3 ms·
I am afraid never - security is never a design goal, even when security is the main purpose of the software (OpenSSL/ heartbleed).
by java-man 7y ago
I am afraid never - security is never a design goal, even when security is the main purpose of the software (OpenSSL/ heartbleed).
- miloignis 7y agoThat's why I think formally verified implementations are so critical, and why Project Everest (formally verified TLS) is so cool: https://project-everest.github.io/ https://project-everest.github.io/
- johnisgood 7y agoAlso: https://github.com/Componolit/libsparkcrypto https://github.com/Componolit/libsparkcrypto
- java-man 7y agoNot an ADA guy, just curious: 1. does this library provide a way to clear secrets from memory? 2. does it provide means to ensure that the secrets will not be swapped to disk on page fault or copied in memory? 3. does it bignum implementation provide a way to clear the internal buffer? thank you.
- johnisgood 7y agoHey! I only found https://github.com/Componolit/libsparkcrypto/blob/0a3a3c5ed74f483e5d8539e2d84bf988547bf5b4/src/shared/generic/lsc-internal-pad64.adb https://github.com/Componolit/libsparkcrypto/blob/0a3a3c5ed7.... I hope someone who is more acquainted will help us out. In any case, you should read: - https://www.auto.tuwien.ac.at/~blieb/AE2017/presentations/ae2017_chapman.pdf https://www.auto.tuwien.ac.at/~blieb/AE2017/presentations/ae... - https://www.auto.tuwien.ac.at/~blieb/AE2017/presentations/Hardware-based-data-protection-in-Ada.pdf https://www.auto.tuwien.ac.at/~blieb/AE2017/presentations/Ha... - https://dwheeler.com/secure-programs/Secure-Programs-HOWTO/protect-secrets.html https://dwheeler.com/secure-programs/Secure-Programs-HOWTO/p... - https://dwheeler.com/lovelace/s17s5.htm https://dwheeler.com/lovelace/s17s5.htm