IDA Home is coming
hex-rays.com
hex-rays.com
Ghidra is absolutely amazing - I've been using it since release and it's been a huge breath of fresh air compared to the hot mess IDA is. Ghidra has great APIs, which are really well documented. It has a very powerful decompiler. It comes with a built-in, programable emulator for every platform! It has a built-in way to do collaborative reverse engineering! And it's super easy to modify the Sleigh if there's something that needs tweaking to improve the decompiler output!
Not to mention, adding your own CPU is reasonably simple - all you have to do is write a "Sleigh" description of your architecture (basically map CPU instructions to PCode) and it gives you the disassembler, decompiler, and emulator for free.
This is quite unbelievable for me. Granted, a home user could reasonably only use one of these and be fine. But in the face of Ghidra's processor support, this is laughable.
I noticed earlier this week that there is a forthcoming book from NoStarch about Ghidra. There's a sample chapter available in case anyone is interested:
You haven't been able to work-around that have you?
https://www.youtube.com/watch?v=8U6JOQnOOkg
Tl;dr - press Ctrl+Shift+G on the instruction you want to modify and it will outline the instruction in red, allowing you to modify it.
That being said, it doesn't work for all architectures, and Ghidra will pop up with a rating box when you press Ctrl+Shift+G, explaining the compatibility/support for your current processor (for example, amd64 binaries are considered a "GOLD" rating, meaning there's an extremely high chance of your modification working correctly)
But the biggest problem is, exporting a runable binary is not currently supported by Ghidra. Ghidra has a Binary Export function, but it's used as a sort of memory dump. It won't try to make a runnable program. This is by design, see issue #19[0]. It will probably work for RAW images, but that's it.
Exporting a runnable binary is a highly desirable feature, though I can't find any issue tracking it. There's an open PR, #1505[1], that might provide people what they need.
[0]: https://github.com/NationalSecurityAgency/ghidra/issues/19#i...
[1]: https://github.com/NationalSecurityAgency/ghidra/pull/1505
The amazing thing about Ghidra is that all of its tools (disassembler, emulator, decompiler) work on P-Code, which is Ghidra's IR. All you have to do to get the tools to work is write a Sleigh file, which basically describes the registers, address spaces, and map the instructions to P-Code. This is dead easy to do, and with very little tweaking, gives really clean decompiler output. A friend of mine implemented Nvidia Falcon support to Ghidra in a week-end or two[0].
As far as built-in processor goes, Ghidra has X86 16/32/64, ARM/AARCH64, PowerPC 32/64/VLE, MIPS 16/32/64/micro, 68xxx, Java / DEX bytecode, PA-RISC, PIC 12/16/17/18/24, Sparc 32/64, CR16C, Z80, 6502, 8051, MSP430, AVR8, AVR32, and variants of these processors. I dunno if IDA has more, but it's still far from AMD64 centric!
Ghidra is very useful for reverse engineering video games and all related technology! There are blogs showing how to do it:
Initially, most students and home users I knew used a cracked copy because there was no way in hell any of the students I knew had a spare $500 to pay for an IDE.
JetBrains seemed to realize this so first, they made a "self purchase" option that was half the price (or less) and belonged solely to the developer that bought it, with the caveat that they had to use their own funds. It could be used commercially too - this was the option to take if your boss couldn't be convinced to buy you a commercial license and you still wanted to use it legally.
Next, they made their tools free for people working on open source projects.
Then they made a version that had almost all the features available for free (it may have originally been only for non-commercial use but it's fine to use commercially now).
Then they worked with Google to make their free tool the default for Android development, which added many more users.
Then they switched to a monthly licensing scheme that was about $12 a month for a single product (while retaining the ability to outright buy a copy if you wanted to).
Almost everything that IntelliJ does is possible with open source competitors, but I still pay for it because of the level of polish they apply to each feature and the intuitiveness of each feature.
I think that if a $12/month copy was available initially, the number of cracked copies being used would have gone down dramatically.
EDIT: Photoshop did something similar. NO ONE I knew that used it for home use had a real license because it was so damn expensive, but I know plenty of people paying $15/month or so for access.
[1] https://github.com/radareorg/radare2
[2] https://github.com/radareorg/cutter
$365 per year is still prohibitive for most hobbyist/home use. I was hoping it'd be $100 one-off, or $60 per major release + 2 years of updates, or something like that.
That should allow them to regain some popularity with hobbyists, whilst still making the bulk of their money from the BigCorps paying $$$ for a commercial license.
In any given month, it's likely I'll end up disassembling x86-64, AArch64, and MIPS at the very least; that would cost me nearly $1200/year to do that as a hobbyist using IDA Home, or $0/year with Ghidra. For me, there's huge value in the muscle memory I've built with IDA, and generally I get my job to pay for a license, but the odds of me still using it in 2025 are quickly dwindling to zero. They need to make a big, big change or they're going to lose all of us.
My problem with IDA Pro isn’t even the license cost. It’s the licensing unfairness. Costs get multiplied a bunch of times if you want to work across multiple host OSes or want both 32 bit and 64 bit decompilation for an architecture.
