Show HN: Differential Fuzzing of Cryptographic Libraries
guidovranken.com
guidovranken.com
In a nutshell: This open-source project provides a framework for fuzzing cryptographic libraries. It can find both memory bugs and implementation errors. So far it has found about 35 bugs of varying severity in the stable releases of major cryptographic libraries. The fuzzers run continually on Google's OSS-Fuzz platform which helps detect bugs before they end up in stable releases.
The article describes the technical details of the software. Here you can find a summary of the bugs it has found: https://github.com/guidovranken/cryptofuzz#hall-of-fame
It's a pretty powerful technique at least in problem domains where fully specified behavior is a realistic expectation.
Mutation testing-- where you break the code and confirm that your tests fail-- is also pretty powerful in those same domains.
1) Compare two programs
2) Generate two inputs for one program which should produce the same output
3) generate two inputs for one program where there is a simple relationship between the outputs.
In all cases, it has been a great way of testing, and has shuck out some incredibly subtle bugs I don't think we would have found any other way.
Crypto libs (or any libs) typically can be used in a vast number of ways with completely untrustworthy input.
Some of the modern libraries take a different approach where they deliberately limit the functionality to a few select things that can be implemented easily (thinking nacl, libsodium, boringSSL etc here) and which guide the user towards sensible defaults that work rather than having huge numbers of levers to tweak, only some of which arrive at a secure and supported solution.