logoalt Hacker News

plagiaristtoday at 1:23 PM1 replyview on HN

I thought we were all supposed to be encrypting our swap. Or is there something better an app can do about this?


Replies

hackingonemptytoday at 1:39 PM

We're all supposed to be encrypting our storage too but this tool advertises that it encrypts your secrets before they hit the disk.

All of the supported operating systems have memory locking functions that prevent swapping out but they are not used in this tool, AFAIK. Also, they are intended to lock things like secret keys that are small and not displayed to the user in a GUI. You can lock the whole process though but a big web browser process is going to significantly up the amount of unswappable memory. Stuff sent to the windowing system may get swapped out too.