Assuming we’re talking about Scala and not C.
Assuming we’re talking about Scala and not C.
https://www.theverge.com/2018/5/3/17316684/twitter-password-...
Introducing a separate type for passwords doesn’t solve this issue.
Whether it's a password or an "unparsed client data" structure or whatever.
I find this exciting from a problem-solving point of view, because for one, this is potentially a hard, ground-shifting problem. And on the other hand, languages like scala, haskell or rust have the tools to make this kind of requirements simple. There's an interesting time coming.
And in a language with deconstructors, you can remove the secret from memory after it has been used. This in turn reduces the window of vulnerability against memory disclosure attacks, especially in shared virtualized environments.