Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity
    • Development

    BlackBerry, Mozilla Team Up to Develop Free Web Security Testing Tool

    Written by

    Brian Prince
    Published August 1, 2013
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Security experts at BlackBerry and Mozilla have teamed up to develop a testing tool aimed at discovering and fixing software vulnerabilities in Web browsers.

      The two companies are working together to develop “Peach,” a free testing tool, to improve Web browsers security. Peach was created by Michael Eddington of Déjà vu Security in 2004 and has been under active development since.

      According to Adrian Stone, director of security response and threat analysis at BlackBerry, the idea for Mozilla and BlackBerry to work together on Peach was born from talks between employees of the companies at the CanSecWest Applied Security Conference in Vancouver. Peach is a fuzzing tool, and works by utilizing fault injection to identify security risks before they impact users.

      “One of the main benefits of fuzzing is the automatic fault injection, which is kind of by nature what you are doing–manipulating data and sending tons of different variations into a set of code,” Michael Coates, Mozilla’s director of security assurance, told eWEEK.

      “And your goal there is to figure out how did that code fail? How did the developer miss something when he gets a particular type of crazy malformed data? And the benefit of using fuzzing is you are trying many different iterations…that would never be possible by hand, so you flush out these rather esoteric issues that you couldn’t have discovered” through other forms of security testing.

      The plan, Stone and Coates explained, is to add new file formats for fuzzing HTML5 features as well as to build out the framework so that it scales more readily. Already, Mozilla has used Peach to perform fuzz testing against HTML5 features, including multimedia APIs like WebGL and most recently protocols used in WebRTC. According to BlackBerry, the collaboration with Mozilla fits into its existing security processes and infrastructure, as the company regularly uses third-party fuzzers as well as its own proprietary tools for security resting.

      Within the next year, the companies plan to release more information about what they did, how they used the tool and the lessons learned along the way.

      “Security is a challenging area and when you get similar minds thinking about these problems to work together, it’s a huge benefit,” Coates said.

      Separate from the announcement of their partnership with BlackBerry, Mozilla also discussed plans for Minion, an open-source security project aimed at application developers and security professionals. Minion is being developed by the Security Automation team at Mozilla to enable “integration and adoption of automated security testing,” and has been under development for the past year, Mozilla noted in a blog post.

      “The platform allows any team to set up the basic requirements to perform automated scanning and testing of Websites and services by providing sensible defaults for plug-ins that enable scanning of many types of Web applications and services,” according to the blog.

      The goal is to make it easier for Web developers to do security testing of their Web applications, Coates said.

      “What we’ve found is with Web application security testing, in most situations there is a need for a security professional to be involved to either run the tool and analyze the results [or] do the testing themselves, and that doesn’t scale,” he said.

      “Not all Web developers are security experts. What we’ve done is we’re working to build a tool that gives developers something that is easy to use, where they understand the output, and they get results that they can use—that are actionable.”

      Brian Prince
      Brian Prince

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.