Zeroization, part 1: Wiping can make things worse
Summary
The article explores why naive zeroization can worsen security by showing how compilers and CPU behavior can leave secrets in registers or memory despite wiping calls. Through examples (memset optimization, volatile stores, cross-file wipes, and stack spills) it demonstrates that writes may not clear the intended data and that additional copies can persist across calls, creating a false sense of cleanup. It concludes with practical guidance to inspect optimized builds, LTO, and to consider more reliable secret-cleansing techniques, with a promise to cover this in Part 2.