just now

Solidity Fuzzing & Web3 Testing with a Trail of Bits Security Engineer

Listen to this episode

0:00 / 0:00

Summary

This week's episode features an interview between Patrick Collins and a Web3 Security Engineer at Trail of Bits. They cover:- testing methodologies- fuzzing- static analysisWith Trail of Bits Security Engineer, Troy!Timestamps3:10 - Exploring Smart Contract Testing Methodologies with Trail of Bits5:37 - Testing Strategies for Smart Contracts8:10 - Fuzz Testing and Invariant-Based Testing Explained10:56 - Coverage Guided Fuzzing Explained13:50 - The Benefits of Coverage Guided Fuzzing and the Differences between Echidna, Foundry, & Others16:27 - Using Coverage Guided Fuzzing with Optic and Echidna19:12 - Symbolic execution and coverage-guided fuzzing in Echidna21:57 - Testing Philosophies: Dynamic vs. Static Testing24:24 - Dynamic vs Static Analysis and the trade-offs of each approach27:10 - The Importance of Efficient Testing and Using a Variety of Testing Methods29:57 - The Role of Security Firms and Testing Philosophies32:33 - Balancing Cost and Efficiency in Security Audits35:15 - The Importance of Code Reuse in Building Tools and Languages38:04 - The pitfalls of focusing on language intricacies in programming and the benefits of prioritizing language design and philosophy40:41 - The Need for More Open Source Tools and Communication in the Ethereum Community43:22 - Advice for becoming more security-minded in smart contract coding45:51 - Discussion with Alpha Rush on Testing Compilers and Security Focus Journeys

First published

04/27/2023

Genres

technology business entrepreneurship

Duration

46 minutes

Parent Podcast

Devs Do Something

View Podcast

Share this episode

Similar Episodes

  • Mechs, Devs & Beer #10

    04/16/2013

    Mechs, Devs & Beer #10 by NoGutsNoGalaxy

    Clean
  • Mechs, Devs & Beer #9

    04/16/2013

    Mechs, Devs & Beer #9 by NoGutsNoGalaxy

    Clean
  • Mechs, Devs & Beer #7

    04/16/2013

    Mechs, Devs & Beer #7 by NoGutsNoGalaxy

    Clean
  • Mechs, Devs & Beer #6

    04/16/2013

    Mechs, Devs & Beer #6 by NoGutsNoGalaxy

    Clean

Similar Podcasts

  • Make Do Co.

    08/15/2020

    Make Do Co.

    People of Purpose by Johanna Scott features conversations with people doing meaningful work and living with heart.People of Purpose sits under the website Make Do Co. For more content visit wearemakedo.com.au.The series is produced by Johanna Scott. Introduction provided by Shaun White.

    Clean
  • Crônicas do Fim do Mundo

    08/11/2020

    Caio Salgado

    E se as histórias secretas de pessoas aleatórias fossem reveladas?"Crônicas do Fim do Mundo" é um projeto que constrói narrativas curtas com um toque de suspense noir.Escrito e produzido por Caio Salgado. Leia essas e outras crônicas no Medium, acessando o link: https://goo.gl/tIGy6pComentários, críticas e sugestões: caio@chsalgadofoto.com.br ou pelo Twitter: @chsalgado.

    Clean
  • Selling Your Books Online

    08/11/2020

    Dr. Robert C. Worstell

    Since I've been self-publishing and blogging for over a decade now, it's only right that you should benefit from all the hard knocks, scraped pride, and quiet cussing I've had to do in order to figure this all out.With over a dozen-dozen books published, it's pretty simple now for me to write, edit, and publish books.The next case to crack is getting them to sell better. If you're interested in some extra passive income every month, maybe there is something here for you as well. Join me on this journey...

    Clean
  • CreateCast

    08/15/2020

    CreateCast

    Welcome to CreateCast, the show about people who make good. Your Host Chase K sits down with chefs, actors, musicians, writers, and other incredible people to talk about what they do and why they do it. Head to www.createcastpod.com for more info!

    Clean
  • Soirée with The Sauce

    08/15/2020

    Soirée-Leone

    The podcast formerly known as Permaculture Velocity is now Soirée with The Sauce. The Sauce is all the things we make, do, and share to live the good life.

    Clean
  • CantinhoCast

    08/07/2020

    Grupo Espírita Cantinho de Luz

    Um Cantinho de Papos que IluminamEspaço para ouvirmos palestras, conversas informais, entrevistas e discussões acerca de temas sob a ótica do Espiritismo. Tudo sendo produzido no Grupo Espírita Cantinho de Luz ou por seus amigos.

    Clean
  • #OladeleOlunikePODCASTER

    08/15/2020

    #OladeleOlunikePODCASTER

    Oladele is the multi-award-winning quintessential polymath and lead consultant at Oladele Olunike and Associates who business leaders, corporate and government institutions seek when they need to boost their personal, career and business effectiveness and marketplace competitiveness. As a professional speaker, communication and business etiquette expert/coach, personal, career and business effectiveness consultant and an accomplished master of ceremonies, his time-proven and result-oriented workplace record impart proven hands-on and recreatable solutions. He believes that: "Effectiveness begins with you. What you want to do easily, you must first do diligently." He yearns always to impart, impact but never impress.

