2 ms·
Go can create C ABI shared libraries, I think OpenSSL-compatible C bindings to Go's crypto/tls would be a really interesting option.
by mappu 8mo ago
Go can create C ABI shared libraries, I think OpenSSL-compatible C bindings to Go's crypto/tls would be a really interesting option.
- AtlasBarfed 8mo agoDo you want garbage collection in your SSL?
- rurban 8mo agoBetter than no memory safety, sure. Also a kernel should be memory safe, so garbage collected.
- codys 8mo agoGarbage collection is not required for memory safety. Languages that have garbage collection are not all memory safe.
- KingOfCoders 8mo agoWhere do you see the problems? Because of memory that was not cleaned up and leaks secrets? There the new runtime/secret could help.
- jezek2 8mo agoClearing of the secrets is a separate issue from memory allocation mechanism. It must be done all the way from the encryption layer to the program to avoid the leaks. This is typically not done, only certain parts such as handling of the crypto keys. That's because it's pervasive and requires reworking everything with that in mind (TLS library, web framework, application). On the other hand the centralization and global usage of GC in the process allows to modify it to always zero out the memory that it deallocated and to do GC at regular intervals so it can have advantage here (it's very easy to inadvertly leak the secrets to some string).