4 ms·
Recently I approached a software project with the idea that I'd like to employ a fuzzer later when possible. What I found particularly interesting is that as so
by Systemic33 9y ago
Recently I approached a software project with the idea that I'd like to employ a fuzzer later when possible. What I found particularly interesting is that as soon as I had this idea in my head, my mind would constantly think of the code in a defensive "I-need-to-account-for-any-input" way.
Not just thinking about making the code work in the desired way, but also that any other input is walled of.
I think fuzzers are something that should get more attention, because it doesn't just help find critical bugs, it also changes your mind-set to defensive programming.
- probably_wrong 9y agoThe teachers in my CS Labs would give us assignments that required reading all parameters from standard input. They would then run our code with /dev/random as input. They didn't fail any project for failing this test, but it sure taught us a lesson on checking inputs and failing gracefully.
- amdavidson 9y agoI went to a computer camp as a child and my first project was a number guessing game where the computer would pick a random number and then tell you hotter and colder as you guessed numbers. I passed it to a friend to show off my work, and the first number he entered was "a", crashing the program immediately. Defending against rogue inputs was literally the first thing I ever learned about writing safe code.
- jdmichal 9y agoThat's my favorite software engineering joke: A tester walks into a bar and orders a beer... And orders 2147483648 beers... And orders 0 beers... And orders -1 beers... And orders "banana" beers... EDIT: I just thought, you might actually get a Bananenheizen if you order the last one in Germany...