RE: [VulnDiscuss] Re: iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Password

Simple Nomad <[email protected]>
Newsgroups gmane.comp.security.vulnerabilities.watch.general
Message-ID <[email protected]>
> Perhaps, but I don't feel as strongly as you do.  You can read memory with
> format string bugs and there have been other vulnerabilities where memory
> is output.  In my opinion, the relatively few cycles required to zero out
> most sensitive buffers in programs such as clients, encryption software,
> etc, are worth it.

I wrote a utility called NCrypt (available from
http://ncrypt.sourceforge.net/, for those interested, updated it last
night in fact) that uses encryption, and I go to the trouble to not only
try to lock memory but also scrub buffers where I can. Yes it is a few CPU
cycles, but yes it does not take care of everything. In the README with
the package I list a number of areas where I feel there are still risks,
simply because I don't want people to think this problem goes away with
simple variable scrubbing. It does *help*.

I do find this discussion interesting though, as it seems most people
don't think in those terms, but (with the probable exception of iDefense)
I am preaching to the choir.

-         Simple Nomad          -    negotium     -
-      [email protected]        -   perambulans   -
-  [email protected]  -   in tenebris   -
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.