Zeroization, part 1: Wiping can make things worse
10 points by olliej
10 points by olliej
Perhaps a programming language could have a compiler directive NOT to optimize away certain lines of code, such as the memset.
As the essay shows in spades the zeroing itself, when it does happen, can cause more harm than good by forcing stack storage or even extra copies. The problem is that the intent is not conveyed to the compiler, so you’re still playing silly bugger with it, not optimizing the wrong operation still does not do the right thing.
As Simon, Chisnall, and Anderson noted near 10 years ago in “what you get is what you C”, you can’t solve this by trying to trick the compiler for eternity, it would be a lot more sensible to tell the compiler what you need clearly.
Yeah, the ideal fix would be some kind of "scrub this value" qualifier/attribute that gets passed to the backend
memset_s serves that purpose, but this is the specific problem being discussed in the article: if the value is not in memory you don't need to zero the memory, but by calling memset[_s] you force the compiler to spill the value onto the stack for the express purpose of zeroing it.
Unless the compiler handles calls to memset_s() specially so it "knows" to zero out the variable, regardless of where it lives (memory or registers). C compilers already can treat memset() (and memcpy(), memmove()) specially (when you include <string.h>) by inlining them or calling a function, depending upon the context.