cross-posted from: https://zerobytes.monster/post/2458702

The original post: /r/mullvadvpn by /u/Imaginary_Dot5703 on 2024-08-14 05:20:49.
you are viewing a single comment's thread
view the rest of the comments
[–] 1 point 2 years ago

The unencrypted data should only be in memory when needed (copied to clipboard, shown on screen etc). After use the objects handling sensitive should overwrite themselves.

A string falling out of scope in C++, or an object being left to the garbage collector is still readable and not overwritten by default. It's a very easy problem to solve in C++, either through custom allocators or destructors. But it makes a bigger difference when objects having short lifetimes

  • source