Skip to content

[TRBFV - 6.4] Secret and Noise Material Is Not Zeroized #116

Description

@0xjei

Sensitive values not automatically zeroized on drop include:

  • Shamir share matrices stored as Array2
  • Collected secret-share matrices
  • Collected smudging-share matrices
  • The ordinary Poly returned by aggregate_collected_shares
  • Smudging coefficients returned as Vec
  • Example-held sk_poly_sum and es_poly_sum
    Poly implements Zeroize, but ordinary Poly values are not automatically erased unless wrapped in Zeroizing or explicitly zeroized. SecretKey has stronger drop handling.
    Smudging noise is also sensitive: disclosure can remove the masking from a recorded decryption transcript.
    Verdict: Valid Low hardening finding. Use zeroizing wrappers or dedicated secret/noise types. Arrays and arbitrary-precision integers may require explicit zeroization support or controlled representations.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions