18 ms·
It is open source software and it can reverse engineer programs from a lot of different systems. Some people may be worried about installing a piece of softwar
by NotSwift 5y ago
It is open source software and it can reverse engineer programs from a lot of different systems.
Some people may be worried about installing a piece of software on their computer that comes from the NSA. I don't think that there are real reasons to worry. One of the tasks of the NSA is defending against cyber attacks. Having more people with good tools helps the defense. Also, you can be pretty certain that some security people have been closely looking at the sources to see if it contains any suspicious features. Besides, if the NSA really wants to install some software on your computer, they can probably do it themselves without your involvement.
- raxxorrax 5y agoI don't think there is anything fishy here, although I don't think the NSA can just install anything on my computer, even if I were based in the US. There is a lot of bluffing when it comes to cyber security. Still it might be quite a useful tool.
- NotSwift 5y agoThere has been a lot of cyber crime in recent years, e.g. see the recent wave of ransomware attacks. These criminals are mostly amateurs that know some exploits and use them. The NSA is a huge organization that employs many professional experts. Spying is one of their main objectives so you can be pretty certain that they are pretty good at it. Computer systems contain a lot of vulnerabilities and you can be pretty certain that they know a lot of them. The computers of most people are vulnerable even to normal cyber criminals, the NSA is a lot more powerful.
- inlikealamb 5y agoMost of their work probably doesn't even need to be technical. How many high-profile attacks have been based on social engineering?
- killjoywashere 5y agoMost people hear "social engineering" and think of someone playing journalist to get access to places. The NSA's idea of social engineering is having the CIA work with the BND to buy Crypto AG.
- inlikealamb 5y agohow many "former" government employees work at Google?
- NotSwift 5y agoSocial engineering can be highly effective. However, from what we know about the NSA, especially from the Snowden leaks, it appears to be mainly a technical agency. It seems likely that the NSA does not use social engineering on a large scale itself but hands it off to other agencies like the CIA or the FBI.
- nix23 5y ago>although I don't think the NSA can just install anything on my computer If it's not connected to a network you are probably right....otherwise 100% wrong, if your a enough valuable target. And just lets say for fun your OS is 100% bulletproof, your +30 firmware's are not.
- raxxorrax 5y agoI doubt it. From operations that went public the attack vectors are known and you can extrapolate something about their capabilities. Of course they could get access if I were a valuable target, but that might just as well be with a large wrench. But they cannot just take control of any device. And I think many companies might even have better capabilities. Or defense, since intelligence work is very often about industrial espionage.
- nix23 5y ago>From operations that went public Are you talking about Snowden's powerpoint slides or the Shadow Brokers arsenal?
- atatatat 5y agoWisen up.
- killjoywashere 5y agoYou don't even exist to them. The NSA wants to infiltrate nations. They do stuff like hire a friendly foreign nation to quietly buy a security company their target depends on and then exploit that vulnerability from a host in a fourth nation.
- NotSwift 5y agoThe NSA is an agency with a yearly budget of approximately 10 billion dollars. There are not many companies that can match that.
- nextlevelwizard 5y agoWhat’s with the doomer mentality. NSA isn’t some magical unicorn that can just walk through everything
- o8r3oFTZPE 5y ago"There is a lot of bluffing when it comes to cyber security." I wish this topic received more discussion.
- nix23 5y agoYes we can talk about that, let's start with the FSB an why they are always so stupid ;) to left the compilation time with the working-hours of moscow and the cyrillic keyboard in the compiled binary.
- imwillofficial 5y agoIt’s almost as if it’s not the FSB… but somebody making it look like it was… (See the Vault7 leak attribution masking)
- ragona 5y agoI’m quite sure they could, but mostly just because they could simply walk into your house and tamper with the hardware. You don’t need a fancy zero day when you’re the government.
- klyrs 5y agoFunny thing about lockdown/wfh4l... they're really gonna wait a while to get in
- rytis 5y agoTurn up with a bunch of fire engines, and a gas company van. Knock on your door, and 3-4 neighbors on each side, for good measure. Tell there's been a report of a gas leak, and you need everyone to leave their houses/apartments immediately for the inspection. 15-20 mins later - you can come back in, all's safe. Thank you for your cooperation.
- user3939382 5y agoIf they could install a virus on Iran's air-gapped uranium centrifuge industrial control systems, I'm pretty sure they could get one on your computer.
