Provide a more privacy-focused configuration (not capturing detailed devices info) #3431
-
Dear Ory community, in my team we have been using a self-hosted version of Kratos for over a year and it has been quite a successful endeavour (kudos to the whole Ory team 🙇). We are now looking at the privacy aspects of it and trying to minimise the amount of personal data we are capturing (in fact we want to capture none of what could be qualified as PII). What we have noticed that there is a list of devices associated with Sessions which currently stores an I am wondering if Kratos has a configuration setting allowing not to capture those details. Alternatively if anybody sees a way to anonymise this information I would also appreciate any pointers & suggestions. Thanks a lot. Update: asked the same question via Ory Slack here |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 3 replies
-
Hello @dmakarenko Can you elaborate a bit more on the privacy issue? AFAICT the devices property is only visible to the user themselves and Ory Network (the latter could not serve the user without knowing their IP). The data in I think its an interesting (and not easy) topic, so happy to start a conversation here! Edit:
|
Beta Was this translation helpful? Give feedback.
-
Hi, I need to drop those fields for privacy reasons and I understand there's no dedicated configuration for this. Is this something achievable by a pre/post login hook? Is adding a property to handle this in the configuration file something we can consider? Thanks! |
Beta Was this translation helpful? Give feedback.
Hey @Pedr0Rocha
I think this should not be stored in Kratos by default anyway - Its been a while since I checked this but it should only be visible to the end user and your Kratos deploy while the session is active.
I don't think you can modify the session contents with an Ory Action webhook 🤔
In any case if you use Ory Kratos for a commercial use case in production it is recommended to get an Ory Enterprise License (OEL).
With the OEL you get bug and security fixes as they come in and you don't have to wait for the next release, as well as professional support, and the Ory dev team can help you out with special feature requests like this.
Plus you ensure long-term sustainability of the p…