logoalt Hacker News

ok123456last Saturday at 7:58 PM1 replyview on HN

This proposal is worse because all the valuable regions of code will be clearly annotated for static analysis, either explicitly via a library/function call, or heuristically using the same boilerplate or fences.


Replies

voodooEntitylast Saturday at 9:03 PM

Makes sense basically creating an easy to point out pattern for static analysis to find everything security related.

As another response pointed out, its also possible that said secret data is still in the register, which no matter what we do to the curr value could exist.

Thanks for pointing it out!

show 1 reply