Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Wrapping the command line should be a little bit safer from a security perspective, since a memory exfiltration bug won't transfer across processes. Just don't use the shell between the wrapper and the command.


Is this really the case? I recall that proper library support is slow-coming, not because of security model concerns, but because "doing it right" takes more time / money that there is in GPG development at the moment.

EDIT: For example, I believe that it would require rewriting a lot of code, and that means said code would need to be audited to make sure no security bugs were introduced. It's "easier" to just wrap the current command-line tools because they are a known quantity.


I'm sure you're right, but because of this "laziness" we get a slight security boost at the cost of a slight performance loss.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: