Did you *really* zeroize that key?

Vincent Penquerc'h vincent.penquerch at artworks.co.uk
Fri Nov 8 02:20:50 PST 2002


On Thu, Nov 07, 2002 at 07:36:41PM -0500, Patrick Chkoreff wrote:
> Everybody probably also knows about the gnupg trick, where they define a 
> recursive routine called "burn_stack":
[...]
> Then there's the vararg technique discussed in Michael Welschenbach's book 
> "Cryptography in C and C++":

How about a simple alloca/memset ? Though it would possibly be more
subject to `optimizations'.

-- 
Vincent Penquerc'h





More information about the cypherpunks-legacy mailing list