TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Fuzzing Ladybird with tools from Google Project Zero

522 pointsby awesomeklingabout 1 year ago

10 comments

classichasclassabout 1 year ago
And thus demonstrated is the value of lots of different implementations of a spec. Already one hole found in the spec in just this article, and I'm sure there will be/were more.
评论 #39726902 未加载
评论 #39730344 未加载
评论 #39731714 未加载
DustinBrettabout 1 year ago
I love that this project keeps showing how possible it is for a small group to make something amazing. This would be very hard to do in a company with stakeholders.
评论 #39727247 未加载
tetris11about 1 year ago
They've implemented SVG? This project is coming along faster than I thought. I watch enraptured
评论 #39726502 未加载
efitzabout 1 year ago
For issue #3, it might also be a good idea to have a maxdepth mechanism in gradients that point to other gradients; this would be a defense in depth control vs some error or limitation in your “have I seen this reference before” logic. I’m not familiar with SVG gradients; maybe there is a reason to have reference chains of these 1000 links long, but I’d bet that if you ever encounter this in the wild then it’s an attack or a fuzzer.
评论 #39731068 未加载
LeFantomeabout 1 year ago
This comment is being left from Ladybird. Hacker News works in Ladybird now. I use Ladybird for the few minutes a day that I surf sites like Hacker News and OSnews.<p>It is slow. It is fragile. But it works. That alone is amazing given how young the project is and how they have written literally everything from scratch.<p>I am really looking forward to Ladybird maturing.
评论 #39749721 未加载
beefnugsabout 1 year ago
Interesting thanks. What bothers me though is that almost all developers do exactly what you see in issue #1: We found it! fix committed done! Nope, you should understand exactly what went wrong: assuming parents must exist... Now search the entire codebase for the same kind of mistakes. Use your creative brain to figure out where else same thing can happen. It will never be in just done place. All modern software is unreliable bug ridden nightmare, mostly because of capitalism constraints yes... but it is possible to do better
aapoalasabout 1 year ago
Will Ladybird make an appearance in Web Engines Hackfest this year?
yafetnabout 1 year ago
A little off topic: what happened to the hacking videos on YouTube? Used to look forward to them but I haven’t seen a new one in a while.
评论 #39727002 未加载
评论 #39727124 未加载
tflolabout 1 year ago
&quot;fuzzing ladybird&quot; is such a delightfully barbaric combination of words
评论 #39726858 未加载
评论 #39727129 未加载
holstaabout 1 year ago
I am secretly hopeful Ladybird can take over the world some day. Don&#x27;t tell anyone.
评论 #39727125 未加载