# Poll: Do you recognize the term "Fuzz Testing", and are you a Software Developer

**URL:** https://boards.straightdope.com/t/poll-do-you-recognize-the-term-fuzz-testing-and-are-you-a-software-developer/997369
**Category:** In My Humble Opinion
**Created:** [February 9, 2024, 10:43pm UTC](https://boards.straightdope.com/t/poll-do-you-recognize-the-term-fuzz-testing-and-are-you-a-software-developer/997369 "2024-02-09T22:43:12Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![Typo\_Knig](https://avatars.discourse-cdn.com/v4/letter/t/cdc98d/32.png) [@Typo\_Knig](https://boards.straightdope.com/u/Typo_Knig)
#### Post date: [February 9, 2024, 10:43pm UTC](https://boards.straightdope.com/t/poll-do-you-recognize-the-term-fuzz-testing-and-are-you-a-software-developer/997369/1 "2024-02-09T22:43:12Z")

</div>

I was talking with a software developer today, and I brought up Fuzz Testing. He’d never heard of it. I thought it was a well-known term. A friend who’s a developer didn’t recognize it either. I guess it’s not commonly known, but can you give me the Straight Dope? Poll:

_Poll ([view on site](https://boards.straightdope.com/t/poll-do-you-recognize-the-term-fuzz-testing-and-are-you-a-software-developer/997369/1))_

---

<div class="post-metadata">

### Author: ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)
#### Post date: [February 9, 2024, 11:01pm UTC](https://boards.straightdope.com/t/poll-do-you-recognize-the-term-fuzz-testing-and-are-you-a-software-developer/997369/2 "2024-02-09T23:01:26Z")

</div>

Hugely obsolete terminology but instantly recognizable 2005 BS terminology

---

<div class="post-metadata">

### Author: ![Cervaise](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cervaise/32/16693_2.png) [@Cervaise](https://boards.straightdope.com/u/Cervaise)
#### Post date: [February 9, 2024, 11:19pm UTC](https://boards.straightdope.com/t/poll-do-you-recognize-the-term-fuzz-testing-and-are-you-a-software-developer/997369/3 "2024-02-09T23:19:32Z")

</div>

I’m not a developer but I’m a longtime technical business analyst and part-time tester. I didn’t recognize the term but after googling for a definition I certainly know the method, just not by that name.

---

<div class="post-metadata">

### Author: ![leahcim](https://avatars.discourse-cdn.com/v4/letter/l/b4bc9f/32.png) [@leahcim](https://boards.straightdope.com/u/leahcim)
#### Post date: [February 10, 2024, 1:02am UTC](https://boards.straightdope.com/t/poll-do-you-recognize-the-term-fuzz-testing-and-are-you-a-software-developer/997369/4 "2024-02-10T01:02:12Z")

</div>

Am a SWE, know the term, don’t use it super often, but have it [available](https://github.com/google/fuzztest) when needed.

---

<div class="post-metadata">

### Author: ![BigT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bigt/32/12044_2.png) [@BigT](https://boards.straightdope.com/u/BigT)
#### Post date: [February 10, 2024, 1:56am UTC](https://boards.straightdope.com/t/poll-do-you-recognize-the-term-fuzz-testing-and-are-you-a-software-developer/997369/5 "2024-02-10T01:56:55Z")

</div>

I also didn’t know the term. But I do know about deliberately trying to break things to test for bugs.

I’m not in the field myself, but I do watch videos and read articles on such stuff. And the above is usually what they call it. Sometimes, they even just call it “bug testing,” with the method being clear from context.

---

<div class="post-metadata">

### Author: ![Dr.Strangelove](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dr.strangelove/32/6613_2.png) [@Dr.Strangelove](https://boards.straightdope.com/u/Dr.Strangelove)
#### Post date: [February 10, 2024, 2:22am UTC](https://boards.straightdope.com/t/poll-do-you-recognize-the-term-fuzz-testing-and-are-you-a-software-developer/997369/6 "2024-02-10T02:22:33Z")

</div>

> [@BigT](#):
>
> But I do know about deliberately trying to break things to test for bugs.

Fuzz testing is a subset of that. The idea is that you can expose bugs not just manually, but by sending random garbage as input to the code. That takes much less manual labor, and in principle you can fully automate the process of detecting when malformed inputs break things. The longer you let it run, the more bugs it finds.

