220 40355 <2144977.3D1Rvy5359@tjmaciei-mobl1> article
Path: news.gmane.org!.POSTED!not-for-mail
From: Thiago Macieira <thiago@macieira.org>
Newsgroups: gmane.comp.lang.c++.isocpp.proposals
Subject: Re: more security concerns
Date: Sun, 07 Oct 2018 00:30:07 -0700
Lines: 43
Approved: news@gmane.org
Message-ID: <2144977.3D1Rvy5359@tjmaciei-mobl1>
References: <CAFdMc-0NqfbqeOhhH1YiVGxDRVPv7COKNqge3mLu8UE8SgcXNw@mail.gmail.com> <94d79dd7-ba3b-4bf8-91ed-e5dc02b33670@isocpp.org> <1442c15c-6a58-4f3e-83cf-9f5554fb9981@isocpp.org>
Reply-To: std-proposals@isocpp.org
NNTP-Posting-Host: blaine.gmane.org
Mime-Version: 1.0
Content-Type: text/plain; charset="UTF-8"
X-Trace: blaine.gmane.org 1538897288 11056 195.159.176.226 (7 Oct 2018 07:28:08 GMT)
X-Complaints-To: usenet@blaine.gmane.org
NNTP-Posting-Date: Sun, 7 Oct 2018 07:28:08 +0000 (UTC)
To: std-proposals@isocpp.org
Original-X-From: std-proposals+bncBCB4TK757YBRBAXM43OQKGQEFBRYQCQ@isocpp.org Sun Oct 07 09:28:04 2018
Return-path: <std-proposals+bncBCB4TK757YBRBAXM43OQKGQEFBRYQCQ@isocpp.org>
Envelope-to: gclcip-std-proposals@m.gmane.org
Original-Received: from mail-qk1-f197.google.com ([209.85.222.197])
	by blaine.gmane.org with esmtp (Exim 4.84_2)
	(envelope-from <std-proposals+bncBCB4TK757YBRBAXM43OQKGQEFBRYQCQ@isocpp.org>)
	id 1g93Tt-0002hO-Af
	for gclcip-std-proposals@m.gmane.org; Sun, 07 Oct 2018 09:28:01 +0200
Original-Received: by mail-qk1-f197.google.com with SMTP id s123-v6sf7606793qkf.12
        for <gclcip-std-proposals@m.gmane.org>; Sun, 07 Oct 2018 00:30:12 -0700 (PDT)
ARC-Seal: i=2; a=rsa-sha256; t=1538897411; cv=pass;
        d=google.com; s=arc-20160816;
        b=vyT3nxC4NWC34DY7bzRTT9oBVkDhE/Tqop9BdgDBjtl1gk6ncIC5Q5wu2TtqVwXNGH
         7U57dVg23+dO6jLomVBxiEA9cd6ZZmgF+PsZRYZXC4lflA5N39n8uAj8HKiFREYOh39s
         1AdgvkNYI/yuBTPrnJ2NDWdx0pln9n0/KoH1qjyvDV/ym15IQXMgFbGT6GBQU3c05ZL/
         15vYOCYTddiX81tHHS0h2dGRpp6UxKwDu+wdq/2ld4dxsAwqRAnHxY/FJU2UdWh5IRRJ
         fohJ2R0aLCyY/JDsldYTA+GzIEnFEQaRjOn15gvt3EMhuS5OX9HDKvI0//6KwAahkI6l
         BdPQ==
ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816;
        h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post
         :list-id:mailing-list:precedence:reply-to:mime-version:references
         :in-reply-to:message-id:date:subject:to:from:dkim-signature;
        bh=F/ne7Q954ats08PgAtAaFG1udKthxjY30cAbXj8I/z4=;
        b=UucLNMKV6BZeDkM5bh61CvPdaom5KGRsCHVW9K9VL/YG+39fYklGfbshJY19zOhg0E
         XK8W3nvTaqY7Aq82C9912HlppN82zNCPn1h/4SpuDOTZNcOWY6aAGjAJOXJzkk0xBfUM
         xaahzlOl5Y4av/ryymImhNEhf1m0zLjY5NC711/p0v2uPPas7dTarID4lx41yJZUk1OQ
         334wTCDpJWxrzhJvk9wT/S+7IKNxP0x0aOXXhG2kbPtPRsJnZ+niIwoevJAjto1Aq8e/
         Obhrzo0pEaW13xDstuW/nlJc4518KO/TFIR6bXUC/B8cbxbuknFCPLuScK+fVFMptm5y
         bwqQ==
ARC-Authentication-Results: i=2; mx.google.com;
       spf=pass (google.com: domain of thiago@macieira.org designates 209.222.10.136 as permitted sender) smtp.mailfrom=thiago@macieira.org
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=isocpp-org.20150623.gappssmtp.com; s=20150623;
        h=from:to:subject:date:message-id:in-reply-to:references:mime-version
         :x-original-sender:x-original-authentication-results:reply-to
         :precedence:mailing-list:list-id:list-post:list-help:list-archive
         :list-subscribe:list-unsubscribe;
        bh=F/ne7Q954ats08PgAtAaFG1udKthxjY30cAbXj8I/z4=;
        b=ntCakfEz8Xr16HD0peMf9SErff/n3OpWpLizIcxMvmiXpNmWtEN7vYwuCR3UwU9kPp
         QG+BEaberPgBZ4XTgt34Su17cLPet4n3yAwo0K5F+uxWaMiFh9fYi5DHcD19fJ1QnfAv
         Zc0MKXA1GjMR4w4pUvJoJWUIprHVV5j5/1aizoCS9bnhI2UIMDdCwPFfLg3IkDClmRpT
         FxMvs4NndWLuObzMyVfEEntrSw06XZLCup3CicyaWtYbKKotpxlqXgYClTjLy428h9/5
         P9lywjSfiL/tLpNtUic4xNQqxHz6J65CEEIbm3eqOLBWeFD1dIRYQ7/BJOzl4IyXrqfT
         f3+Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=1e100.net; s=20161025;
        h=x-gm-message-state:from:to:subject:date:message-id:in-reply-to
         :references:mime-version:x-original-sender
         :x-original-authentication-results:reply-to:precedence:mailing-list
         :list-id:x-spam-checked-in-group:list-post:list-help:list-archive
         :list-subscribe:list-unsubscribe;
        bh=F/ne7Q954ats08PgAtAaFG1udKthxjY30cAbXj8I/z4=;
