Live data from Hacker News

Ghidra, NSA's reverse-engineering tool

nsa.gov

11–20 of 425 posts

Re: Ghidra, NSA's reverse-engineering tool

#11
I am going to sound pessimistic here, but isn't there a real danger of having this technology available to bad actors and is there any value to keeping such things confidential if it plays a role in national security?

If someone was releasing malicious software to hijack the power grid as an example, wouldn't they be first able to use this to try to improve the robustness and invisibility of their attack ?

Or is the functionality here common place enough that it doesn't tilt the axis of power in an unfavorable way?

Re: Ghidra, NSA's reverse-engineering tool

#13
post #11

I am going to sound pessimistic here, but isn't there a real danger of having this technology available to bad actors and is there any value to keeping such things confidential if it plays a role in national security? If someone was releasing malicious software to hijack the power grid as an example, wouldn't they be first able to use this to try to improve the robustness and invisibility of their attack ? Or is the…

Bad actors have been using IDA this entire time. So no, not really.

Re: Ghidra, NSA's reverse-engineering tool

#14

Download: https://ghidra-sre.org/ GitHub: https://github.com/NationalSecurityAgency/ghidra

Download from the NSA without open source software... anyone else virtualizing three layers deep to get to this?

I don't think they would burn some 0-days for this, one container should be enough.

Re: Ghidra, NSA's reverse-engineering tool

#15
post #11

I am going to sound pessimistic here, but isn't there a real danger of having this technology available to bad actors and is there any value to keeping such things confidential if it plays a role in national security? If someone was releasing malicious software to hijack the power grid as an example, wouldn't they be first able to use this to try to improve the robustness and invisibility of their attack ? Or is the…

This is just another reverse engineering tool, similar to IDA. Bad actors have had access to stuff like this for a while.

Re: Ghidra, NSA's reverse-engineering tool

#17
post #11

I am going to sound pessimistic here, but isn't there a real danger of having this technology available to bad actors and is there any value to keeping such things confidential if it plays a role in national security? If someone was releasing malicious software to hijack the power grid as an example, wouldn't they be first able to use this to try to improve the robustness and invisibility of their attack ? Or is the…

Bad actors have been using IDA this entire time. So no, not really.

You mean there is nothing new here? Then why is this news?

I am not wondering about the concept of reverse engineering but the specific (and hopefully novel) feature set that this may enable.

Re: Ghidra, NSA's reverse-engineering tool

#19
post #17

Earlier quoted context omitted.

Bad actors have been using IDA this entire time. So no, not really.

You mean there is nothing new here? Then why is this news? I am not wondering about the concept of reverse engineering but the specific (and hopefully novel) feature set that this may enable.

It's a competitor to IDA's monopoly, basically. It might be better in certain aspects.

Re: Ghidra, NSA's reverse-engineering tool

#20
post #11

I am going to sound pessimistic here, but isn't there a real danger of having this technology available to bad actors and is there any value to keeping such things confidential if it plays a role in national security? If someone was releasing malicious software to hijack the power grid as an example, wouldn't they be first able to use this to try to improve the robustness and invisibility of their attack ? Or is the…

What can stop a bad guy with a toolkit? A good guy with a toolkit!
Post reply on HN