RE: [VulnDiscuss] Re: iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Password
Simple Nomad <[email protected]>
| Newsgroups | gmane.comp.security.vulnerabilities.watch.general |
|---|---|
| Message-ID | <[email protected]> |
> Perhaps, but I don't feel as strongly as you do. You can read memory with > format string bugs and there have been other vulnerabilities where memory > is output. In my opinion, the relatively few cycles required to zero out > most sensitive buffers in programs such as clients, encryption software, > etc, are worth it. I wrote a utility called NCrypt (available from http://ncrypt.sourceforge.net/, for those interested, updated it last night in fact) that uses encryption, and I go to the trouble to not only try to lock memory but also scrub buffers where I can. Yes it is a few CPU cycles, but yes it does not take care of everything. In the README with the package I list a number of areas where I feel there are still risks, simply because I don't want people to think this problem goes away with simple variable scrubbing. It does *help*. I do find this discussion interesting though, as it seems most people don't think in those terms, but (with the probable exception of iDefense) I am preaching to the choir. - Simple Nomad - negotium - - [email protected] - perambulans - - [email protected] - in tenebris -