Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
World desk4 min

Constant-Time Comparison and Secure Erasure in C

Use a documented constant-time equality API for secrets and a platform-supported explicit-erasure function to keep the compiler from discarding wipe writes.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For secret equality checks in C, use a cryptographic library function documented for constant-time comparison at the required length—not ordinary memcmp. To erase a password or key, use an explicit-erasure API documented by your target platform; a final ordinary memset can be optimized away when the cleared object is never used again.

Compare secret values with an equality API

memcmp is designed to compare byte sequences and can stop at the first differing byte. When the input contains a secret—such as an authentication tag or key—that behavior can make execution time depend on how much of the input matches. Choose a library function whose documentation promises content-independent timing for the comparison you need.

As an Amazon Associate I earn from qualifying purchases.

These guarantees are about the compared contents for a given length, not identical wall-clock timing under every scheduler, processor, cache state, or application context. The length and surrounding control flow can also disclose information if they depend on secret data. Keep the length independent of the secret where possible, and avoid adding secret-dependent branches around the comparison.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Function Documented timing and purpose Result and availability
sodium_memcmp Libsodium documents constant-time equality comparison for inputs of the same length. See Libsodium Helpers. Returns 0 if equal and -1 otherwise. It does not provide lexicographic ordering.
CRYPTO_memcmp OpenSSL documents runtime that depends on len but not on the contents of the memory regions. See OpenSSL documentation. Returns 0 if equal and nonzero otherwise. Unequal inputs have no meaningful ordering contract.
timingsafe_bcmp OpenBSD documents content-independent running time for equality testing. OpenBSD extension; use only where the target environment provides and documents it.
timingsafe_memcmp OpenBSD documents content-independent running time and lexicographic comparison. OpenBSD extension. Its ordering behavior makes it distinct from equality-only APIs.

Pick the API your target library supports and follow its declared length and return-value contract. In particular, do not treat an equality-only constant-time function as a drop-in replacement when your program needs lexicographic ordering. Libsodium specifically advises using a constant-time comparison for secret data such as keys and authentication tags; see its helper documentation.

Why an ordinary memset may disappear

A call such as memset(secret, 0, size) looks like it clears memory, but the compiler can remove it if the object is dead afterward—meaning no later operation in the program can observe the cleared bytes. In that case, the write has no effect on the program’s abstract behavior. A 2015 GCC mailing-list explanation describes the compiler’s rationale: it is entitled to delete a final memset when the object is dead after the call. See the GCC discussion.

Use an explicit-erasure function provided by the platform

Check the official documentation and headers for the C library or operating system you actually target. GNU libc documents explicit_bzero and memset_explicit; their writes are retained even when the compiler can determine that no correct program path will read them. Other environments may offer APIs such as memset_s or Windows SecureZeroMemory. Names, declarations, and availability vary, so verify support rather than assuming an API is portable.

The guarantee is deliberately narrow. GNU libc says of explicit_bzero: “The only optimization that explicit_bzero disables is removal of ‘unnecessary’ writes to memory.” See GNU libc’s erasure documentation. The function preserves its designated writes against dead-store removal; it does not disable all optimization or establish that every copy of the secret has been removed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Use the target platform’s documented explicit-erasure API, with the correct buffer and length.
  • Do not silently fall back to ordinary memset if the explicit API is unavailable.
  • Do not assume a hand-written volatile loop is a universally reliable substitute; CERT secure-coding guidance cautions against that assumption.
  • If the security requirement depends on the exact generated implementation, inspect generated code as part of your own project’s validation.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What explicit erasure cannot promise

An explicit wipe of one buffer does not necessarily clear other copies. A secret may also have been placed in a register, a compiler scratch area, a stack temporary, or another buffer. GNU libc notes that register-held values are beyond what stack clearing can reach. Treat explicit erasure as protection against one specific failure—the compiler discarding the requested writes—not proof that all traces of a secret are gone.

For robust handling, minimize copies and the time secrets remain in memory, use established cryptographic libraries, and consider the whole program and platform rather than relying on one wipe call. The appropriate measures depend on how the secret is created, copied, and used.

Best Value

Practical decision checklist

  1. For equality: identify the cryptographic library available on the target, then use its documented constant-time equality function for a fixed, appropriate length.
  2. For ordering: use an API that explicitly documents lexicographic behavior; equality-only functions do not provide it.
  3. For erasure: check the target’s official headers and documentation for an explicit-erasure function, then use that function rather than relying on a final ordinary memset.
  4. For validation: if correctness depends on generated code, inspect what the project’s compiler emits under its actual build settings and revalidate when the compiler or target changes.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.