Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

More on the vulnerability from cryptographer Matthew Green:

http://blog.cryptographyengineering.com/2014/04/attack-of-we...



I am curious about which static code analysis tools pick up this problem. Could it have been found automatically by Coverity, for example?


We tested most of the major ones at work on the faulty code, and only PC-Lint caught the issue.


Wow -- that's scary.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: