If anyone uses Emerald Chat WATCH OUT
I was poking around Emerald Chat in their production code is :
- maskAllText: false,
- maskAllInputs: false
Sentry Session Replay is running on 50% of sessions. maskAllInputs: false means password fields aren't masked your keystrokes are being recorded and shipped to Sentry's US servers.
The worst part: replays OnErrorSampleRate: 1.0. If you've ever miss typed your password on Emerald Chat, that session was recorded at 100%. Your password attempt went straight to Sentry.
Their privacy policy says "protecting your privacy is our top priority." None of this is disclosed anywhere in it.
maskAllInputs is ON by default in Sentry. Someone turned it off deliberately.
Change your password and don't reuse it.