- bitsculpt 5y agoyeah but I just finished doing a security update /s
- nextlevelwizard 5y agoBribing people in generally corrupt and poor countries to smuggle a USB stick is kind a different than just breaking into random persons home in a country with relatively low corruption. Latter might actually be more difficult. Obviously depends on what your end goal is
- ozfive 5y agoEver heard of a bump key? It's easy to break into a home in a country with relatively low corruption. One might even say easier. It just comes down to whether you have one person corrupt enough to use it. A locked door is nothing more than a social contract. Door is locked means do not come in. Tell that to the person with a bump key.
- arthurcolle 5y agoPassing an infected USB stick to operators in poorer countries (as you say) is hardly the most impressive part of the deployment procedure.
- nextlevelwizard 5y agobut literally the most important when you need to attack air gapped machine
- arthurcolle 5y agoNo, it's not the most important. The most important was clearly obtaining the PLC zero days to infect the physical machines. It's unclear to me why you choose to be so explicitly obtuse but in any case, for your own personal edification, feel free to read some details on how it went down - [0] https://www.wikiwand.com/en/Stuxnet https://www.wikiwand.com/en/Stuxnet [1] https://www.wired.com/2014/11/countdown-to-zero-day-stuxnet/ https://www.wired.com/2014/11/countdown-to-zero-day-stuxnet/ [1] https://www.hsdl.org/?view&did=792239 https://www.hsdl.org/?view&did=792239
- px43 5y agoI guarantee that whatever browser you use, they have 0day for it. Whatever ISP you use, they can inject traffic into it, and they have a much easier time about it if you aren't in the US. If you're someone who uses the Internet, the NSA can take over whatever you use to browse with and have their way with it. If you don't, well that's what their interdiction program is for. The thing is though, the economics of 0day indicate that the more you use it, the more likely it is that it'll get burnt, and supply is limited. They can certainly hack anyone, but it doesn't scale, so they can't simply hack everyone. They can maybe use these techniques on a handful of targets per year, so they make it count, but most of their intelligence comes from the data we all give away for free every day.
- zarzavat 5y agoIndeed the best protection against getting 0day'd is probably to be into computer security. I feel confident that the NSA is not throwing 0days at computer security professionals; whereas they could use them on the average person with little risk of detection.
- dhx 5y agoI think a lot of people underestimate how hard it would be to build something like Ghidra not from a technical perspective, but from an avoiding big organisation bureaucracy perspective. Unlike a typical bureaucracy however, and amongst other problems[1], the barrier for entry for hiring is extremely high, everything happens within an echo chamber (closed community with little external influence) and paranoia and overbearing security process has a freezing effect on morale and the use of modern workplace practices and technology. Whilst other companies and organisations hire staff quickly who can more freely experiment with the latest technology from a hip coffee shop or their home, someone at an organisation like the NSA after waiting a year to start the job and after having hiked 8km from their car to a windowless and soulless building in the middle of nowhere instead has to fill out dozens of forms and seek dozens of approvals just to consider the idea of experimenting with some new technology. I am amazed something as useful as Ghidra could actually be built within such a large bureaucracy in modern times, and then even more amazed that someone managed to get it released as open source software to ensure it continues to be maintained and useful long after the next internal reorganisation and exodus of developers. [1] https://news.ycombinator.com/item?id=16057449 https://news.ycombinator.com/item?id=16057449
- deleted 5y ago[deleted]
- karteum 5y agoThe Google Service Framework (which is installed on 99.999% of Android phones) gives a root access to Google on your device, and Google has the power to silently install/uninstall apps...
- tracedddd 5y agoI was quite suspicious of it when it was first announced, but an open source RE tool is probably the stupidest place to put a backdoor. Author considerations aside, it’s a great tool, and does pretty well with decompiling.
- thedracle 5y agoI'm amazed at how often it does better than hexrays decompiler wise. It's pretty spectacular. Radare2 has a plugin for using ghidra's decompiler too https://github.com/radareorg/r2ghidra https://github.com/radareorg/r2ghidra So you can get all of the terminal level unix like goodness of radare2, yet still get really great ghidra quality decompiler output.
- userbinator 5y agoHow well does it decompile itself? I've always considered that a great test, much like a self-compiling compiler is a notable milestone. (I believe IDA has a check to stop you from doing this. Cracking that was one of the "rite of passage" exercises back in the day.)
- rjzzleep 5y agoIsn't it written in Java? Why would it need to do that? IDA has had watermarks and all sorts of other fancy stuff. The real challenge with IDA was extending the demo to allow it to save databases before they started publishing a working older free version. I like IDA a lot more than I like all the other tools, especially since I consider the user experience and hotkeys far superior, but the other day I did look at something where the disassembly and decompilation was great compared to other tools(one of the r2+ghidra UIs). I think because flirt signatures were missing and I can't get Hexrays to sell me a new license.
