The Android Fuzzing Pivot That Cut Costs and Found Better Bugs

https://hackernoon.imgix.net/images/UQq3DWa6P8Y8T6f0oxHysFyXvM23-2z03beh.png

When I was the head of Microsoft's Edge security for the US market, we ran into an infrastructure challenge that forced us to completely rethink how we fuzzed Android.

The project we built no longer exists at Microsoft, and the Android-x86 project we relied on is now officially dead and unsupported. However, the architectural pivot we made to get around cloud compute constraints remains a novel approach to Android fuzzing—one that solved a myriad of technical headaches while drastically cutting costs.

Here is a look back at how we bypassed the Android Emulator entirely to find better, real-world bugs.

The Catalyst: Losing Nested Virtualization

Fuzzing has always been a core focus of the Edge security posture. Using our own tooling alongside open-source frameworks, we achieved millions of fuzz hours per month across desktop environments. But doing this at scale for Android always presented unique friction.

In 2022, that friction hit...

Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE

Read more

https://cdn.mos.cms.futurecdn.net/7EpEu8Xo2XadaegiM5zG6U-2000-80.jpg

'It's ok to use AI to help you write, but your posts and comments need to represent your voice and your perspectives': LinkedIn is finally set to crack down on AI slop — and save our collective sanity

* LinkedIn exec reveals plans to cut down on AI slop * Move looks to cut down on inauthentic or unoriginal content and posts * Users will no longer see AI-generated content in their recommendations LinkedIn may soon be a much nicer place to network and follow updates from old colleagues after the