Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Microsoft previews Project Springfield, a cloud-based bug detector (blogs.microsoft.com)
86 points by Qworg on Sept 26, 2016 | hide | past | favorite | 9 comments


Here's the research paper, Automated Whitebox Fuzz Testing by Patrice Godefroid, Michael Levin, and David Molnar:

"Our approach records an actual run of the program under test on a well-formed input, symbolically evaluates the recorded trace, and gathers constraints on inputs capturing how the program uses these. The collected constraints are then negated one by one and solved with a constraint solver, producing new inputs that exercise different control paths in the program. This process is repeated with the help of a code-coverage maximizing heuristic designed to find defects as fast as possible."

https://www.microsoft.com/en-us/research/wp-content/uploads/...


I usually scroll down for appealing infographics before I start reading the post. But all we got here is people posing for their new Linkedin profile pic


Yeah, this was totally the wrong page to link. This seems more appropriate for HN: https://www.microsoft.com/en-us/springfield/


You're 100% right - I didn't know if the actual site was up yet.


From what I could gather from this article, this software is for people who want to make better beer.


And isn't fuzzing the software of the people who make beer a worthy thing? I'd be upset if any l33t haxors interfered with my supply of beer...


If these are their new profile pics, I can only imagine how bad the old ones were.


>> With widely used software such as an operating system or productivity suite, deploying those patches can cost as much as $1 million, the researchers say.

That is part of why so many people dislike Microsoft's attitude. Who cares that it costs 1m to deploy a patch. Corporate customers are going to be spending far more than a million installing that patch. Just think about how many customers are out there who have to test and apply this patch. Fixing a vulnerability prior to release is worth billions of dollars to millions of customers. That should be the math, not how much MS must spend every other Tuesday.


But catching bugs before release solves both problems, no?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: