Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • Home
  • SEARCH
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 3306844
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 17, 20262026-05-17T21:20:12+00:00 2026-05-17T21:20:12+00:00

I know there is the SecureString class, but for most scenarios I don’t think

  • 0

I know there is the SecureString class, but for most scenarios I don’t think it’s really useful.

For example, let’s say I have a client/server system. The server doesn’t need an application made by me, it could be even SQL Server without integrated authentication. When the user enters his password on a form in the client app, it’s stored in clear text in memory, so, while I can use a SecureString to read it, I can’t really see the point on doing so. Sure, it can reduce the attack surface, but not much… Even if I did, when the user hits ‘OK’, a plain text string must be generated, even if I just need to compute a hash from it.

So, is there anyway to avoid the password strings to float around until the GC decides to reclaim the memory? Even then, would the memory get erased before it’s used again?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-17T21:20:13+00:00Added an answer on May 17, 2026 at 9:20 pm

    SecureString is a great idea whose time has not quite arrived. It is most useful in the following scenario:

    1. Your presentation layer password box grabs each keypress individually and stuffs them into a SecureString one at a time. The class exposes several mutating methods specifically designed to facilitate this. For example, WPF supports this (via the PasswordBox.SecurePassword control property).
    2. Your authentication API accepts passwords of type SecureString natively.

    If either of these is untrue, then you are pretty much wasting your time, since at some point in the code path you will be forced to unpack the SecureString into a String.

    The safest way to authenticate a user is always to avoid handling username/password credentials altogether. You could use Windows authentication, InfoCards, OpenID, etc instead.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I know there is a registry key indicating the install directory, but I don't
I know there are a lot of positive things mod-rewrite accomplishes. But are there
I know there have been a few threads on this before, but I have
I know there are HTML entities for 1/2, 1/4, and 3/4, but are there
I know there exists a command like jQuery.noConflict. But for this it first registers
I know there's a simple UIViewAnimationOptionTransitionFlipFromLeft and way to implement that, but how do
I know there are quite a few line count tools around. Is there something
I know there is a way to add a IE control, how do you
I know there is a function somewhere that will accept a client rect and
I know there's some JAVA_OPTS to set to remotely debug a Java program. What

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.