Live data from Hacker News

Ghidra

nsa.gov

31–40 of 60 posts

Re: Ghidra

#31
I wonder what the NSA does with the analytics on a page like this.

Re: Ghidra

#32
post #23

Earlier quoted context omitted.

It's going to be an open source release so depending on your paranoia levels you could just build it yourself.

You'd have to audit the source code first, though, which is not a trivial thing to do.

Given the audience I feel like the source code will be audited by the community in record time.

Re: Ghidra

#33
post #16

I'm still trying to figure out, in this day and age, especially after the Snowden disclosures, why anyone would trust software released by this organization. you do realize their primary goal is intelligence gathering?

It's a reverse engineering tool . The community is going to have plenty of ability to do network analysis on it. Also, it's trivial to sandbox it, even if it weren't going to be open-sourced.

I am familiar with the concept. However, I would recommend hesitating to anyone who thinks any software from the organization, open source or no, is entirely harmless to the user...

Re: Ghidra

#34
post #17

Earlier quoted context omitted.

This is basically how a monopoly works. And the defense industry behaves like a monopoly even if its made up of a bunch of different companies.

I disagree, I think there's an important difference between a monopoly and a company that happens to have no competition at the moment. I think that active anti-competitive actions are one of the defining characteristics of a monopoly, and so far we haven't seen that behavior from hex-rays. They had a significant barrier to entry protecting them, in that making a decompiler (the hex rays decompiler is the expensive p…

> I think there's an important difference between a monopoly and a company that happens to have no competition at the moment. I think that active anti-competitive actions are one of the defining characteristics of a monopoly

You are of course free to think so, but be aware that does not align with the common use of the term monopoly.

Re: Ghidra

#35
NSA releasing an open-source tool? My first thought is, better subject it to serious, in-depth security review before installing it locally. Even then, build it from source.

Re: Ghidra

#36
post #5

My brother is into reverse engineering, he is literally counting the days to the open source release of this. He said there isn't anything quite like it as it can actually stand toe-to-toe with IDA Pro, the commercial software that apparently nothing yet can really beat.

As someone who learned to program by reverse engineering, I also cannot wait to see this being released.

Nothing really beat the combination of SoftICE and IDA Pro, although some of the newer entrants like radare2 & good ol’ OllyDBG are pretty good, but nothing beats IDA Pro.

I hope the scripting language are real programming language like Lua or Python and some custom DSL.

Re: Ghidra

#37

Earlier quoted context omitted.

It's a reverse engineering tool . The community is going to have plenty of ability to do network analysis on it. Also, it's trivial to sandbox it, even if it weren't going to be open-sourced.

Sandboxing things is rarely trivial ;)

Air gapped RE machines (recall you're probably looking at malware anyway). One way transfer of samples. Print reports and OCR. Done.

Re: Ghidra

#38
post #23

Earlier quoted context omitted.

It's going to be an open source release so depending on your paranoia levels you could just build it yourself.

You'd have to audit the source code first, though, which is not a trivial thing to do.

But you can bet there will be plenty of people looking at it, and that group of people will also likely include security professionals looking to use it. I'm not sure I can honestly think of a stupider move in this area than to include nefarious code in an open source security auditing tool aimed at the highest and most complex levels of security auditing and used by professionals whose job it is to find and announce these things.

That doesn't mean assume nothing's wrong, but I'm pretty sure this thing will have some pretty talented people looking at it fairly early just for kicks, so of things to worry about, this isn't high on my list.

Re: Ghidra

#39

NSA releasing an open-source tool? My first thought is, better subject it to serious, in-depth security review before installing it locally. Even then, build it from source.

Apache NiFi was also released by the NSA & has seen commercial success in the enterprise.

Re: Ghidra

#40
post #3

There was a thread on HN when they first announced a public release at RSA[0]. A lot of reverse engineers I know are excited for it. 0: https://news.ycombinator.com/item?id=18828083

Since that was less than two months ago, the current submission counts as a dupe. When it's open-sourced, that will be significant new information, which makes for a new story. It will certainly be discussed by HN then.

https://hn.algolia.com/?query=%22significant%20new%20informa...

Post reply on HN