Live data from Hacker News

“Stop reverse engineering our code”

blogs.oracle.com

221–230 of 358 posts

Re: “Stop reverse engineering our code”

#221
post #176

Earlier quoted context omitted.

> The only definition of "reverse engineering software" that I use Uhm, no, that's far too narrow. Reverse engineering is any kind of introspection into a device in question, designed for obtaining any degree of understanding of its inner functioning. What you're talking about is called "decompilation", and it's not even among the most useful reverse engineering techniques.

People have different understandings of words, so I'm not claiming there is one, universal meaning of "software reverse engineering." However, here is the definition some researchers came up with: "Reverse engineering is the process of analyzing a subject system to create representations of the system at a higher level of abstraction. It can also be seen as "going backwards through the development cycle." (from https…

That quote is quite different from the definition you're using.

Your definition is not what anyone else uses, from what I've seen. You don't have to use the same definition, of course, but be aware that unless you clarify what you mean, you're going to be creating a ton of confusion.

Re: “Stop reverse engineering our code”

#222
post #201

Earlier quoted context omitted.

> The only definition of "reverse engineering software" that I use is this That's the definition of decompiling not reverse engineering. The original IBM BIOS was reverse engineered by two teams: one which read the disassembled binary and wrote a written specification and a second team that took that specification and wrote code.

What you just described agrees with my definition. The ultimate goal of both teams was to end up with usable source code that is likely to be close or identical to the original used to create the binary. There is a slight difference in the IBM BIOS project in that, I think the goal was to create code which could not be claimed to infringe on the patents/copyrights of IBM. That last bit is an extension of reverse engi…

You are right, that does agree with your definition. But, in my opinion, the reverse engineering was done only by the first team. They took the binary and constructed an understanding of the code. The second team just did basic software engineering from a spec. Your definition requires both teams and that's where your definition is too narrow.

Re: “Stop reverse engineering our code”

#223

Earlier quoted context omitted.

For general sanity: $150,000,000

To be pedantic, 1.5e8 carries additional information about accuracy: $150,000,000 ± $5,000,000. By contrast, 1.50e8 would be ten times as accurate, and so on. Of course, accuracy is hardly relevant here.

s/accuracy/precision

Sorry, I don't usually try to be pedantic, but when the conversation is already about nitpicking, I think it's necessary.

Significant figures are precision, not accuracy. Accuracy is "being in the ballpark". Precision is "tight groups".

Re: “Stop reverse engineering our code”

#224
post #162

Earlier quoted context omitted.

> Reverse engineering software is completely different from penetration testing How is it so? You cannot find funny vulnerabilities without reverse engineering the binaries. > It doesn't make sense for it to be illegal to forbid reverse engineering in a license agreement, where is that the case? France, Switzerland, Russia and many more. > it would make more sense to just forbid closed source software How did you mak…

I think there may be a language barrier here. So, this should clear it up: The only definition of "reverse engineering software" that I use is this -- "Using tools and deep binary analysis to take a compiled binary, and convert it back to source code as close to the original as possible". It is a very specific definition. I do not mean general "analysis" or vulnerability testing or input manipulation, etc... only att…

Under EU law it is illegal to forbid someone to convert a binary back into source code.

Even further, if I buy a software, and it does not run on my system, I can turn it back into source, modify it, recompile it, and use it as much as I want.

If the original company tries to prevent me from doing this, they commit a crime that can be punished with multiple months of jail for their CEO or 10% of their profit as long as they have that practice.

Re: “Stop reverse engineering our code”

#225

So, I disagree with the poster on a bunch of things here (no surprise, really). But: this is authentic. This is what we (i.e. hackers) are always claiming we want. Someone speaking her mind, shooting from the hip, etc. Not an anodyne blob of corporate-speak: this is an opinion, stated pretty clearly, and backed up with fighting words. You'd expect: "Our legal team has advised us to remind consultants that they are bo…

> But: this is authentic. This is what we (i.e. hackers) are always claiming we want. Someone speaking her mind, shooting from the hip, etc. Not an anodyne blob of corporate-speak: this is an opinion, stated pretty clearly, and backed up with fighting words.

We also want intelligence and clear thinking along with it. We don't, as a rule, want loud and dumb as a bag of rocks. That way lies Donald Trump.

At the same time, this is a huge improvement over corporate doublespeak. It helps the stupidity and arrogance shine through clearly, which is one reason that I like it when people talk this way.

Re: “Stop reverse engineering our code”

#226

> Q. If you don’t let customers reverse engineer code, they won’t buy anything else from you. > A. I actually heard this from a customer. It was ironic because in order for them to buy more products from us (or use a cloud service offering), they’d have to sign – a license agreement! With the same terms that the customer had already admitted violating. “Honey, if you won’t let me cheat on you again, our marriage is t…

She also missed the fact, that there are things called laws. If the non-overridable (cogent) clause in the law says I can do reverse engineering for purpose X, I can do that and what is in license agreement is not relevant at all.

Re: “Stop reverse engineering our code”

#227
post #80

Wow. Really? This single blog post is strong evidence for why you should never, ever buy an Oracle product, and if you are running anything written by them, why you should plan to migrate away. Now, the culture of consultants in the Oracle sphere of influence is pretty toxic and money-grubbing. I can imagine companies being badgered into paying security weasels big bucks to analyze software with tools that cough up a…

I went to a prominent tech school that adopted an Oracle platform for student course management in my last few years. I won't mince words: it was a piece of shit, and my school's administrators ate shit by agreeing to a contract that forbid them from making any changes to Oracle's broken system. Now I work in college administration and we have to deal with the very same pile of junk. Someone once told me that Larry E…

> Larry Ellison is the biggest asshole in Silicon Valley, and also the richest, so he must be doing something right.

This weekend I learned that Larry Ellison purchased ~90% of an island in Hawaii.

Re: “Stop reverse engineering our code”

#228
post #62

> I am not dissing bug bounties, just noting that on a strictly economic basis, why would I throw a lot of money at 3% of the problem Aren't the issues not found by Oracle the problem? I'm amazed that stil 23% of the externally found security issues are reported by researchers, the incentive to responsibly disclose security issues to Oracle isn't really big. It sounds like a cumbersome process with potential legal co…

When 0-days can exist in the 13% she handwaved away, it really makes you wonder how she's Chief Security Officer...

Re: “Stop reverse engineering our code”

#230

Earlier quoted context omitted.

I actually understand how it gets to be this way though. I literally can't touch a Government project without an Oracle license. When I talk to a salesman, the attitude is "I know you can't do this without me", contrary to salesmen for any other product in any other industry. When I talk to a project manager, they don't ask how it will be hosted, or what the platform will be, or anything else obvious. The first quest…

Interesting. In what industries is Oracle so dominant? You say government is one, but where else? In industry, all I've ever seen is Sybase, SQL Server, and MySQL (ok, technically Oracle). (My background is finance and technology.)

Oracle is very popular for mission-critical databases in banks. I've seen Sybase used in banks too but it's definitely less popular now than it used to be.
Post reply on HN