【 #Togetter 注目のまとめ #RSSfeed 】
藤井七段、AMDのCPUに言及
https://togetter.com/li/1293954
A common bug is to leave sensitive mem uncleared and reuse memory (e.g. via #malloc’s cache) without proper initialisation, leading to secret leakage. The purpose of freezero() and recallocarray() is to protect against that threat. Big threat to the application is the application.
Sensitive data? memset(p, 0, sz); free(p); does not do want you think it does. The compiler is allowed to optimise the memset away. Use freezero(p, sz). For large allocations #OpenBSD just unmaps the pages, avoiding the clearing and still making the memory inaccessible.
#openbsd's #malloc stores meta-data separated from the memory returned to the caller, making it harder to use heap overflows to achieve code injection and execution. See e.g. http://www.mathyvanhoef.com/2013/02/understanding-heap-exploiting-heap.html … and references. Having malloc meta-data near program data is dangerous!