Comment by afiori
2 months ago
Nope, there is no need for this.
Think of it like an attacker (the app) would breach a cryptographic target (you and every other user of the app). The attacker starts to send random messages or try to mess around with signatures/tokens/APIs and listens for errors, timeouts, spam filters, possible side channels until it learns enough to figure out how to predict how the system will behave and maybe even to influence it.
Both in the analogy and with the timeline out does not matter if you mix a few random messages between a test and another as long as you comprehensively keep track of how the target behaves.
Every interaction is a data point, some data points are more useful than others but none is useless
No comments yet
Contribute on Hacker News ↗