Security of data in memory

From: Nicholas Brawn (ncb@pobox.com)
Date: 12/25/01


Date: Wed, 26 Dec 2001 00:31:16 +1100
From: Nicholas Brawn <ncb@pobox.com>
To: secprog@securityfocus.com

I have a unix program that reads in an encrypted file, decrypts it and
works on it whilst in memory. What security considerations should I be
aware of? I'm thinking of things like clearing the decrypted buffer
prior to exiting, not storing any of the data in a temporary file, etc.

Cheers,
Nick

--
Real friends help you move bodies.



Relevant Pages

  • Re: Security of data in memory
    ... >> I have a unix program that reads in an encrypted file, decrypts it and ... memory pages to prevent them from being swapped out to disk. ...
    (SecProg)
  • Re: Security of data in memory
    ... >>>I have a unix program that reads in an encrypted file, decrypts it and ... >memory pages to prevent them from being swapped out to disk. ...
    (SecProg)
  • Re: Security of data in memory
    ... > I have a unix program that reads in an encrypted file, decrypts it and ... > works on it whilst in memory. ...
    (SecProg)
  • Re: Security of data in memory
    ... > I have a unix program that reads in an encrypted file, decrypts it and ... > prior to exiting, not storing any of the data in a temporary file, etc. ... Storing it "in memory" risks having it written out to swap, ...
    (SecProg)
  • Re: Security of data in memory
    ... want to access that range of memory. ... Or put a flag at the begining of that ... > I have a unix program that reads in an encrypted file, ... I'm thinking of things like clearing the decrypted buffer ...
    (SecProg)

Quantcast