Giter VIP home page Giter VIP logo

Comments (13)

claucece avatar claucece commented on June 14, 2024 1

Very interesting. I can start playing with this a little.

from circl.

kriskwiatkowski avatar kriskwiatkowski commented on June 14, 2024 1

oh, while I'm here. I was recently informed by the author via linkedin that this exists and uses CIRCL
https://github.com/kuking/go-pqsw

thought you may want to know

from circl.

guidovranken avatar guidovranken commented on June 14, 2024 1

Hey @henrydcase @claucece , I'm the maintainer of Cryptofuzz. I'm still improving it every day. It now supports elliptic curve operations and has been effective at finding EC bugs (see full bug list here ). PQ crypto not yet but I'm planning on implementing that. Have you gotten around to work with Cryptofuzz to test circl? Feel free to reach out to me at [email protected] to discuss these plans in depth.

from circl.

claucece avatar claucece commented on June 14, 2024

Oh, wow, interesting @henrydcase .. check it out @bwesterb : https://github.com/kuking/go-pqsw

from circl.

armfazh avatar armfazh commented on June 14, 2024

Fuzzing is something we want to include in CIRCL, we are open for discussion.
thanks for the pointer @guidovranken

from circl.

guidovranken avatar guidovranken commented on June 14, 2024

I now have a circl module for Cryptofuzz https://github.com/guidovranken/cryptofuzz/tree/master/modules/circl
It found one bug so far #312

I can install it on OSS-Fuzz if you want @armfazh ?

from circl.

armfazh avatar armfazh commented on June 14, 2024

I now have a circl module for Cryptofuzz https://github.com/guidovranken/cryptofuzz/tree/master/modules/circl It found one bug so far #312

Thanks for writing the module.

I can install it on OSS-Fuzz if you want @armfazh ?

What does this implies and what it is required to be included? (sorry, not so familiar with the internals of the project).

from circl.

guidovranken avatar guidovranken commented on June 14, 2024

Basically:

  • Requires participants to have a Google account. I need a list of e-mail addresses (linked to a Google account) of maintainers. Note: these will be public
  • You will receive an e-mail notification when a bug is found, and when it is detected as fixed
  • There is an expectation that bugs found by OSS-Fuzz will be fixed by the maintainers (you)
  • Bugs found remain private for 90 days, then they are automatically publicly disclosed whether they are fixed or not
  • "To be accepted to OSS-Fuzz, an open-source project must have a significant user base and/or be critical to the global IT infrastructure."
  • Usage of OSS-Fuzz is free of charge
  • I will collect the $1,000 integration reward

More information: https://google.github.io/oss-fuzz/

from circl.

chris-wood avatar chris-wood commented on June 14, 2024

Requires participants to have a Google account. I need a list of e-mail addresses (linked to a Google account) of maintainers. Note: these will be public

@guidovranken can you please clarify who the "participants" are here?

from circl.

guidovranken avatar guidovranken commented on June 14, 2024

People who receive the bug reports, typically the maintainers of the software being fuzzed, in this case the circl maintainers.

from circl.

armfazh avatar armfazh commented on June 14, 2024

@guidovranken just reached at this address https://guidovranken.com/contact/, please confirm you have received my email.

from circl.

guidovranken avatar guidovranken commented on June 14, 2024

Yes I did, thanks, I will reply in a minute.

from circl.

armfazh avatar armfazh commented on June 14, 2024

Tracking integration at: google/oss-fuzz#7262

from circl.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.