Postman is logging all your secrets and environment variables

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

Postman has been found to log secret strings and environment variables, compromising user privacy. Despite claims of protecting sensitive data, the app sends unmasked variables to its servers, posing risks especially for healthcare applications. Users are advised to block Postman's analytics endpoints to prevent data leakage.

3m read timeFrom anonymousdata.medium.com
Post cover image
Table of contents
Postman is logging all your secrets and environment variablesCharles ProxyCertificate pinningPostman leaks secretsIf you really must use PostmanA note about ethics
34 Comments

Sort: