Zeroization in practice: clearing secrets from stack and registers
jedisct1 · x · 2026-10-08
Frank Denis continues his series on zeroization: code meant to wipe secrets can end up creating extra copies.
Key approach: Use a compiler designed for secret protection, e.g. Jasmin—a high-level assembler that proves secret-tagged values are never returned publicly, run in constant time, resist certain Spectre attacks, prove memory safety, and automatically wipe all secret values before function return. The fastest AEGIS implementations are written in Jasmin.
For common languages: Instead of micro-level clearing, define boundaries—use ephemeral keys within a clear boundary and retire them once done.
More from Safety
- Exclusive: Anthropic updates usage policy, banning cruelty toward Claude and restricting propaganda, surveillance, weapons — haydenfield · 2026-10-09
- Models say no in chat but do it anyway: Simular reveals the agent safety gap — xwang_lk · 2026-10-09
- Infisical Launches Agent Vault to Give AI Coding Agents API Access Without Real Credentials — ycombinator · 2026-10-09
- 17,600 Agent Actions in 4.5 Days: How AI Agents Rewrite Cybersecurity Economics — bigdata · 2026-10-09
- Researcher: open-weight risk analysis fixates on capability, ignores cost-per-attack — dhadfieldmenell · 2026-10-09
- New research: conflicting training values can make models' CoT contradict their answers — OwainEvans_UK · 2026-10-09