Earlier quoted context omitted.
An open source project used by people capable of analyzing the network and disk I/O of binaries they run doesn't sound like a good target -- if something was found it would have massive consequences.
Backdoors from TLAs don't look like backdoors.
A first look at Ghidra’s Debugger – Game Boy Advance Edition
11–17 of 17 posts
Re: A first look at Ghidra’s Debugger – Game Boy Advance Edition
#12Earlier quoted context omitted.
Backdoors from TLAs don't look like backdoors.
People who use Ghidra know that backdoors from TLAs don't look like backdoors.
Also, it is as if people forget the launch of Ghidra; https://github.com/NationalSecurityAgency/ghidra/issues/6
Re: A first look at Ghidra’s Debugger – Game Boy Advance Edition
#13Off topic but I have to ask. Does anyone else wonder if there are backdoors in NSA projects like this? It seems like a way you could get a foothold into lots of interesting places. Edit: Spelling. Also, I recognize this particular program may not be the best target, but SELinux for example, or any of their projects. As for the "It's open source argument", if they provide binaries, do they have instructions for reprod…
I can't imaging a project aimed at reverse engineers would be the best place to try to hide that sort of thing. Ghidra is open source, you are free to audit and build it yourself if you are concerned.
^ the manyeyeballs fallacy
Re: A first look at Ghidra’s Debugger – Game Boy Advance Edition
#14Off topic but I have to ask. Does anyone else wonder if there are backdoors in NSA projects like this? It seems like a way you could get a foothold into lots of interesting places. Edit: Spelling. Also, I recognize this particular program may not be the best target, but SELinux for example, or any of their projects. As for the "It's open source argument", if they provide binaries, do they have instructions for reprod…
https://latesthackingnews.com/2019/03/24/critical-vulnerabil...
Re: A first look at Ghidra’s Debugger – Game Boy Advance Edition
#15Earlier quoted context omitted.
I can't imaging a project aimed at reverse engineers would be the best place to try to hide that sort of thing. Ghidra is open source, you are free to audit and build it yourself if you are concerned.
> Ghidra is open source, you are free to audit and build it yourself if you are concerned. ^ the manyeyeballs fallacy
Re: A first look at Ghidra’s Debugger – Game Boy Advance Edition
#16Earlier quoted context omitted.
> Ghidra is open source, you are free to audit and build it yourself if you are concerned. ^ the manyeyeballs fallacy
I don’t think the many eyes fallacy states that code audits are impossible or useless.
Re: A first look at Ghidra’s Debugger – Game Boy Advance Edition
#17Earlier quoted context omitted.
People who use Ghidra know that backdoors from TLAs don't look like backdoors.
I wouldn't say this is true at all, there are lots of kids out there who will cut their teeth with this seeing as it is entirely free. Also, it is as if people forget the launch of Ghidra; https://github.com/NationalSecurityAgency/ghidra/issues/6
Your issue (which is barely a vulnerability at all, in my personal opinion) demonstrates a failure to hide a vulnerability, if you think it was intentionally-placed (which I don't), in that you quickly learned about it.