Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

David Steckler

@entiat@mastodon.gruezi.net
mastodon 4.7.3
  • Open on mastodon.gruezi.net

Software engineer and startup founder in environmental geospatial science, outdoors enthusiast, cyclist, mountain biker, endurance horse rider, dogs are awesome

0 Followers
0 Following
2 Posts
Joined November 05, 2022
Open post
David Steckler @entiat@mastodon.gruezi.net
· 46mo ago
Replying to
@epixoip@infosec.exchange @noahtheduke@indieweb.social @sc00bz@infosec.exchange Re: secret scrubbing, prevention of swapping to disk, etc. in gc languages: This can sometimes be accomplished by calling directly down into OS mem mgmt functions, often handled by standard libraries. One example: C#/dotnet has a SecureString class. On Windows, SecureString.Clear() calls the Win32 API SecureZeroMemory() *I have no information on whether this type of thing is actually done in the case of Bitwarden, cross-platform disclaimers apply, YMMV, etc.
1
2
0
0
Open post
David Steckler @entiat@mastodon.gruezi.net
· 46mo ago
Replying to
@epixoip@infosec.exchange @noahtheduke@indieweb.social @sc00bz@infosec.exchange Glancing through bitwarden source, looks like it uses Rust functions to call client OS apis, inc cred management. I see no evidence it is doing anything to either zero memory that held plain text passwords, nor calling the necessary functions to prevent swapping of memory (inc passwords) to disk. In fact it looks like it is lobbing plain text passwords back up to the typescript/electron layer. Ouch. Would be interesting to learn how #1password handles this.
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 10:02:02 UTC