DigiNews

Tech Watch by Johan Denoyer

← Back to articles

Zeroization, part 1: Wiping can make things worse

Quality: 8/10 Relevance: 9/10

Summary

The article explores why naive zeroization can worsen security by showing how compilers and CPU behavior can leave secrets in registers or memory despite wiping calls. Through examples (memset optimization, volatile stores, cross-file wipes, and stack spills) it demonstrates that writes may not clear the intended data and that additional copies can persist across calls, creating a false sense of cleanup. It concludes with practical guidance to inspect optimized builds, LTO, and to consider more reliable secret-cleansing techniques, with a promise to cover this in Part 2.

🚀 Service construit par Johan Denoyer