In practice, there’s some hand-holding, because you might not explore the space of malformed inputs very efficiently without some domain knowledge. Say you’re trying to break a JPEG decoder–you might not catch many errors by inputting purely random files. But fuzzing specific parts, like random width/height values, data lengths, and so on, is likely to catch bugs faster.

It’s not a replacement for manual testing, but can be a good adjunct. And if you don’t do it, hackers will (if it’s a potential security vulnerability).

---

<div class="post-metadata">

### Author: ![griffin1977](https://avatars.discourse-cdn.com/v4/letter/g/977dab/32.png) [@griffin1977](https://boards.straightdope.com/u/griffin1977)
#### Post date: [February 10, 2024, 2:31am UTC](https://boards.straightdope.com/t/poll-do-you-recognize-the-term-fuzz-testing-and-are-you-a-software-developer/997369/7 "2024-02-10T02:31:31Z")

</div>

I only know of it from this project:

> **[GitHub - google/graphicsfuzz: A testing framework for automatically finding...](https://github.com/google/graphicsfuzz)**
>
> A testing framework for automatically finding and simplifying bugs in graphics shader compilers. - GitHub - google/graphicsfuzz: A testing framework for automatically finding and simplifying bugs i...

---

<div class="post-metadata">

### Author: ![CaveMike](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cavemike/32/16379_2.png) [@CaveMike](https://boards.straightdope.com/u/CaveMike)
#### Post date: [February 10, 2024, 7:23am UTC](https://boards.straightdope.com/t/poll-do-you-recognize-the-term-fuzz-testing-and-are-you-a-software-developer/997369/8 "2024-02-10T07:23:07Z")

</div>

Android has a tool called Monkey Test that ‘tests’ an app by pressing and swiping the touchscreen randomly to look for crashes.

---

<div class="post-metadata">

### Author: ![enipla](https://avatars.discourse-cdn.com/v4/letter/e/54ee81/32.png) [@enipla](https://boards.straightdope.com/u/enipla)
#### Post date: [February 10, 2024, 2:30pm UTC](https://boards.straightdope.com/t/poll-do-you-recognize-the-term-fuzz-testing-and-are-you-a-software-developer/997369/9 "2024-02-10T14:30:32Z")

</div>

There used to be, or is a term called Fuzzy Creep/Tolerance in GIS

- _1. [spatial analysis] The distance within which coordinates of nearby features are adjusted to coincide with each other when topology is being constructed or polygon overlay is performed. Nodes and vertices within the fuzzy tolerance are merged into a single coordinate location. Fuzzy tolerance is a very small distance, usually from 1/1,000,000 to 1/10,000 times the width of the coverage extent, and is generally used to correct inexact intersections._

Never been a problem. At least for me.

---

<div class="post-metadata">

### Author: ![leahcim](https://avatars.discourse-cdn.com/v4/letter/l/b4bc9f/32.png) [@leahcim](https://boards.straightdope.com/u/leahcim)
#### Post date: [February 10, 2024, 4:04pm UTC](https://boards.straightdope.com/t/poll-do-you-recognize-the-term-fuzz-testing-and-are-you-a-software-developer/997369/10 "2024-02-10T16:04:27Z")

</div>

> [@CaveMike](#):
>
> Android has a tool called Monkey Test that ‘tests’ an app by pressing and swiping the touchscreen randomly to look for crashes.

I feel like there are two kinds of testing here:

- “Chaos Monkey” type testing, where you’re generating random noise and making sure nothing crashes/leaks, but the test cases are mostly expected not to “work” in sense of doing anything useful.
- “Property” type testing, where you are constructing real test cases that might actually show up in production, and the randomness ensures you are covering a good sample of those test cases, instead of just trying a few like you would in a unit test.

One thing I’ve seen in a couple of frameworks of the latter type is that if the framework finds an error case, it will try to find a simpler error case for easier debugging.

---

<div class="post-metadata">

### Author: ![Balance](https://avatars.discourse-cdn.com/v4/letter/b/ccd318/32.png) [@Balance](https://boards.straightdope.com/u/Balance)
#### Post date: [February 10, 2024, 5:18pm UTC](https://boards.straightdope.com/t/poll-do-you-recognize-the-term-fuzz-testing-and-are-you-a-software-developer/997369/11 "2024-02-10T17:18:31Z")

</div>

I’ve never heard it called by that term, but I’ve certainly done it. I’ve run servers completely dry of entropy throwing random garbage at cellular network nodes.