        b=Mv5FttiZsE2aDa7Yl6AQF3/vUs+M+mTcZHc5RwASLgkb+mgAnaGJ5dgMOiUphSI3Ya
         bUriBoCk57QDKMfX9/kVR3v5L/3//5eeinlun1LEFxIaaz/gMeSKrDIjWg/xZBzMiMXl
         TTr2AFjeHaWj7PFlRnbG3ZSDe6M5vgeVe+/cRnkLudreSI71hruUmlda5TumtsOy+WH8
         KcFFfi9Elk++lZQpZK1RDX6ocPDPBmELyItwn17VXbcQvNH5QVxx/B2Rfihzw6MnHV9G
         6ekWOQvPaZQoV3QhmAIecruNVZvFPTiUZ9PrbHKD0UjgLLas8DqotMqBBS8S0otbbNwP
         klvQ==
X-Gm-Message-State: ABuFfohT3F7rhqytQNcR3BYwc9vf9TeVbWU7pUHRp8/gjiPKEHc1hGIn
	9g75jpHpOGSK+5V0JbJ+wDF41Q==
X-Google-Smtp-Source: ACcGV60Na/dnavw5PjSec1lLbMOxa5uDko+7k7Isfq7znwOZPXGZg0HF9TpHdvtOSUCyDPr/8KyBuQ==
X-Received: by 2002:a05:6214:1047:: with SMTP id l7mr13232549qvr.27.1538897411590;
        Sun, 07 Oct 2018 00:30:11 -0700 (PDT)
X-BeenThere: std-proposals@isocpp.org
Original-Received: by 2002:a37:2a48:: with SMTP id q69-v6ls4781184qkh.11.gmail; Sun, 07
 Oct 2018 00:30:10 -0700 (PDT)
X-Received: by 2002:a37:3642:: with SMTP id d63-v6mr14152995qka.306.1538897410421;
        Sun, 07 Oct 2018 00:30:10 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1538897410; cv=none;
        d=google.com; s=arc-20160816;
        b=uZjRuLOpnWFORa1OCftFGmzkgv0RHgC20bBvX5u/+iUDpNgxuhSD67b163aAej89w+
         8dIr2OlU2/Zt5ahKfag4wwMxMH9I3jspOoNSo3EaZCNSY9gF5aGLMt4K17LiXcrcSauY
         8GUJOu4z4W5xYixjagptdLATOO9eSrVozwpoJIgznqTBnPJqRojLZ+ntBfNA7jTWwk5D
         OfNDznKfL/VTwIKt41AqHc4mrP3taFtiUP3thIOxu0NxmxYP62es+R/sRiNkKL9yqmD2
         Va3JdzQc5CvQPRYpi6qrU4pt8rUHTkIW0J0Z+uz8W//wCexy29PltIYAaAbxmZb4YTvc
         45EA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816;
        h=content-transfer-encoding:mime-version:references:in-reply-to
         :message-id:date:subject:to:from;
        bh=HqwiyMPNqPu25FRTSwOYdTP/hQhXkEgk+Zn1aBbhufI=;
        b=WdBb2l2jWwqucmLaVy+OhyscuDqaCoGisPfWQ2m29FfskBNBPoBf0BLbtFAMdGUuSQ
         nbFuhGLWYAxyMGXu7H/5vlhKyVLzZSus6+XBxMeWJM8OBX1fBtJkRlUxsZzlGFrqUSaS
         FpTXhDNDkx4w261VhneifxfiIsibGNFvsbVNwaq0/JkcW8EyFMS6YThhOde+QlVZWSiv
         GLY0OoeKRE3r0yru//UGQdipf18p+tHOlRQoYU8lsCWuXRV0ePuzcDCmq8SKaRyhXHpD
         5t5lhFEPpsMO1XijyblyCEfxR2Q/49GSkjQADWEAtF4nD9ENtH1CeHJyP4Oz3Mo5HEJk
         jC2g==
ARC-Authentication-Results: i=1; mx.google.com;
       spf=pass (google.com: domain of thiago@macieira.org designates 209.222.10.136 as permitted sender) smtp.mailfrom=thiago@macieira.org
Original-Received: from smtp.macieira.info (arvernien.macieira.info. [209.222.10.136])
        by mx.google.com with ESMTPS id e67-v6si1941436qkd.399.2018.10.07.00.30.09
        for <std-proposals@isocpp.org>
        (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128);
        Sun, 07 Oct 2018 00:30:09 -0700 (PDT)
Received-SPF: pass (google.com: domain of thiago@macieira.org designates 209.222.10.136 as permitted sender) client-ip=209.222.10.136;
Original-Received: from tjmaciei-mobl1.localnet (unknown [IPv6:2601:1c0:4500:d000:f1f7:a58d:7beb:9a94])
	by smtp.macieira.info (Postfix) with ESMTPSA id D49DF19FE3
	for <std-proposals@isocpp.org>; Sun,  7 Oct 2018 00:30:08 -0700 (PDT)
In-Reply-To: <1442c15c-6a58-4f3e-83cf-9f5554fb9981@isocpp.org>
X-Original-Sender: thiago@macieira.org
X-Original-Authentication-Results: mx.google.com;       spf=pass (google.com:
 domain of thiago@macieira.org designates 209.222.10.136 as permitted sender) smtp.mailfrom=thiago@macieira.org
Precedence: list
Mailing-list: list std-proposals@isocpp.org; contact std-proposals+owners@isocpp.org
List-ID: <std-proposals.isocpp.org>
X-Spam-Checked-In-Group: std-proposals@isocpp.org
X-Google-Group-Id: 399137483710
List-Post: <https://groups.google.com/a/isocpp.org/group/std-proposals/post>, <mailto:std-proposals@isocpp.org>
List-Help: <https://support.google.com/a/isocpp.org/bin/topic.py?topic=25838>, <mailto:std-proposals+help@isocpp.org>
List-Archive: <https://groups.google.com/a/isocpp.org/group/std-proposals/>
List-Subscribe: <https://groups.google.com/a/isocpp.org/group/std-proposals/subscribe>,
 <mailto:std-proposals+subscribe@isocpp.org>
List-Unsubscribe: <mailto:googlegroups-manage+399137483710+unsubscribe@googlegroups.com>,
 <https://groups.google.com/a/isocpp.org/group/std-proposals/subscribe>
Xref: news.gmane.org gmane.comp.lang.c++.isocpp.proposals:40355
Archived-At: <http://permalink.gmane.org/gmane.comp.lang.c++.isocpp.proposals/40355>

