4 ms·
Libsodium Audit Results
- imaginenore 9y agoNo fuzzing?
- technion 9y agoFuzzing will catch C related bugs - it won't generally detect crypto implementation bugs, which this appears to have focussed on. There's a lot of people who can write a fuzzer in their spare time and I'd be surprised if libsodium had never been a target. Comprehensive crypto audits on the other hand, are a different story. Edit: It does state dynamic analysis was performed for classes of C bugs