Skip to main content

Zeroize

Trait Zeroize 

Source
pub trait Zeroize {
    // Required method
    fn zeroize(&mut self);
}
Expand description

Types whose in-memory representation can be securely erased.

Required Methods§

Source

fn zeroize(&mut self)

Overwrite self with zeroes using non-elidable volatile writes.

Dyn Compatibility§

This trait is dyn compatible.

In older versions of Rust, dyn compatibility was called "object safety".

Implementations on Foreign Types§

Source§

impl Zeroize for [u8]

Source§

fn zeroize(&mut self)

Eight bytes per volatile store, then the tail a byte at a time.

A volatile store of a [u8; 8] is exactly as non-elidable as eight volatile byte stores, and is one store rather than eight. That matters because wipes are on hot paths: every SHA-2 state wipes its buffered block when dropped, and HMAC drops two per tag, so byte-at-a-time wiping was a measurable share of a short HMAC. [u8; 8] has the alignment of u8, so the pointer cast needs nothing a byte slice does not already guarantee, and no temporary larger than eight bytes is involved – which a single store of the whole array would need.

Source§

impl Zeroize for [u32]

Source§

fn zeroize(&mut self)

Source§

impl Zeroize for [u64]

Source§

fn zeroize(&mut self)

Source§

impl<const N: usize> Zeroize for [u8; N]

Source§

fn zeroize(&mut self)

Source§

impl<const N: usize> Zeroize for [u32; N]

Source§

fn zeroize(&mut self)

Source§

impl<const N: usize> Zeroize for [u64; N]

Source§

fn zeroize(&mut self)

Implementors§