A good hygiene when processing secrets is to wipe them after use.

And projects receives countless PRs about adding calls to zeroization functions for anything that looks like a secret.

This is a low-hanging fruit, something LLMs love to report, and it feels theoretically useful. But unfortunately, things are a little bit more complicated. Blindly zeroing secrets can do more harm than good.

Turns out that adding a wipe for a secret can leave more copies of a secret than the original code. Copies that wouldn’t have existed without it, and that are still there after it returns.

Code snippets and their compiled output can be verified in this Godbolt example.