From: Chad Perrin Date: 2010-02-20T11:16:23+09:00 Subject: Re: using secure memory --LZvS9be/3tNcYl/X Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Sat, Feb 20, 2010 at 09:45:47AM +0900, Ryan Davis wrote: >=20 > AFAIK, secured virtual memory is a system-wide needs-a-reboot type of > thing. So other than good doco, I think the answer defaults to "no". It > is the route I'd go. The software will be as clean as it can be, > easy(ier) to security audit, etc. All with the caveat, that you need to > run it in a secured environment. Given the original requirements, that > just seems common sense/expected to begin with. I know that one does not need to reboot a computer to have a guarantee that data in memory will not be swapped out. For an example, check the way GnuPG works on BSD Unix and Linux systems if the SUID bit is set, where it will start with administrative privileges to secure memory against swapping to disk then drop administrative privileges to run as the current user. That way, passwords, private keys, and cleartext data that is being encrypted or decrypted will not be swapped to disk where it could be harvested later by a malicious security cracker more easily than it could from RAM. Of course, GnuPG is not written in Ruby, which is why I'm not looking at GnuPG source code for hints on how to do something similar in Ruby. --=20 Chad Perrin [ original content licensed OWL: http://owl.apotheon.org ] --LZvS9be/3tNcYl/X Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.14 (FreeBSD) iEYEARECAAYFAkt/Q+EACgkQ9mn/Pj01uKXcIACeNgP1uknlafXHH8bOzmyHfTRX axcAnAzgLznLtbF+RZQ6N4QX8TDNUebF =JwLO -----END PGP SIGNATURE----- --LZvS9be/3tNcYl/X--