or SHA-1 password hashes in a breach dump
- Full object serialization returned by an API
Controls that stop it
-
Harden TLS and Security Headers
Serve everything over TLS with HSTS so downgrades are impossible, set a modern Content-Security-Policy, enable HSTS preload, deny framing with frame-ancestors, and switch on Referrer-Policy and Permissions-Policy. Disable unused legacy protocols and cipher suites rather than leaving them configured for compatibility.