Zeroization can make things worse: how wiping secrets creates more copies
jedisct1 · x · 2026-10-06
Cryptographic engineer Frank DENIS explains why blindly adding zeroization to secrets — a favorite LLM-suggested 'low-hanging fruit' — can do more harm than good.
Key points:
- A classic memset() wipe gets optimized out by the compiler, but a diff shows the compiled output is identical either way: the intermediate value never touched memory and lived only in registers
- 'Fixing' this with volatile byte stores forces secrets into memory, creating copies that wouldn't otherwise exist — and those copies persist after the function returns
- Code snippets and compiled output are verified on Godbolt
Takeaway: secret wiping is a security-sensitive operation; batch-adding memset/volatile wipes without analysis can leave more secret copies behind than the original code.
More from coding & agent
- Cloudflare launches cf, an agent-first CLI to query observability data via the API — dinasaur_404 · 2026-10-06
- celld: Self-Hosted Cloudflare Workers-Style Runtime With a Cell per AI Agent — letandrewcook · 2026-10-06
- 9 Prompt Rules Cut Agent Thinking Up to 29% With Zero Task Loss, Across 664 Runs — PilgrimofHaqq2 · 2026-10-06
- Low Effort Can Burn More Tokens: Qwen3.8-27B-pi Fine-Tunes Coding Agent Effort Ordering — lmoroney · 2026-10-06
- Building a local LLM agent stack on a 128GB Mac Studio: Reddit thread weighs inference layer options — DrainBramage · 2026-10-06
- Yacine's 90-Minute Chat With a1zhang: Why Harnesses Boost LLM Generalization — yacinelearning · 2026-10-06