[vox-tech] Which cipher to use?

Matt Roper vox-tech@lists.lugod.org
Mon, 3 Jun 2002 22:46:11 -0700


On Mon, Jun 03, 2002 at 10:25:23PM -0700, Ryan wrote:
> > Hrm, I'd argue that this isn't true.  Many applications specifically pin
> > pages so they aren't swappable (I.e. ssh).  Not to mention a healthy linux
> > box shouldn't be swapping bins out to disk while they are being
> > actively used.  Have you ever found a password there?
> 
> Yea, I grep'ed it for fragments of several passwords I use and found them.

Do you know which applications where leaving these passwords in swap?
It might be worth submitting a patch that zeroes out the password in
memory as soon as it is no longer needed...


Matt

-- 

*************************************************
* Matt Roper <matt@mattrope.com>                *
* http://www.mattrope.com                       *
* PGP Key: http://www.mattrope.com/mattrope.asc *
*************************************************