---

<div class="post-metadata">

### Author: ![TriPolar](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/tripolar/32/3008_2.png) [@TriPolar](https://boards.straightdope.com/u/TriPolar)
#### Post date: [February 10, 2024, 5:36pm UTC](https://boards.straightdope.com/t/poll-do-you-recognize-the-term-fuzz-testing-and-are-you-a-software-developer/997369/12 "2024-02-10T17:36:14Z")

</div>

Same here. I created heritable classes to provide random test data for high and low level application testing. My recollection is there was more support for unit testing at the time, which was mostly implemented the wrong way by having developers write the unit tests for their own code in an isolated environment so it would reveal nothing and allow problems to propagate through future development.

---

<div class="post-metadata">

### Author: ![What\_Exit](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/what_exit/32/10652_2.png) [@What\_Exit](https://boards.straightdope.com/u/What_Exit)
#### Post date: [February 10, 2024, 5:42pm UTC](https://boards.straightdope.com/t/poll-do-you-recognize-the-term-fuzz-testing-and-are-you-a-software-developer/997369/13 "2024-02-10T17:42:12Z")

</div>

I retired a few years ago and never heard of it.  
I was a Business oriented Programmer/Analyst.

---

<div class="post-metadata">

### Author: ![Chronos](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chronos/32/134_2.png) [@Chronos](https://boards.straightdope.com/u/Chronos)
#### Post date: [February 10, 2024, 6:05pm UTC](https://boards.straightdope.com/t/poll-do-you-recognize-the-term-fuzz-testing-and-are-you-a-software-developer/997369/14 "2024-02-10T18:05:05Z")

</div>

> [@Dr.Strangelove](#):
>
> and in principle you can fully automate the process of detecting when malformed inputs break things.

Wouldn’t automating that process be just as hard as writing the original program bug-free to begin with?

---

<div class="post-metadata">

### Author: ![What\_Exit](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/what_exit/32/10652_2.png) [@What\_Exit](https://boards.straightdope.com/u/What_Exit)
#### Post date: [February 10, 2024, 6:17pm UTC](https://boards.straightdope.com/t/poll-do-you-recognize-the-term-fuzz-testing-and-are-you-a-software-developer/997369/15 "2024-02-10T18:17:41Z")

</div>

Depends on what you’re testing I would think.

For simple stuff like EDI testing it is a good idea that should work well as it could be used again and again.

Probably true for alarm testing and logging for companies like AT&T.

A lot of online inquiries also seem suitable for this.

---

<div class="post-metadata">

### Author: ![Telemark](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/telemark/32/372_2.png) [@Telemark](https://boards.straightdope.com/u/Telemark)
#### Post date: [February 10, 2024, 6:26pm UTC](https://boards.straightdope.com/t/poll-do-you-recognize-the-term-fuzz-testing-and-are-you-a-software-developer/997369/16 "2024-02-10T18:26:47Z")

</div>

SW engineer for the last 40 years, not familiar with the term.

But I know to always mount a scratch monkey.

---

<div class="post-metadata">

### Author: ![Sam\_Stone](https://avatars.discourse-cdn.com/v4/letter/s/ecccb3/32.png) [@Sam\_Stone](https://boards.straightdope.com/u/Sam_Stone)
#### Post date: [February 10, 2024, 6:43pm UTC](https://boards.straightdope.com/t/poll-do-you-recognize-the-term-fuzz-testing-and-are-you-a-software-developer/997369/17 "2024-02-10T18:43:37Z")

</div>

I’m a recently retired software engineer. I’ve written a gazillion unit tests, built integration test frameworks, used github and cloud for development, full stack web development, etc. C/C++/C#, Java, all the latest frameworks up to about 5 years ago.

I’ve never heard the term. Of course the concept has been around forever, especially in security testing. Most of the time our tests push out to the edge cases, but not truly random. Things like if a function takes a string as input, you try zero length strings, huge strings, etc. You test for buffer overflow issues, commands hidden in strings depending on what’s done with them, that kind of stuff.

Writing good tests is a bit of an art. There are lots of garbage unit tests out there. ‘fuzz trsting’ sounds like a good tool to overcome developer bias in testing code.

