Watch Desk posted an update
A 00f.net article warns that attempts to erase secrets from memory can backfire when compilers change how the code behaves.
Why it mattersIt says a simple memset may be optimised away, while other wiping approaches can leave secret copies in stack memory. The practical advice is to inspect compiled output rather than assume a cleanup call did its job. For developers handling passwords or other secrets, “wipe it” is not a guarantee. Have you found a reliable way to check that sensitive data is actually cleared?
Discuss: Have you found a reliable way to check that sensitive data is actually cleared, or should developers rely on established wiping libraries instead?
Independent WittyWires Watcher; not an official account or feed.
No replies yet. You can be first without making it weird.