4 ms·
If .NET/C# could output native binaries for Windows Desktop apps, I could seriously think about switching to C# over C++. How do people deal with securing their
by pcunite 7y ago
If .NET/C# could output native binaries for Windows Desktop apps, I could seriously think about switching to C# over C++. How do people deal with securing their source code otherwise? Quite trivial to get the source from a decompiled C# exe file.
- dancek 7y agoYou can reverse engineer native binaries, too. Many companies are happily publishing web apps where the actual source is available, in minified form. Why does your source code need to be so secure?
- mads_ravn 7y agoYou can use an obfuscator (see e.g. https://stackoverflow.com/questions/19163701/how-can-i-obfuscate-my-c-sharp-code-so-it-cant-be-deobfuscated-so-easily https://stackoverflow.com/questions/19163701/how-can-i-obfus...). Note that you can still decompile the obfuscated code and look around (I’ve done so to attempt to debug a 3rd party library), but mangling all identifiers makes it quite hard to read.
- LeifCarrotson 7y agoIt's quite trivial to get the source from a C# exe file in the same way as a decompiler makes it trivial to get the source from a C++ exe file. Obfuscators are common if you're concerned about the symbols leaking. If you don't include the .PDB debugging symbol files it's much the same as native binary code. The .NET virtual machine code is a little more expressive but is superficially similar to x86 native code. In my opinion, if you're concerned about people reading your compiled machine code, the only solution is to run your app on a server and give users an API.
- fsloth 7y agoTo my understanding commercial software licenses can effectively enforced globally as long as you have reach of the local justice system. So need lawyers to represent you and so on. If the financial loss isn’t big enough to warrant a global license compliance scheme then I don’t see the source code would be that valuable (in a general commercial contex). But I don’t think any form of software that is distributed to end users can be fully secured from unlicensed use. You always need a legal recourse if you actually want to stop unlicensed use. The very-small niche where you can’t afford lawyers but want to force license compliance maybe isn’t a niche you can actually serve through a sound business. So, rather than seek for automated technical compliance solutions (they don’t really exist without the physical lawyer component) maybe you should find the biggest market you can serve, use the most productive tool for the job and try to make sure unlicensed use can be noticed.
- pjmlp 7y ago.NET has been able to do that since version 1.0, via NGEN at installation time. UWP makes use of AOT compiled .NET via .NET Native. How do people secure they C++ code otherwise, it is quite trivial to use IDA or HexRays.