by Serguey Shinder
In February 2025 our payment provider emailed to say they had revoked one of our test keys, because it had appeared on a public web page. The link took me to a free website for formatting and comparing data, the kind developers use a dozen times a day without a second thought. It showed two versions of a response from our order system side by side, neatly indented. Between them they held the names, delivery addresses and order histories of about three hundred and forty customers, and near the top, the key.
We traced it within the hour. A developer of ours, chasing a pricing difference, had pasted the before and after into the tool, pressed its share button, sent the link to a colleague in our chat and closed the tab. The site kept shared pages indefinitely and let search engines find them.
When I asked around, nobody was surprised except me. Everybody used these sites. Formatters, decoders for the tokens our login system issues, converters that turn a timestamp into a date, online diff checkers, pages for testing patterns against sample text. We counted twenty three in regular use in one team. The first thing you do with every one of them is paste something in, and what developers paste is whatever they happen to be working on, which is production data more often than anybody would say in a meeting.
Each of those sites was, in effect, a supplier processing our customers' data. None had been through the review we give a supplier. Most had no owner we could name. Several ran advertising, which means other companies' scripts loaded on the very page where our data sat in a text box.
The first proposal was a ban, and I argued against it. The developers were not being reckless. They were reaching for the fastest tool to hand, and a ban leaves them with the same need and one more reason to hide it. So we made the safe route the quick one. A small internal page now does the dozen jobs people had been going outside for, formatting, comparing, decoding, converting. It runs entirely in the browser, sends nothing anywhere, and is bookmarked on every developer machine, with command line equivalents in our standard setup. Only after that did we block the sites we knew about, with a block page that points to ours.
We wrote to the affected customers that week. Use of the internal page overtook the outside sites within a month, which told me more about the original cause than the investigation had.
What stays with me is that nobody involved believed they had sent data anywhere. They were only looking at it. But looking at data on somebody else's website is sending it there, and the small utilities we use without thinking are precisely the ones nobody thinks to ask about.
– Serguey Asael Shinder
Leave a Reply