That's why I think formally verified implementations are so critical, and why Project Everest (formally verified TLS) is so cool: https://project-everest.github.io/
1. does this library provide a way to clear secrets from memory?
2. does it provide means to ensure that the secrets will not be swapped to disk on page fault or copied in memory?
3. does it bignum implementation provide a way to clear the internal buffer?
thank you.
In any case, you should read:
- https://www.auto.tuwien.ac.at/~blieb/AE2017/presentations/ae...
- https://www.auto.tuwien.ac.at/~blieb/AE2017/presentations/Ha...
- https://dwheeler.com/secure-programs/Secure-Programs-HOWTO/p...