Hacker News new | ask | show | jobs
by rurban 2008 days ago
See the safeclib docs and tests. I'm the maintainer. Only a couple do not conform.

Their SecureMemset variant is insecure. Most crypto memset_s implementations are unsafe, but they don't want to flush their cache, so attackers can look at the cache for the secrets.