On Sat, May 09, 2009 at 12:44:27PM -0400, Perry E. Metzger wrote:
 > By that token, it would be of use for NetBSD to port over the encrypted
 > swap features other OSes have (it should be essentially no performance
 > hit), 

Writing even an encrypted copy of a passphrase to disk is still a
hazard compared to not writing it at all. Programs that deal with such
things should lock themselves in memory. :-/

 > and I think it would also be nice if NetBSD could zeroize or
 > randomize RAM on voluntary shutdowns.

That seems like a good idea.

-- 
David A. Holland
dholl...@netbsd.org

Reply via email to