3 ms·
Very interesting. I need to read up on smart contracts to better understand your post but the first question that comes to mind is: if you use virtual machines
by drvdevd 10y ago
Very interesting. I need to read up on smart contracts to better understand your post but the first question that comes to mind is: if you use virtual machines to run the code and test the exploits, against which platform(s) would those VMs be built? Would the idea be to standardize on one virtual infrastructure (and therefore class of exploits) or would you allow just about anything?
I ask because I can imagine some (or many) PoCs would require hardware and software of a different platform than usual e.g. qemu+x86_64 vs ARM vs MIPS. So, I guess I see a somewhat complex infrastructure problem that this would need to have solved.
Perhaps the VM for running the exploit and exploited code in question should be wrapped around the binary that the vendor distributes, with an intention that it be e.g. ELF on x64 Linux 4.x, statically compiled?
- Uptrenda 10y agoTrue. What I can imagine is that when the smart contract is being setup the vendor chooses a list of templates for the platforms / environments used to setup the virtual machines. If they're running their own software on their own infrastructure they can always provide a scale image that reflects what they intend to run in production. (Thanks for the feedback, by the way. It's hard to stand out for anything these days.)