MystenLabs / MystenLabs/fastcrypto

Improve how we use Zeroize and ZeroizeOnDrop

Open
#620 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Rust
Stars
311
Forks
173
Avg merge
22h 47m
Merged PRs (30d)
21

Description

  • Consistent usage
  • Document drawbacks
  • Remove as_ref of secret keys

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating the repository's uses of Zeroize, ZeroizeOnDrop, and as_ref on secret keys. Review the existing usage and document the drawbacks before deciding what consistent usage means; done should include the agreed cleanup, documented drawbacks, and removal of the targeted secret-key as_ref calls.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
cryptography
Issue type
Refactor
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.