- NotSwift 5y agoEven better, the NSA provides the sources which you can compile yourself: https://github.com/NationalSecurityAgency/ghidra/releases https://github.com/NationalSecurityAgency/ghidra/releases
- ShepherdKing 5y agoI would be curious to know if anyone has audited this for malicious code, or how one would go about doing that in the first place. Is that kind of software auditing a use case for Ghidra? A demo of using Ghidra to audit Ghidra would be interesting I suppose.
- pkaye 5y agoIts used to reverse engineer an unknown binary without the matching source code. Since Ghidra already is open source it be no use to audit Ghidra itself except for learning purposes. It might be useful to reverse engineer a closed source driver so you can write an open source one from scratch.
- NotSwift 5y agoA security audit is still useful when you have sources to the program. There may still be some intended or just accidental security problems with it. Having the sources makes such an audit a lot easier to do.
- ShepherdKing 5y agoIs there a standard process anywhere for vetting some software for information leakage? I would imagine that someone would deploy the software behind an MITM proxy and then look at the traffic, but it would be nice if there was some standard process or framework for this somewhere.
- aj3 5y agoIt's a huge code base, of course there are security issues. Same way IDA and radare have security issues. People who reverse malware take that into account.
- barkingcat 5y agoI would expect there to be self-mutating code such that when the open source code is compiled with a particular compiler it activates a different code path (written into the compiler itself) such that the final resulting binary does not correspond to the source code if it were compiled with another compiler. And if this resulting binary is distributed, audits of the source code wouldn't catch these modifications.
- ozfive 5y agoThese are all true statements. Greetings from Seattle, Washington, USA! No need to cc them on this post. No one should kid themselves with what NSA is working on. No one should also kid themselves with what they aren't capable of.
- bitsculpt 5y agoafter 10 years~ of lurking, your comment was the one that encouraged me to finally sign up. I agree with you completely. Let's not joke at the capabilities of a trillion dollar organization focused on "cyber". If you are fortunate enough to be a United States citizen who gets up and contributes to society on a daily basis -- you will never have anything to worry about. The NSA won't care anything about your dealings on the internet. Everyone can safely get back to their weird browsing habits and making lame comments on youtube -- no one is watching, because no one cares :)
- ozfive 5y agoWow, I'm flattered that you would sign up because of my comment! I haven't been here that long and hardly ever comment but have always kept an account for times like you describe.
- rapjr9 5y agoI can think of one concern about downloading and installing it, the NSA might be interested in who uses it. No need for anything malicious in the code, they just watch to see who downloads it.
- aj3 5y agoBut it's hosted on Github. And some distros have ghidra in official repos.
- pelasaco 5y agoprobably makes sense. I see in the government level a lot of open positions for reverse engineers.. having its own tool, helps, at least, to save money in licensing (assuming they are using or planning to use Ghidra to do that)
- cies 5y ago> Besides, if the NSA really wants to install some software on your computer, they can probably do it themselves without your involvement. Running Linux with very few binblobs, I expect they will not be able to. Running any OS published by $tax_evading_big_corp, I expect they can.
- imwillofficial 5y agoHave you seen the crazy stuff the NSA does?
- cies 5y agoLink please? I know they collect data, and have Windows backdoors.
- imwillofficial 5y ago> Documents obtained by Der Spiegel reveal a fantastical collection of surveillance tools dating back to 2007 and 2008 that gave the NSA the power to collect all sorts of data over long periods of time without detection. The tools, ranging from back doors installed in computer network firmware and software to passively powered bugs installed within equipment, give the NSA a persistent ability to monitor some targets with little risk of detection. While the systems targeted by some of the “products” listed in the documents are over five years old and are likely to have been replaced in some cases, the methods and technologies used by all the exploit products could easily still be in use in some form in ongoing NSA surveillance operations. https://arstechnica.com/information-technology/2013/12/inside-the-nsas-leaked-catalog-of-surveillance-magic/ https://arstechnica.com/information-technology/2013/12/insid... Reading their processes is so fascinating.
- kaba0 5y agoRunning linux* that has basically no security at all, good luck! A rouge extension/bash script can install whatever backdoor it wants without problem. * under linux I mean mainstream distro here. Unless you use qubes os, it will not have good sandbox, everything runs as your user and can easily modify eg. .bashrc and start up a key logger to get sudo password.