I don't have much experience with this but it would be nice to run some static/dynamic analysis security tools on the code base.
Valgrind would also be a good one to run, primarily to avoid mem leaks.
I suggest setting up CI to do this, so they'll get run with every change.
Also an audit performed by humans may be relevant to this project (:
More hardware than software related but when I get my tokens in I'll be x-raying them. Would you be interested in copies of the x-rays?
I'll appreciate that ! (Even if I will be unable to see anything "wrong")
Thanks for the answer !
Le sam. 6 oct. 2018 Ã 20:16, Jacob Alberty notifications@github.com a
écrit :
More hardware than software related but when I get my tokens in I'll be
x-raying them. Would you be interested in copies of the x-rays?—
You are receiving this because you commented.
Reply to this email directly, view it on GitHub
https://github.com/SoloKeysSec/solo/issues/3#issuecomment-427595341, or mute
the thread
https://github.com/notifications/unsubscribe-auth/AGZ3Lj_kpn9ggto6bKtFwNlLJLC8h5yrks5uiPNqgaJpZM4WoWto
.
@jacobalberty Hell yeah!
Most helpful comment
More hardware than software related but when I get my tokens in I'll be x-raying them. Would you be interested in copies of the x-rays?