3 ms·
Ghidra is just better overall now. Full stop. IDA still does some things better, but Ghidra is a great tool and most people still on IDA are there because of th
by bitexploder 4y ago
Ghidra is just better overall now. Full stop. IDA still does some things better, but Ghidra is a great tool and most people still on IDA are there because of their existing tooling, scripts, and experience with the software. Starting from scratch, Ghidra would win. Been using IDA for like 16 years now.
- Beached 4y agoooof, ghidra is great because it is free and works, but I wouldn't call it better. I'd still choose ida or binja over ghidra for work. IDC about license cost, I care about ease of use, and binja wins on ease of use for me (and. alot of people I talk to)
- rjzzleep 4y agoI think a lot of the people that say how much better ghidra is, just started reversing and use the decompiler a lot. The workflow and UX of IDA is so much better. I guess there are a lot of people that just click around in the UI but for a keyboard based workflow, Ghidra has a lot of catching up to do even to IDA 4.x.
- blincoln 4y agoI've been doing RE work off and on for about twenty years. IDA is a solid tool with some really neat features[1], but the only reason I use it anymore is if I need to look at a binary that's for an architecture so obscure that Ghidra doesn't support it yet. I like Ghidra's interface better, but I'm also not a keyboard-first type of user. I work with a lot of different OSes and software. I stopped trying to remember most keyboard shortcuts 10+ years ago, because there were too many variations, and the consequences of using the wrong one can be dire. Releasing and open-sourcing Ghidra was a truly magnificent gift by the NSA, and I can't thank them enough for it. [1] I'd love to see a Ghidra equivalent of Lumina, for example.
- kuroguro 4y agoThere's an open source Lumina server, writing a plugin for Ghidra wouldn't be too difficult, here's some details on how they hash functions: https://github.com/naim94a/lumen/issues/2 https://github.com/naim94a/lumen/issues/2
- bitexploder 4y agoI have not done it full time, but I find IDA is only useful for niche processors and out of the way things. I have still done it deeply and consistently for the last 16 years. For day to day use Ghidra is just better for me and I went pretty deep into the IDA well with tooling and Python scripting. Decompiler, yes, but it really depends on what features you need and what processor architectures you are reversing. IDA is still the most versatile and indispensable for some tasks, but that is not the majority of my work or interests these days and when it is, right tool, right job, etc. Arguments of keyboard/mouse efficiency are dead to me. The limiting factor of any reverse engineering is definitely not how efficiently you can keyboard navigate a UI. People are too in love with efficiency of the wrong things and not what the real limiting factors of reversing are, which is comprehending the program. I don't love clicking around but it has never once slowed me down on a project.
- bitexploder 4y agoStuff like IDA refusing to have an undo feature and other dumb stuff until the market forced them to. No reason for it, just Ilfak's insistence on an outmoded philosophy of software design that does not benefit users. I do like Binja but Ghidra is free and works. I think Binja has the edge on the highest end features now. I have and use both. I like getting a second opinion on disassembly anyway. Some times they are just wrong and one tool catches something another doesn't. Can't count the hours lost to poor disassembly. Correctness is probably one of the most important features of any disassembler and reverse engineering tool.