> Making sure the password is not in memory any longer then it should
> provides that KDE will not be the weakest link in the security chain.

But KDE isn't a weak link here, unless it's choosing to write passwords to 
files without the user asking for it.

Regardless of what KDE does, it's up to the OS to clear the RAM, it's up to 
the OS to make sure that other users can't read your RAM, it's up to the 
OS to keep swap secure, it's up to the OS to enforce permissions.

The OS can keep it secure, or the OS can make sure it's insecure.  Playing 
around with const char *s won't actually protect users from an attacker.

