Live data from Hacker News

Ghidra: A software reverse engineering suite of tools developed by the NSA

ghidra-sre.org

141–147 of 147 posts

Re: Ghidra: A software reverse engineering suite of tools developed by the NSA

#141

Earlier quoted context omitted.

If they could install a virus on Iran's air-gapped uranium centrifuge industrial control systems, I'm pretty sure they could get one on your computer.

Bribing people in generally corrupt and poor countries to smuggle a USB stick is kind a different than just breaking into random persons home in a country with relatively low corruption. Latter might actually be more difficult. Obviously depends on what your end goal is

Ever heard of a bump key? It's easy to break into a home in a country with relatively low corruption. One might even say easier. It just comes down to whether you have one person corrupt enough to use it. A locked door is nothing more than a social contract. Door is locked means do not come in. Tell that to the person with a bump key.

Re: Ghidra: A software reverse engineering suite of tools developed by the NSA

#142
post #13

Earlier quoted context omitted.

Its used to reverse engineer an unknown binary without the matching source code. Since Ghidra already is open source it be no use to audit Ghidra itself except for learning purposes. It might be useful to reverse engineer a closed source driver so you can write an open source one from scratch.

A security audit is still useful when you have sources to the program. There may still be some intended or just accidental security problems with it. Having the sources makes such an audit a lot easier to do.

Is there a standard process anywhere for vetting some software for information leakage? I would imagine that someone would deploy the software behind an MITM proxy and then look at the traffic, but it would be nice if there was some standard process or framework for this somewhere.

Re: Ghidra: A software reverse engineering suite of tools developed by the NSA

#143
post #43
post #2

It is open source software and it can reverse engineer programs from a lot of different systems. Some people may be worried about installing a piece of software on their computer that comes from the NSA. I don't think that there are real reasons to worry. One of the tasks of the NSA is defending against cyber attacks. Having more people with good tools helps the defense. Also, you can be pretty certain that some secu…

These are all true statements. Greetings from Seattle, Washington, USA! No need to cc them on this post. No one should kid themselves with what NSA is working on. No one should also kid themselves with what they aren't capable of.

after 10 years~ of lurking, your comment was the one that encouraged me to finally sign up.

I agree with you completely. Let's not joke at the capabilities of a trillion dollar organization focused on "cyber".

If you are fortunate enough to be a United States citizen who gets up and contributes to society on a daily basis -- you will never have anything to worry about. The NSA won't care anything about your dealings on the internet. Everyone can safely get back to their weird browsing habits and making lame comments on youtube -- no one is watching, because no one cares :)

Re: Ghidra: A software reverse engineering suite of tools developed by the NSA

#144

Earlier quoted context omitted.

I don't think there is anything fishy here, although I don't think the NSA can just install anything on my computer, even if I were based in the US. There is a lot of bluffing when it comes to cyber security. Still it might be quite a useful tool.

If they could install a virus on Iran's air-gapped uranium centrifuge industrial control systems, I'm pretty sure they could get one on your computer.

yeah but I just finished doing a security update /s

Re: Ghidra: A software reverse engineering suite of tools developed by the NSA

#145
post #100
post #96

Earlier quoted context omitted.

I don’t know. Seeing how extensively these key signing ceremonies (Let’s Encrypt included) are designed against tampering and collusion, I’d be shocked and impressed if they were infiltrated. We’ve found instead that the NSA can just take over your unpatched computer easily instead of putting in the effort of hacking Let’s Encrypt.

Unfortunately, a child can take over an unpatched computer using public exploits. Please explain your comment about how key signing ceremonies stop people from being bribed. The creation of those keys creates a root of trust but doesn't stop leaf certs from being generated.

Sure it doesn’t stop certs for certain domains but again it feels handwavy to say someone can just as easily do these things. Theoretically yeah. But to be a publicly trusted CA, the kind of processes you need to have a pretty extensive.

Still, there are hundreds of publicly trusted CAs so the chance for exploitation is higher.

Re: Ghidra: A software reverse engineering suite of tools developed by the NSA

#146
post #43

Earlier quoted context omitted.

These are all true statements. Greetings from Seattle, Washington, USA! No need to cc them on this post. No one should kid themselves with what NSA is working on. No one should also kid themselves with what they aren't capable of.

after 10 years~ of lurking, your comment was the one that encouraged me to finally sign up. I agree with you completely. Let's not joke at the capabilities of a trillion dollar organization focused on "cyber". If you are fortunate enough to be a United States citizen who gets up and contributes to society on a daily basis -- you will never have anything to worry about. The NSA won't care anything about your dealings…

Wow, I'm flattered that you would sign up because of my comment! I haven't been here that long and hardly ever comment but have always kept an account for times like you describe.

Re: Ghidra: A software reverse engineering suite of tools developed by the NSA

#147
post #91

Earlier quoted context omitted.

Not really. TLDR: You cannot trust code you did not botch up yourself.

Never thought I'd see the day where someone on HN is suggesting Ken Thompson isn't worth reading. If you've never read it I highly encourage you to do so.

I did read that article, my tldr is what I said.

Perhaps in 1984 what he writes was groundbreaking, but to me it wasn't. Do I need to apologize now for not being bamboozled by Ken's genius this time?

Post reply on HN