M
Mark C
I know a string is immutable, but is there any trick or any other way
to destroy a string
Thanks
www.quiznetonline.com
to destroy a string
Thanks
www.quiznetonline.com
Follow along with the video below to see how to install our site as a web app on your home screen.
Note: This feature may not be available in some browsers.
I know a string is immutable, but is there any trick or any other way
to destroy a string
Thanks
www.quiznetonline.com
Not so much destroy the string as overwrite it:I know a string is immutable, but is there any trick or any other way
to destroy a string
Thanks
www.quiznetonline.com
rossum said:Not so much destroy the string as overwrite it:I know a string is immutable, but is there any trick or any other way
to destroy a string
Thanks
www.quiznetonline.com
/// <summary>
/// Overwrites a string in-situ. Useful for removing
/// evidence of keys, passwords etc.
/// </summary>
/// <param name="text">The string to overwrite.</param>
public static unsafe void OverwriteString(string text) {
const char overwriteChar = 'X';
fixed (char* cp = text) {
for (int i = 0; i < text.Length; ++i) {
cp = overwriteChar;
} // end for
} // end fixed
} // end OverwriteString()
The string is still on the heap, but the sensitive information it
contained is no longer there.

rossum said:Not so much destroy the string as overwrite it:I know a string is immutable, but is there any trick or any other way
to destroy a string
Thanks
www.quiznetonline.com
/// <summary>
/// Overwrites a string in-situ. Useful for removing
/// evidence of keys, passwords etc.
/// </summary>
/// <param name="text">The string to overwrite.</param>
public static unsafe void OverwriteString(string text) {
const char overwriteChar = 'X';
fixed (char* cp = text) {
for (int i = 0; i < text.Length; ++i) {
cp = overwriteChar;
} // end for
} // end fixed
} // end OverwriteString()
The string is still on the heap, but the sensitive information it
contained is no longer there.
The current location of the buffer is wiped, but if the string survived a
generation, the garbage collector has made copies
rossum said:rossum said:On 3 Jan 2007 06:11:00 -0800, "Mark C" <[email protected]>
wrote:
I know a string is immutable, but is there any trick or any other way
to destroy a string
Thanks
www.quiznetonline.com
Not so much destroy the string as overwrite it:
/// <summary>
/// Overwrites a string in-situ. Useful for removing
/// evidence of keys, passwords etc.
/// </summary>
/// <param name="text">The string to overwrite.</param>
public static unsafe void OverwriteString(string text) {
const char overwriteChar = 'X';
fixed (char* cp = text) {
for (int i = 0; i < text.Length; ++i) {
cp = overwriteChar;
} // end for
} // end fixed
} // end OverwriteString()
The string is still on the heap, but the sensitive information it
contained is no longer there.
The current location of the buffer is wiped, but if the string survived a
generation, the garbage collector has made copies
There may also be a copy on disk in swapspace, on automatic backups
and written on a post-it under the keyboard. It is not possible to be
completely secure, all that is possible is to make the attacker's job
more difficult.
rossum
rossum said:On 3 Jan 2007 06:11:00 -0800, "Mark C" <[email protected]>
wrote:
I know a string is immutable, but is there any trick or any other way
to destroy a string
Thanks
www.quiznetonline.com
Not so much destroy the string as overwrite it:
/// <summary>
/// Overwrites a string in-situ. Useful for removing
/// evidence of keys, passwords etc.
/// </summary>
/// <param name="text">The string to overwrite.</param>
public static unsafe void OverwriteString(string text) {
const char overwriteChar = 'X';
fixed (char* cp = text) {
for (int i = 0; i < text.Length; ++i) {
cp = overwriteChar;
} // end for
} // end fixed
} // end OverwriteString()
The string is still on the heap, but the sensitive information it
contained is no longer there.
The current location of the buffer is wiped, but if the string survived a
generation, the garbage collector has made copies
There may also be a copy on disk in swapspace, on automatic backups
and written on a post-it under the keyboard. It is not possible to be
completely secure, all that is possible is to make the attacker's job
more difficult.
rossum
That's why the SecureString was invented, it get's allocated in a non swappable fixed
portion of the process heap, it's contents get's encrypted and it' doesn't need the GC to
get wiped-out.
Willy.
Secondly, I understand that SecureString is either uncertain, or not
present, in .NET 3, so I am reluctant to use something that I am just
going to have to rewrite when I come to upgrade.
Ben said:The current location of the buffer is wiped, but if the string survived a
generation, the garbage collector has made copies![]()
rossum said:rossum said:On 3 Jan 2007 06:11:00 -0800, "Mark C" <[email protected]>
wrote:
I know a string is immutable, but is there any trick or any other way
to destroy a string
Thanks
www.quiznetonline.com
Not so much destroy the string as overwrite it:
/// <summary>
/// Overwrites a string in-situ. Useful for removing
/// evidence of keys, passwords etc.
/// </summary>
/// <param name="text">The string to overwrite.</param>
public static unsafe void OverwriteString(string text) {
const char overwriteChar = 'X';
fixed (char* cp = text) {
for (int i = 0; i < text.Length; ++i) {
cp = overwriteChar;
} // end for
} // end fixed
} // end OverwriteString()
The string is still on the heap, but the sensitive information it
contained is no longer there.
The current location of the buffer is wiped, but if the string survived a
generation, the garbage collector has made copies
There may also be a copy on disk in swapspace, on automatic backups
and written on a post-it under the keyboard. It is not possible to be
completely secure, all that is possible is to make the attacker's job
more difficult.
rossum
That's why the SecureString was invented, it get's allocated in a non swappable fixed
portion of the process heap, it's contents get's encrypted and it' doesn't need the GC to
get wiped-out.
Willy.
The problems I have with SecureString are firstly that I cannot use it
directly, very few .NET methods accept SecureString as a parameter. I
have to take my sensitive data out of the secure string and transfer
it to something insecure, such as a string or a byte array, before I
can do anything useful with it. For example, none of the various
GetBytes() methods takes a SecureString as a parameter, I have to
write my own function to do this. I don't want to have to rewrite all
the .NET methods that can take a string as a parameter just so I can
have a SecureString as a parameter.
Secondly, I understand that SecureString is either uncertain, or not
present, in .NET 3, so I am reluctant to use something that I am just
going to have to rewrite when I come to upgrade.
Thanks for the info. Scratch my second reason.rossum wrote:
Everything in .NET 2.0 is in .NET 3.0 as .NET 3.0 is just the addition
of a bunch of new libraries, effectively. (WPF etc.)
Want to reply to this thread or ask your own question?
You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.