Most people are now aware that @trailofbits conducted a security review of the Bitcoin Cash client on behalf of @BitcoinSVNode. While we cannot release our report in its entirety yet, I wanted to share a few details of what we found…https://twitter.com/JimmyWinMedia/status/1101668023335833601 …
Here's what we said in the report about oss-fuzz. There are downsides to using oss-fuzz and I think it makes more sense to run your own fuzz tests in this particular case. I don't think use of oss-fuzz is planned.pic.twitter.com/Hya9NDvXMF
-
-
Thanks. Running fuzz tests on someone's own infra is a common misconception among those who haven't tried fuzzing at scale. Though it's easier now with ClusterFuzz being open sourced.
-
I don't understand what you're saying. Do you not think it's possible for people other than Google to operate high performance fuzzing systems?
- 1 more reply
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.