On Friday, 28 September 2018 15:22:25 PDT Arthur O'Dwyer wrote:
> This certainly seems to make sure that the write reaches L1 cache, but do
> you know whether the write is guaranteed to have reached and overwritten
> any copies of the data that might remain in L2 and main memory?
> What about the swap partition? Are you worried that a copy of the secret
> may have been swapped out to disk?  (Reductio ad absurdum: What if it was
> swapped out to removable media that has since been ejected?)
>
> Before you can start talking meaningfully about preventing the compiler
> from eliminating your dead "=0" statements, you need to have a mental model
> that explains what good those "=0" statements are supposed to do in the
> first place.

I agree, this needs some further thinking to define the problem. Just tackling 
the problem of eliminated stores is insufficient, since the same data could be 
found elsewhere, like in registers. That's why the -mzero-caller-saved-regs 
patch exists for GCC
  https://github.com/clearlinux-pkgs/gcc/blob/master/zero-regs-gcc8.patch

A function attribute is the best way to solve the problem of local variables: 
just tell the compiler to clear ALL variables, both in stack and in registers. 
Or maybe provide hints to the compiler of which variables are hazardous and 
must be cleared, so it won't spend CPU cycles clearing a large but innocuous 
buffer.

Similarly for memory-allocated blocks, as the compilers do understand free() 
and that any stores prior to that are dead. But I also don't think this is 
that big a security issue, as secure code must have used mlock() to prevent 
swapping out, so it will have to use munlock() after it cleared the memory, 
meaning the compiler cannot conclude it's a dead store.

-- 
Thiago Macieira - thiago (AT) macieira.info - thiago (AT) kde.org
   Software Architect - Intel Open Source Technology Center



-- 
You received this message because you are subscribed to the Google Groups "ISO C++ Standard - Future Proposals" group.
To unsubscribe from this group and stop receiving emails from it, send an email to std-proposals+unsubscribe@isocpp.org.
To post to this group, send email to std-proposals@isocpp.org.
To view this discussion on the web visit https://groups.google.com/a/isocpp.org/d/msgid/std-proposals/2144977.3D1Rvy5359%40tjmaciei-mobl1.

.
