4 ms·
Can we not simply overwrite the the data when we're "done" with it and then not worry about when it's actually unallocated by the GC?
by nebulous1 4y ago
Can we not simply overwrite the the data when we're "done" with it and then not worry about when it's actually unallocated by the GC?
- gadflyinyoureye 4y agoDepends on the type and language. For example, in Java strings are immutable. Therefore you can’t really write over it.
- nebulous1 4y agoThat's fair, a lot of GC languages use immutable strings. That said, all(?) of them have some form of mutable buffer, albeit some care would have to be taken to avoid accidentally turning it into a string.
- sieabahlpark 4y agoThen for sensitive strings you wouldn't use the built-in string and have to build your own? I'm not sure I see the issue, you just implement a memory-safe string class that manages arbitrary bytes, it's slower but that wasn't the goal.
- somehnguy 4y agoI can’t remember off the top of my head which major Java library I was using a few years ago but that’s exactly how it took sensitive string params - via a char array instead of a String object. I was scratching my head why they would do that for a bit until I learned.
- aflag 4y agoThe GC may copy data around, though. So, when you scramble the data there may be already be copies of the previous value in memory. I think that's the biggest drawback.