This app displays a form with a textbox where the user is supposed to enter a password used to decrypt a document.
I have code that looks like this:
string password = passwordTextBox.Text;
...
DecryptDocument(password);
But I was told that, technically speaking, this is a security flaw, because the data that represents the password might remain in memory even after the application is closed.
I tried to use the System.Security.SecureString class but now I'm dealing with pointers to CoTaskMem which seems to make the problem worse:
SecureString password = new SecureString();
foreach(char i in passwordTextBox.Text.ToCharArray())
password.AppendChar(i);
IntPtr ptr = Marshal.SecureStringToCoTaskMemAnsi(password);
int length = password.Length;
byte[] bytes = new byte[length];
Marshal.Copy(ptr, bytes, 0, length);
DecryptDocument(Encoding.Default.GetString(bytes));
Marshal.FreeCoTaskMem(ptr);
As you can see, it doesn't look like I'm making the application safer, since sooner or later I will have to take the input (passwordTextBox.Text) and convert it into a string that I can pass to the DecryptDocument() function.
Is there a way to solve this problem or should I just deal with this security vulnerability?