Urgent.News

What's breaking now, across thousands of outlets.

Tech

Your Low-Code Platform Is a Credential Store Whether You Planned It or Not.

I was on a call with a customer's IT lead four months after their system went live. He was calm, which was the strange part. Then he said the sentence I have not been able to unhear since: "We found our ERP key in a data export." It had been sitting in a table row the whole time. Someone in procurement had filled in a field labelled "Access Token" during go-live testing. That field was in the…

A low-code platform can accidentally become a credential store, even if it wasn't intended to be one. This was discovered by a customer's IT lead after their ERP system went live. The key to the ERP was found in a data export, sitting in a table row all along. The key had been entered during go-live testing by someone in procurement, who then unknowingly shared the export.

A low-code platform treats credentials as regular data, often storing them in fields alongside other data. These fields inherit permissions, export paths, audit trails, search indexes, and more from the surrounding data model. This means a password stored in a text field is treated as a record, not a password.

When a customer connects their ERP, the provider typically doesn't ask questions about who owns the key, where it lives, how long it lives, or who can read it. These questions usually come up during an incident. The key belongs to whoever entered it, which may be a former employee. The key lives in backups, clones, exports, screenshots, and more. It can live indefinitely if not properly managed.

The clone feature is particularly dangerous for credentials. Cloning an application also clones its connector configurations, potentially spreading the key to various environments and users. Exports, logs, screenshots, and even AI agents can inadvertently expose credentials. The platform's design makes it easy to accidentally expose credentials, even in well-intentioned situations like testing connections or generating error messages.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

SoundSafari: ten seconds of recording, one minute of listening

Built for the DEV Week 1 “Touch Grass” challenge . What I Built SoundSafari is a small outdoor listening exercise. You record ten seconds of your surroundings, get a tentative sound category, and use…

  • SoundSafari app encourages users to record 10 seconds of ambient sound
  • Users listen for 1 minute to outdoors after recording and write reflection
  • App uses Audio Spectrogram Transformer for local audio classification

Node.js Email Verification Needs Atomic Tokens

Email verification looks like a small feature: create a token, send a message, and accept the token when the user clicks it. In a real Node.js service, the difficult part is not generating the token.

  • Email verification in Node.js requires atomic database operations to prevent duplicate activations.
  • Store cryptographic token digest, not raw value, in database to protect against exposure.
  • Use conditional UPDATE with row lock in consumption process to ensure token acceptance once.

APN, VoLTE, Wi-Fi Calling y 5G: cómo comparar por operadora

Dos personas pueden tener el mismo iPhone, actualizado a la misma versión de iOS, y una hace videollamadas por Wi-Fi mientras a la otra la llamada se le corta apenas sale del rango del router.

  • APN, VoLTE, Wi-Fi Calling y 5G son ajustes de operadora.
  • Estos ajustes dependen del firmware del teléfono, no de la tarjeta SIM.
  • La base de datos Carrier-Explode compila y compara estos parámetros.

Pocket Outside gives you a park plan to print

This is a submission for the Hacktoberfest Open-Source AI Challenge Week 1: Touch Grass . What I Built Pocket Outside helps you choose a small outdoor break in Mississauga.

  • Pocket Outside app finds parks based on user preferences like parks with trees or wetland boardwalks
  • Open-source code allows local park updates and AI model changes, licensed under MIT

More from Saturday 10 October →