Earlier quoted context omitted.
Buddy, I'm not gonna follow this thread anymore because you seem to be baiting me to read you a lecture on OPSEC, security in depth and compartmentalization.
Buddy, your distro hopping advice is advice so bad, that the most charitable interpretation is you have no idea what you’re talking about. Seriously? Distro hop? My brain hurts, I need coffee.
Ghidra: A software reverse engineering suite of tools developed by the NSA
121–130 of 147 posts
Re: Ghidra: A software reverse engineering suite of tools developed by the NSA
#122I used this again just the other day with the cantor.dust plugin. My rev.eng skills are dull and were never great to begin with, but for anything below a real APT with obfuscation, runtime decoding and unpacking, Ghidra is an equalizer. Between this and Chef from gchq, someone with devops skills can probably skill up to an entry level threat analyst level in a few weeks or months. The tooling available today is reall…
You mean my electricity has been backdoored? Now that's paranoia on a different level, how does that work
Re: Ghidra: A software reverse engineering suite of tools developed by the NSA
#123Earlier quoted context omitted.
Yeah, that's bullshit. For NSA-proof personal tech stack you'd rely more on tamper-evident blocks that's all. Also, security in depth and security through obscurity are much more applicable if you're a person and not an organization. Finally, +20 years head start does not mean much if you distrohop and FOMO into bleeding edge stuff like a tech podcaster.
Yeah this is bullshit. There is no demonstrated NSA proof setup. If they haven’t broken in to something, they aren’t telling us about it.
This principle isn't scalable to every computer system out there and will definitely go against other requirements in most organizations, but if you are an individual, it's not hard to pull it off.
Re: Ghidra: A software reverse engineering suite of tools developed by the NSA
#124Earlier quoted context omitted.
How well does it decompile itself ? I've always considered that a great test, much like a self-compiling compiler is a notable milestone. (I believe IDA has a check to stop you from doing this. Cracking that was one of the "rite of passage" exercises back in the day.)
It's open source and written in Java.
Re: Ghidra: A software reverse engineering suite of tools developed by the NSA
#125It is open source software and it can reverse engineer programs from a lot of different systems. Some people may be worried about installing a piece of software on their computer that comes from the NSA. I don't think that there are real reasons to worry. One of the tasks of the NSA is defending against cyber attacks. Having more people with good tools helps the defense. Also, you can be pretty certain that some secu…
> Besides, if the NSA really wants to install some software on your computer, they can probably do it themselves without your involvement. Running Linux with very few binblobs, I expect they will not be able to. Running any OS published by $tax_evading_big_corp, I expect they can.
* under linux I mean mainstream distro here. Unless you use qubes os, it will not have good sandbox, everything runs as your user and can easily modify eg. .bashrc and start up a key logger to get sudo password.
Re: Ghidra: A software reverse engineering suite of tools developed by the NSA
#126Earlier quoted context omitted.
Yeah this is bullshit. There is no demonstrated NSA proof setup. If they haven’t broken in to something, they aren’t telling us about it.
Assuming that time travel is impossible, NSA can't break into something that does not exist anymore. Hence the idea when facing such adversary is to provide them a constantly moving target. Although NSA might be able to break any full disc encryption given enough time, they aren't able to decrypt something that no longer exists. This principle isn't scalable to every computer system out there and will definitely go a…
Are those parts vulnerable to the NSA?
I believe due to what was made public, that they do have that capability.
I would suggest more research. If you are actually changing distros every month, that seems like a very manual process, with many points to use an insecure config. I think your time could be better spent hardening a current system.
And yes the NSA could own your box every month (and would) if it suited them.
Check out this link, this stuff is fascinating.
> In some cases, the NSA has modified the firmware of computers and network hardware—including systems shipped by Cisco, Dell, Hewlett-Packard, Huawei, and Juniper Networks—to give its operators both eyes and ears inside the offices the agency has targeted. In others, the NSA has crafted custom BIOS exploits that can survive even the reinstallation of operating systems. And in still others, the NSA has built and deployed its own USB cables at target locations—complete with spy hardware and radio transceiver packed inside.
https://arstechnica.com/information-technology/2013/12/insid...
Re: Ghidra: A software reverse engineering suite of tools developed by the NSA
#127Earlier quoted context omitted.
Yes and we've seen their shit get leaked over the years. From that we can see clear patterns in what they view as valuable and where they spend their significant, but still limited focus.
Can you proof that it is a leak, and not a stunt by the NSA itself?
Re: Ghidra: A software reverse engineering suite of tools developed by the NSA
#128Earlier quoted context omitted.
Have you seen the crazy stuff the NSA does?
Link please? I know they collect data, and have Windows backdoors.
https://arstechnica.com/information-technology/2013/12/insid...
Reading their processes is so fascinating.
Re: Ghidra: A software reverse engineering suite of tools developed by the NSA
#129Earlier quoted context omitted.
Reflections on Trusting Trust is worth a read. https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_Ref...
Not really. TLDR: You cannot trust code you did not botch up yourself.
If you've never read it I highly encourage you to do so.
Re: Ghidra: A software reverse engineering suite of tools developed by the NSA
#130Earlier quoted context omitted.
Can you proof that it is a leak, and not a stunt by the NSA itself?
You have be wearing multiple tinfoil hats if you think NSA released DeepBlue as some sort of black flag OP
EternalBlue...and it was a part of the shadow broker package, but that was just one occasion, Snowden is one of the other.
One must probably wear a Tar-hat to think that this is impossible.