keepassxc/src/proxy
Janek Bevendorff 13eb1c0bbd Improve resilience against memory attacks
To reduce residual fragments of secret data in memory after
deallocation, this patch replaces the global delete operator with a
version that zeros out previously allocated memory. It makes use of
the new C++14 sized deallocation, but provides an unsized fallback
with platform-specific size deductions.

This change is only a minor mitigation and cannot protect against
buffer reallocations by the operating system or non-C++ libraries.
Thus, we still cannot guarantee all memory to be wiped after free.

As a further improvement, this patch uses libgcrypt and libsodium
to write long-lived master key component hashes into a secure
memory area and wipe it afterwards.

The patch also fixes compiler flags not being set properly on macOS.
2019-04-21 09:39:28 -04:00
..
CMakeLists.txt Improve resilience against memory attacks 2019-04-21 09:39:28 -04:00
keepassxc-proxy.cpp Ran make format 2019-03-19 18:56:17 -04:00
NativeMessagingHost.cpp Code quality updates for 2.4.0 (#2709) 2019-02-18 08:26:56 -05:00
NativeMessagingHost.h Code quality updates for 2.4.0 (#2709) 2019-02-18 08:26:56 -05:00