    Clean
  • Doug Bost and Adam Bernstein are Grown Ass Men

    08/11/2020

    Adam Bernstein

    Writer Doug Bost and musician Adam Bernstein discuss the things that grown men shouldn’t care about -- but these guys do. What’s on the table? Only fun stuff. Episodes focus on all aspects of the comic book universe, from the warehouse of a professional comic book hoarder to interviews with some of the greatest comics creators alive -- Neal Adams, Klaus Jansen, Chris Claremont, and more. With frequent guests, Doug and Adam also cover movies, music, classic TV, and important topics like, “What musical style do you associate with James T Kirk?” (The answer, of course, is Wagner.) And the kicker: Original music by Adam Bernstein in each episode.

    Clean
  • WIRED's Webmonkey Podcast

    08/15/2020

    WIRED

    Listen in every week as the Wired tech team waxes poetic about Internet news, and behind the scenes look at the tech at WIRED. It may not change your life, but you'll hear our take on a Javascript frameworks, WordPress development, and web performance. Laugh. Cry. Learn. Love. Just tune in. We'll do the rest.

    Clean
  • Feelin' Film

    08/12/2020

    Aaron White and Patrick Hicks

    Welcome to Feelin' Film. Aaron and Patrick embark on a quest to change the tone of film criticism, one movie review at a time. Discussion on main episodes is family friendly and centered around positive takeaways and emotional experience more than technical merit. We believe that all art is worthy of some praise and every movie makes us feel something. On FF+, Aaron reviews new releases and upcoming films - offering spoiler-free thoughts on the things he liked, the things he didn't, and whether he believes a film is worth your time and money. He also interviews filmmakers, hosts trivia and other fun games, and makes an assortment of recommendations from time to time.Tune in and join the conversation.

    Clean
  • Mountain View United Methodist Church

    08/17/2020

    Mountain View United Methodist Church

    As a United Methodist Church in Kingsport, Tennessee, Mountain View is a community that: makes the worship of God central to all that we do, nurtures all in people in Christian fellowship and community, encourages the witness of faith to be shared with others, reaches out to meet the needs of others, challenges each person to be faithful in our prayers, presence, gifts, service and witness, and grows each person in faith through Scripture, Reason, Tradition and Experience.

    Clean
  • Wisdom-Trek ©

    08/15/2020

    H. Guthrie Chamberlain, III

    Do you desire to gain wisdom, make an impact on your world, and create a living legacy? Through the use of positive/encouraging stories, parables, allegories, and analogies we will explore the trails of everyday life in a practical and meaningful manner as we scale towards our summit of life. The purpose of our Wisdom-Trek podcast and journal is to teach you wisdom and discipline, to help you understand the insights of the wise, to teach you to live disciplined and successful lives, to help you do what is right, just, and fair. By obtaining this wisdom then you will be able to create a living legacy for today that will live on and be multiplied through the lives of others.Wisdom-Trek.com is your portal to all things pertaining to the acquisition of wisdom, insight, and knowledge. The Wisdom-Trek platform includes this website along with a daily journal, and a daily podcast on wisdom and creating a living legacy. It is your portal because it is our hope that everyone

    Clean

Episode Description

This week's episode features an interview between Patrick Collins and a Web3 Security Engineer at Trail of Bits. They cover:
- testing methodologies
- fuzzing
- static analysis

With Trail of Bits Security Engineer, Troy!

Timestamps
3:10 - Exploring Smart Contract Testing Methodologies with Trail of Bits
5:37 - Testing Strategies for Smart Contracts
8:10 - Fuzz Testing and Invariant-Based Testing Explained
10:56 - Coverage Guided Fuzzing Explained
13:50 - The Benefits of Coverage Guided Fuzzing and the Differences between Echidna, Foundry, & Others
16:27 - Using Coverage Guided Fuzzing with Optic and Echidna
19:12 - Symbolic execution and coverage-guided fuzzing in Echidna
21:57 - Testing Philosophies: Dynamic vs. Static Testing
24:24 - Dynamic vs Static Analysis and the trade-offs of each approach
27:10 - The Importance of Efficient Testing and Using a Variety of Testing Methods
29:57 - The Role of Security Firms and Testing Philosophies
32:33 - Balancing Cost and Efficiency in Security Audits
35:15 - The Importance of Code Reuse in Building Tools and Languages
38:04 - The pitfalls of focusing on language intricacies in programming and the benefits of prioritizing language design and philosophy
40:41 - The Need for More Open Source Tools and Communication in the Ethereum Community
43:22 - Advice for becoming more security-minded in smart contract coding
45:51 - Discussion with Alpha Rush on Testing Compilers and Security Focus Journeys

Discussion (0)

Be respectful and constructive in your comments

No comments yet

Be the first to share your thoughts about this episode!