Ghidra
31–40 of 60 posts
Re: Ghidra
#32Earlier quoted context omitted.
It's going to be an open source release so depending on your paranoia levels you could just build it yourself.
You'd have to audit the source code first, though, which is not a trivial thing to do.
Re: Ghidra
#33I'm still trying to figure out, in this day and age, especially after the Snowden disclosures, why anyone would trust software released by this organization. you do realize their primary goal is intelligence gathering?
It's a reverse engineering tool . The community is going to have plenty of ability to do network analysis on it. Also, it's trivial to sandbox it, even if it weren't going to be open-sourced.
Re: Ghidra
#34Earlier quoted context omitted.
This is basically how a monopoly works. And the defense industry behaves like a monopoly even if its made up of a bunch of different companies.
I disagree, I think there's an important difference between a monopoly and a company that happens to have no competition at the moment. I think that active anti-competitive actions are one of the defining characteristics of a monopoly, and so far we haven't seen that behavior from hex-rays. They had a significant barrier to entry protecting them, in that making a decompiler (the hex rays decompiler is the expensive p…
You are of course free to think so, but be aware that does not align with the common use of the term monopoly.
Re: Ghidra
#35Re: Ghidra
#36My brother is into reverse engineering, he is literally counting the days to the open source release of this. He said there isn't anything quite like it as it can actually stand toe-to-toe with IDA Pro, the commercial software that apparently nothing yet can really beat.
Nothing really beat the combination of SoftICE and IDA Pro, although some of the newer entrants like radare2 & good ol’ OllyDBG are pretty good, but nothing beats IDA Pro.
I hope the scripting language are real programming language like Lua or Python and some custom DSL.
Re: Ghidra
#37Earlier quoted context omitted.
It's a reverse engineering tool . The community is going to have plenty of ability to do network analysis on it. Also, it's trivial to sandbox it, even if it weren't going to be open-sourced.
Sandboxing things is rarely trivial ;)
Re: Ghidra
#38Earlier quoted context omitted.
It's going to be an open source release so depending on your paranoia levels you could just build it yourself.
You'd have to audit the source code first, though, which is not a trivial thing to do.
That doesn't mean assume nothing's wrong, but I'm pretty sure this thing will have some pretty talented people looking at it fairly early just for kicks, so of things to worry about, this isn't high on my list.
Re: Ghidra
#39NSA releasing an open-source tool? My first thought is, better subject it to serious, in-depth security review before installing it locally. Even then, build it from source.
Re: Ghidra
#40There was a thread on HN when they first announced a public release at RSA[0]. A lot of reverse engineers I know are excited for it. 0: https://news.ycombinator.com/item?id=18828083
https://hn.algolia.com/?query=%22significant%20new%20informa...