Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Vuln Dev
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: Software leaves encryption keys, passwords lying around in memory Oct 30 2002 09:22PM
Dan Kaminsky (dan doxpara com)
>
>
>volatile char key[ 16 ];
>
>(== don't optimise access to/from this var in any way)
>
>end of problem.
>
>
Yes, but here you *hope* the compiler has the same semantics for
"volatile" that you do. The "keys to the kingdom"(sufficient context to
zap your memset) are left in place; you just ho...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus