<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>C on Kuldeep Pisda</title><link>https://kdpisda.in/tag/c/</link><description>Recent content in C on Kuldeep Pisda</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 08 Oct 2026 08:30:00 +0530</lastBuildDate><atom:link href="https://kdpisda.in/tag/c/index.xml" rel="self" type="application/rss+xml"/><item><title>Wiping a Secret Can Create the Copy You Leave Behind</title><link>https://kdpisda.in/zeroization-wipe-secrets-compiler-copies/</link><pubDate>Thu, 08 Oct 2026 08:30:00 +0530</pubDate><guid>https://kdpisda.in/zeroization-wipe-secrets-compiler-copies/</guid><description>&lt;p&gt;A pull request that adds &lt;code&gt;secure_zero(&amp;amp;key, sizeof key)&lt;/code&gt; to a crypto function looks like pure upside. Frank Denis&amp;rsquo;s &lt;a href="https://00f.net/2026/10/06/zeroization-1/"&gt;first zeroization post&lt;/a&gt; shows it is not. For a small local value, the wipe can be deleted by the optimizer, can clear bytes that never held the secret, or can make the compiler write a copy of the secret to memory that did not exist before the wipe was added.&lt;/p&gt;
&lt;p&gt;The mechanism is the same each time. A wipe takes an address, and taking an address changes how the compiler lays out the value. Whether the wipe helps depends on where the secret actually lives in the generated code, which you can only see by reading the assembly of the build you ship.&lt;/p&gt;</description></item></channel></rss>