3 ms·
This isn't true. You can use disassembly tools to trace through code, and you can see what imports/exports there are, as well as what API calls are being made u
by TimJYoung 8y ago
This isn't true. You can use disassembly tools to trace through code, and you can see what imports/exports there are, as well as what API calls are being made using static analysis tools.
You can also use all sorts of runtime tools to see what a binary is doing at runtime, so I imagine it would be pretty easy to see if an application is phoning home, and where home is located, although the data is probably encrypted.
In fact, it might actually be easier for an end user to audit a binary using such automated tools instead of looking at the source code itself. At least with the automated tools, the tools can flag suspicious constructs in the binary that may indicate that it's up to no good, and do so in a way that is more understandable to the end user.