Subject: Re: [PATCH] wincng: Added explicit memory overwrite feature to WinCNG backend

Re: [PATCH] wincng: Added explicit memory overwrite feature to WinCNG backend

From: Daniel Stenberg <daniel_at_haxx.se>
Date: Sun, 18 May 2014 19:02:09 +0200 (CEST)

On Sun, 18 May 2014, Marc Hoersken wrote:

> attached you will find a new patch that has been rebased to the current
> master.

I think the configure help text and commit message could use some improvement.

This option only disables the random fill of the free data, it still
overwrites memory - only with zeros instead. So it doesn't disable memory
overwrite at all.

A question though: is there really anyone who suggests that it is safer to
fill the data with random data rather than just zeros? I just can't see the
point with doing such a slow operation and waste random seed on this.

-- 
  / daniel.haxx.se
_______________________________________________
libssh2-devel http://cool.haxx.se/cgi-bin/mailman/listinfo/libssh2-devel
Received on 2014-05-18