Live data from Hacker News

Viewing profile — metzmanj

metzmanj

HN member
Joined
Thu, Feb 07, 2019, 3:51 PM UTC
HN karma
125
Public activity
25 items

About metzmanj

No profile information was provided.

Recent public activity

  1. comment
    Comment #42183867

    Very interesting, this will really change the dynamics of bug bounty and webapp security more broadly

  2. comment
    Comment #39905769

    This is interesting, but do you think this would have aroused enough suspicion to find the backdoor (after every Ubuntu user was owned by it)? I don't see why this is the case. It …

  3. comment
    Comment #39898865

    I work on oss-fuzz. I don't think it's plausible OSS-Fuzz could have found this. The backdoor required a build configuration that was not used in OSS-Fuzz. I'm guessing "Jia Tan" k…

  4. comment
    Comment #39868391

    That's what people are saying though I haven't had the chance to look into this myself. Fuzzing isn't really the best tool for catching bugs the maintainer intentionally inserted t…

  5. comment
    Comment #39867772

    >Woha, is this legit or some sort of scam on Google in some way?: I work on OSS-Fuzz. As far as I can tell, the author's PRs do not compromise OSS-Fuzz in any way. OSS-Fuzz doesn't…

  6. comment
    Comment #34629818

    No projects yet, but I bet we'll have some by next week.

  7. story
  8. comment
  9. story
  10. story
  11. comment
    Comment #21815405

    I don't think we have plans to build this for now. I find it a really cool idea, but for now, running fuzzers natively on Google Cloud with ClusterFuzz ( https://github.com/google/…

  12. comment
    Comment #21815335

    Right I think WASM offers some nice advantages over native for distributed fuzzing. It's also worth pointing out that Mozilla made a (non-WASM) distributed fuzzing project, virgo: …

  13. comment
    Comment #21815310

    I haven't done a comprehensive study of this but in general I find that fuzzing programs in different environments (e.g. CPU architectures, OSes) tends to find some bugs that won't…

  14. comment
    Comment #19108999

    It uses AFL. ClusterFuzz is infrastructure for running fuzzers, so we use it to run AFL, libFuzzer, and other domain specific fuzzers we've written. Using it to run AFL gives us a …

  15. comment
    Comment #19108778

    The other possibility for completely on-prem use right now is running it using the dev server: https://google.github.io/clusterfuzz/getting-started/local-i...

  16. comment
  17. comment
    Comment #19108690

    Thanks Tanin!

  18. comment
    Comment #19108417

    Great post Guido! Guido's bignum fuzzer which tests the correctness of math operations in crypto libraries is one of the most interesting fuzzers we run on ClusterFuzz.

  19. comment
    Comment #19107712

    We would like to support this use case. For now, you can actually do the fuzzing on prem while communicating with app engine. We do this for our OS X bots since GCE doesn't offer O…

  20. comment
    Comment #19107256

    There are tools for fuzzing go: https://github.com/dvyukov/go-fuzz But I think the kinds of bugs found by fuzzing aren't generally security issues in go (I don't know much about go…

  21. comment
    Comment #19107225

    +1 I can speak a little bit about what motivated us. We saw from OSS-Fuzz ( https://github.com/google/oss-fuzz ) that this sort of thing could be widely useful and wanted non-open …

  22. comment
    Comment #19107048

    I don't think so. But solidity was recently added to OSS-Fuzz: https://github.com/google/oss-fuzz/tree/master/projects/soli...

  23. comment
    Comment #19107015

    >So before I go too much further, would it be possible to use this for web apps or unity games? Web apps, almost certainly no. ClusterFuzz (and fuzzing generally) is most useful fo…

  24. comment
    Comment #19106901

    btw, ClusterFuzz, the infrastructure behind OSS-Fuzz was open sourced today: https://news.ycombinator.com/item?id=19106771

  25. comment
    Comment #19106876

    I work on this. Happy to answer questions if people have any.