The way you worded these responses makes me feel like a bad person if I reply :P I think I'd fall under "I already fuzz when I feel like I need to".
-
-
-
Why would feel bad?
But also, if you do fuzz you don't have to respond 
- Još 4 druga odgovora
Novi razgovor -
-
-
We use go-fuzz but still have a lot of unanswered questions around fuzzing functions with multiple inputs, multiple targets etc. We want to do more but documentation lacking.https://github.com/dosco/super-graph …
-
So you would say that [advanced] documentation is missing? Thanks for the feedback.
- Još 2 druga odgovora
Novi razgovor -
-
-
I don't know how, and I can barely work up the strength to write sufficient unit tests.
Most of the data I process is xml or json, and if it is malformed, I expect the marshaller/unmarshaller to predictably fail. Fuzzing feels important for the stdlib and low-level libraries. -
What happens if you correctly parse the json with the stdlib but the unmarshalled data is something your logic does not expect and your program ends up in a corrupted state?
- Još 2 druga odgovora
Novi razgovor -
-
-
"Does not apply to my project" It is hard to fuzz a fuzzer with other fuzzers. It is also hard to fuzz runtime instrumentation. To be clear, it is hard even to setup Travis for a fuzzer for simple correctness tests :( Damn fuzzers.
-
They ruined fuzzing.
Kraj razgovora
Novi razgovor -
-
-
Is fuzzing really that critical?
-
It is one of the very few ways to find a set of bugs. If you have a parser, third party libraries, code that takes untrusted inputs or commands it is critical that you fuzz at least those.
Kraj razgovora
Novi razgovor -
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.
with parallel programming and security. (he/him)