---

<div class="post-metadata">

### Author: ![SunUp](https://avatars.discourse-cdn.com/v4/letter/s/ea5d25/32.png) [@SunUp](https://boards.straightdope.com/u/SunUp)
#### Post date: [February 10, 2024, 9:33pm UTC](https://boards.straightdope.com/t/poll-do-you-recognize-the-term-fuzz-testing-and-are-you-a-software-developer/997369/18 "2024-02-10T21:33:54Z")

</div>

> [@Chronos](#):
>
> Wouldn’t automating that process be just as hard as writing the original program bug-free to begin with?

Not necessarily.

A lot of fuzzers these days use profile-driven fuzzing - so that, for example, the fuzzer provides an input to the module under test and then checks to see what part of that module’s code executed for that input. It then takes that information and varies the input and over many iterations builds an understanding of how inputs exercise each basic block of the module’s code - some even take into account the values stored in variables. Over time, it tries to maximize the amount of code covered by the fuzz testing, and can point to parts of code it hasn’t been able to reach, so that a tester can guide the process a little to find how to cover what the fuzzer hasn’t.

---

<div class="post-metadata">

### Author: ![Dr.Strangelove](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dr.strangelove/32/6613_2.png) [@Dr.Strangelove](https://boards.straightdope.com/u/Dr.Strangelove)
#### Post date: [February 10, 2024, 9:48pm UTC](https://boards.straightdope.com/t/poll-do-you-recognize-the-term-fuzz-testing-and-are-you-a-software-developer/997369/19 "2024-02-10T21:48:29Z")

</div>

> [@Chronos](#):
>
> Wouldn’t automating that process be just as hard as writing the original program bug-free to begin with?

You’d like to think so, but no. Software is hard, and we’re still bad at it.

Also, the people writing the tests are not necessarily the developers. This is most obvious in the case of hackers, who have an interest in exploiting vulnerabilities. Developers have an interest in writing bug-free code, but they’re subject to different priorities. They don’t win a million dollars if they fix some subtle bug that allows stealing a bunch of passwords or whatever.

Less maliciously, fuzz testing is used by security researchers to find bugs before hackers do. The old Heartbleed bug (in the OpenSSL library) was found via fuzz testing:

> **[The Fuzzing Files: Testing for Heartbleed | Mayhem](https://www.mayhem.security/blog/the-fuzzing-files-the-anatomy-of-a-heartbleed)**
>
> In 2014, fuzz testing was used to discover the Heartbleed vulnerability which affected systems providing secure transactions.

Fuzz testing is a form of black box testing. I.e., you don’t need to know anything about the internals–you just feed in inputs and see what happens. So it doesn’t require the same degree of domain expertise as the original software development did.

And there are various generic fuzz testing frameworks, so a lot of the work has already been done and packaged up. There’s still some work involved in connecting it to the target code, but much less than building it all from scratch.

I’m a little surprised that less than half of developers have heard of it. It’s not _that_ common a general practice in my experience, but I’d hope most developers follow security news just to keep abreast of things, and it’s very commonplace there.

**Sam\_Stone** makes a very good point that fuzz testing is a way of overcoming developer bias. We can be very blind to the defects in our own code (otherwise we’d have fixed them already).

---

<div class="post-metadata">

### Author: ![Sam\_Stone](https://avatars.discourse-cdn.com/v4/letter/s/ecccb3/32.png) [@Sam\_Stone](https://boards.straightdope.com/u/Sam_Stone)
#### Post date: [February 10, 2024, 10:07pm UTC](https://boards.straightdope.com/t/poll-do-you-recognize-the-term-fuzz-testing-and-are-you-a-software-developer/997369/20 "2024-02-10T22:07:40Z")

</div>

Towards the end, my company demanded that developers be their own QA. I pushed back on that quite hard, and lost. We were always told to write our own unit tests, and towards the end even write the test plans and waste expensive computer engineering time setting up test machines and building docker images and integration tests.

But having developers write their own test plans and execute them was a ridiculous idea. If the developer didn’t notice the design flaw in their code, why would you expect them to know to test for it? And Quality Assurance is its own professional field, and it shouldn’t be assumed that developers are all capable of decent QA - especially on their own code.

Fuzz testing at least adds an element of randomness to the testing. But the fact that so many developers have never heard of it backs up the idea that not all developers are educated in the latest QA things.

[Next page](https://boards.straightdope.com/t/poll-do-you-recognize-the-term-fuzz-testing-and-are-you-a-software-developer/997369.md?page=2)
