11 ms·
> BinDiff: you can't patch software without disclosing vulnerabilities That’s why Microsoft has been obfuscating its binary builds for at least the last two de
by sedatk 5mo ago
> BinDiff: you can't patch software without disclosing vulnerabilities
That’s why Microsoft has been obfuscating its binary builds for at least the last two decades so that even the two builds from the same source would produce very different blobs.
- wglb 5mo agoHow are they obfuscated?
- dataflow 5mo agoSounds dubious, do you have a citation? The disassembly looks very straightforward for a lot of Windows code.
- sedatk 5mo agoThey're not encoded, but the code blocks are shuffled. That's why disassembly does look straightforward, but it used to thwart BinDiff at the time.
- dataflow 5mo agoWhat made you believe this is the case? any examples/links/etc.?
- j16sdiz 5mo agoIf I understand correctly, that is just randomness comes from parallel compiling and linking. If you saying there is a whole step just scrambling blobs, i will be very surprised.
- shakna 5mo agoThat sounds a lot like US9116712, but I don't think its ever been publicly said that Windows does this.
- prezk 5mo agoAll the while, Linux is going towards reproducible builds (Debian just announced it as a policy). This is of course the only sane way for FOSS, and, I believe, the only sane long term approach in any case. Security by obscurity, while not worthless, is just a thin mitigation layer. By the way, build-time randomization is ineffective in light of AI analysis---it needs to be per-binary-run, in the style of KASLR.