/plushcap/analysis/sonar/juliet-c-benchmark-and-the-securestring-case

Juliet C# Benchmark and the SecureString case

What's this blog post about?

In 2023, Sonar's teams worked on improving their SAST benchmarks coverage, including Juliet C# 1.3 from the National Institute of Standards and Technology of the USA. The SecureString test case in Juliet C# showcases an issue where sensitive data is written unprotected in an unsafe location. Microsoft discourages using SecureStrings due to various security vulnerabilities. However, when properly used, they can add some additional security to an application. The idea of tracking sensitive data usage inside a program could represent a nice addition to Sonar's engines.

Company
Sonar

Date published
Feb. 1, 2024

Author(s)
Gaƫtan Ferry

Word count
1413

Hacker News points
None found.

Language
English


By Matt Makai. 2021-2024.