Re: [PATCH] Revert "conf: clean up memory containing secrets before freeing"

2022-09-07 Thread Ján Tomko
On a Wednesday in 2022, Peter Krempa wrote: Adding supposedly secure cleanup for secrets in anything related to the XML parser is pointless because there are multiple other un-sanitized copies of the full XML and the XML parser state at the very least. Similarly in case RPC was used to transport

Re: [PATCH] Revert "conf: clean up memory containing secrets before freeing"

2022-09-07 Thread Martin Kletzander
On Wed, Sep 07, 2022 at 01:13:23PM +0200, Peter Krempa wrote: Adding supposedly secure cleanup for secrets in anything related to the XML parser is pointless because there are multiple other un-sanitized copies of the full XML and the XML parser state at the very least. Similarly in case RPC was

Re: [PATCH] Revert "conf: clean up memory containing secrets before freeing"

2022-09-07 Thread Pavel Hrdina
On Wed, Sep 07, 2022 at 01:13:23PM +0200, Peter Krempa wrote: > Adding supposedly secure cleanup for secrets in anything related to the > XML parser is pointless because there are multiple other un-sanitized > copies of the full XML and the XML parser state at the very least. > > Similarly in case

[PATCH] Revert "conf: clean up memory containing secrets before freeing"

2022-09-07 Thread Peter Krempa
Adding supposedly secure cleanup for secrets in anything related to the XML parser is pointless because there are multiple other un-sanitized copies of the full XML and the XML parser state at the very least. Similarly in case RPC was used to transport the XML the RPC buffers are not sanitized. A