Announcing OSS-Fuzz: Continuous Fuzzing for Open Source Software
testing.googleblog.com
testing.googleblog.com
Edit: Thanks for the downvote! Every time I consider sending in a pile of automated bug-reports to a project where I'm not already part of the community, I look at them myself first. If that's bad, I'm happy to be bad.
This project is awesome and incredibly valuable but what alternatives are there to making the libraries it checks more secure besides rewriting them in another language? When languages exist where buffer overflows and use-after-free are essentially impossible it's a bit depressing that we have to rely on fuzzing unless fuzzing can find these kinds of bugs with high reliability?
I'm not sure what you mean by rewriting a library.
For example, if a library is written in Ruby, fuzzing might not be suitable. you shouldn't rewrite it in C, so that you can fuzz it. (I thinkI misunderstand your point here. Please correct me.)
If we want to discover vulnerabilities in Ruby, we should fuzz the Ruby VM directly. We shouldn't fuzz a Ruby library.
Let's see - Firefox and/or the Tor browser? I imagine Google wouldn't be too happy about doing free security research for Firefox, but it seems to fit the bill quite well for the goals and mission of the Core Infrastructure Initiative organization.
It often feels like it, yes. Could it be that you don't see it because you are already using Chrome?
I use Edge on my Windows gaming machine (for minimal maintenance, I install drivers, Steam, and that's pretty much it) and configured Edge to clean everything including cookies on exit, like a permanent stateless Private Mode available for the occasional search.
End result: many Google apps (Search, Maps, YouTube, and probably many others) constantly display huge "Get Chrome" banners, that end up not only painful for the user experience, but contain plain lies: "A more modern, faster browser" says one, whereas Edge/Firefox/Chrome are now objectively in the same ballpark.
This constant soliciting across vast swaths of the web by one dominant actor controlling the end-to-end experience is abusive.
IIRC they still pay Mozilla for making Google the default homepage
True.
> "is there anything else they've done?"
Nah, and frankly that's just irrational in-my-head ranting, their behavior is entirely expected rational behavior. Google is a data junkie which critically all-caps NEEDS as much data as possible about us, in order to machine-learn our lives from head to toe so that it can make money helping companies sell us more stuff.
Of course Apple isn't bothering us to use Safari when browsing apple.com, it doesn't care as long as you buy Macs. Of course Microsoft neither, it doesn't care as long as you use their platforms.
But Google is different, it needs your data to operate, and so it will do whatever it takes to get its data fix, including bullying.
</rant>
EDIT+OFFTOPIC: cool article on your blog about AFL, thanks for sharing it :)
> True.
Not true. Mozilla switched to Yahoo a few years back; Google doesn't give them any money. And it's not the default homepage, it's the default search engine (the default homepage always starts out `about:home`).
And running firefox with a fresh new profile, I confirm all search sources (awesome bar, in-chrome search box, about:home in-content search box) default to querying Google, not Yahoo.
Is it new to be back to Google? Or maybe it's specific to Nightly builds? (53.0a1 2016-12-01) -- EDIT no, same behavior under 50.0.2 stable. And it's not the OS either, I tried Ubuntu and Windows --. Any idea why, then?
https://blog.mozilla.org/blog/2014/11/19/promoting-choice-an...
Nit: s/North America/USA/, I guess, as I live in Canada and get Google.
[1] https://en.wikipedia.org/wiki/Internet_Explorer_10 says "On January 12, 2016, support ended for IE10 on Windows operating systems capable of running Internet Explorer 11, due to new support policies dictating that only the newest version of IE available for a supported version of Windows will be supported. IE10 will only be supported on Windows Server 2012 and Windows Embedded 8 Standard."
Also the interest is very often shared, because a whole pile of libraries are used by both browsers: freetype, libjpeg-turbo, libpng, giflib, expat, webrtc, opus, ...
Google's biggest revenue stream is ads. It has many others, but that's the big one. Ads are seen by people who use Google search, and who browse many ad-supported websites. Google also has a lot of users of its services, e.g., gmail, who have accounts. Some also entrust valuable data to Google.
Google therefore has a great deal of incentive to make sure that: (a) Nobody messes with the ability of general users to browse the Internet safely (preserving ad revenue); and (b) It's very hard to compromise users computers and gain access to their Google/gmail/whatever accounts (reducing support costs and keeping users happy), or destroy their data, or exfiltrate it. Even if the compromise was the user's computer, it's still a very bad experience.
Project zero is a pretty good example of this incentive structure in action. (such as fuzzing for windows font bugs: https://googleprojectzero.blogspot.com/2016/07/a-year-of-win... ).
With fuzzing itself, as DannyBee alluded to below, one of the leads of a lot of this infrastructure, Kostya Serebryany, is also personally passionate about seeing it be taken up to make the software of the world better. I've seen this in action - he convinced me to use libFuzzer to improve TensorFlow's robustness, and mentioned that he was doing so in part so I'd take that experience back to Carnegie Mellon and spread the word. :) (and it worked - https://github.com/tensorflow/tensorflow/commit/7231d01fcb2c... for example).
But as Google definitely does do security testing on competitors' products such as Windows, it definitely goes to show that Google would be more than happy to test for security flaws in Firefox. And regardless of Google's motives, finding security flaws does, in the end, make a more secure Internet for everybody.
(You'll note the explicit discussion in there about the deadline:
"Chromium issues should be treated the same as any others. So there's a 90-day deadline (which was not exceeded in this case), ...
Same disclosure warning to the Chrome team was in this bug: https://bugs.chromium.org/p/project-zero/issues/detail?id=51...
And project zero explicitly warned the Android team about the 90 day disclosure policy in the one bug report I checked:
https://code.google.com/p/android/issues/detail?id=182510
Edited to add:
Here's one where they disclosed prior to Android fixing the bug: https://bugs.chromium.org/p/project-zero/issues/detail?id=86...
with the note "deadline exceeded". Unfortunately, the link to the Android bug is still protected, so we can't learn why AOSP hasn't fixed it yet.