I’m sure they know this stuff drives away home users, hence IDA Home. Where they miss, is what home users do. Home users do everything. I’ve seen people using Ghidra with 8-bit processors.
I don’t imagine things will continue to work out well with this strategy if Ghidra gets support for debugging and continues to receive improvements for its decompiler. Ghidra is already immensely useful today.
[1] https://github.com/NationalSecurityAgency/ghidra/issues/24#i...
The core point made regarding why IDA is a superior product despite license unfairness is vendor support. However, the authors seem to miss that the target audience of IDA are tinkerers, who would be fine with fixing their own tools as long as the issues are only on the surface.
Hex-Rays is not Oracle, who can afford to live from license unfairness because their product is embedded deeply into the livelihood of so many large companies. Hex-Rays provides just a tool, which I have already replaced by Cutter with Radare2 and Ghidra's decompiler in my workflow.
I would not use IDA Home even if it was free due to its limitations and lack of Hex-Rays' Decompiler.
[1] https://www.hex-rays.com/products/ida/compelling-reasons-to-...
It is literally shit-talking their own product.
> Isn’t IDA an aging software?
> Doesn’t it have shortcomings?
> Or structural limitations?
> Also… It’s closed source, right?
> And how about its high price tag?
> Well sure [...]
I didn't have half of these preconceptions before reading this page.... but now I do.
"Well, sure, but" isn't something you see every day in a competitive context...
They should release a free home version with mostly the same features (especially Hex-Rays, nobody uses IDA without it) and just prohibit commercial use in the terms of use. The kind of companies that already shell out tens of thousands every year for IDA licenses will happily oblige by the "no-commercial-use-with-the-home-edition" terms... If you want to curtail feature set then make a compelling set of features for enterprises (e.g. builtin collaboration, annotation sharing, fuzzy function search) and then make that exclusive to the commercial version, not the decompiler. Just my two cents...
And then they changed their model so that IDA Free was a horribly gimped version that was useless: no save support, no scripting support (so you can't use it in other projects that use IDA for the disassembly parts), and it shuts itself off after a short amount of time.
This was pre-Ghidra's release obviously, so I looked around for disassembler and came across IDA. I couldn't find a student version, so I actually emailed them asking about it.
The answer I got was a prompt, but terse, "No, sorry.".
I always wondered, how do you expect to gain mind-share if you won't even throw an undergrad a trial license? Regardless, it looks like Ghidra is eating IDA's lunch and at $365/year this doesn't seem like an adequate response.
Every specialized field should have gold standard open source software like this. Companies could avoid paying hundreds of thousands per year in license fees if only they pooled their resources and hired programmers to implement common technology everyone could use.
It sounds like this field will have it soon with Ghidra.
I concede it was more accessibly priced than e.g. IDA but it's definitely a shame HexRays and others aren't as willing to allow non-commercial educational use. I think they'd benefit in the long run, you'd definitely have some folks using the products they're familiar with commercially after a few years.
Meanwhile for software development, you have companies like JetBrains and GitHub offering premium products completely free of price.
> Thank you for your interest in Hopper. Yes, I usually offer a 20% discount to students. If you are still interested, please let me know, and I’ll prepare an invoice for you.
But that said, I'm still pretty wary about IDA's sales process. There seems to be many negative stories, talking about what a frustrating & arbitrary experience it has been in the past. If even Tavis Ormandy is being treated poorly, that doesn't give me much confidence as a prospective Home user. Hopefully things will have improved substantially!
And then there's little things like Linux and Windows licenses being sold separately, so I have a choice between running IDA in Wine, or almost doubling the price I'm being quoted.
But still, I think this is a very promising move! And the price might seem high for hobbyist use now that there are very high quality free alternatives, but compared to the previous high four digits quotes it's practically a bargain =]
Let's see where this goes.
Yeah, I got bit. https://news.ycombinator.com/item?id=19316240
Hopefully the site redesign means they've given other parts of their sales process some love, too: in particular, their self-service tool and their policy of forbidding people from registering personal licenses to personal emails.
EDIT: Looks like I got a reply from ilfak himself, but it was 6 days later and I didn't see it. If anyone from hex-rays is listening, here's a subject line with some order numbers in it: "Hex-Rays Invoice 2016-2240 orderID: (my-last-name)_4732_20160515". My email is (HN-username)@gmail. I never did get that license working, I'd greatly appreciate a reset.
I find it strange to imply that a RE hobbyist would use this software every single day.
https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...
https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...
Edit: well, this thread is unusually good, so maybe we'll relax the objection this time.
Though I don't see this recapturing the casual reverse engineering market that Ghidra ate for lunch unless they have very compelling IDA Home pricing for the decompilers as well (the “One processor family of choice from the most common processors: PC, ARM, M68K, MIPS, PPC” statement is kind of vague about that).
Can we just switch to . everywhere already.
That means there is a standard way of doing it, it just depends on your language. If you were speaking German you'd also write 30,00$ and not $30.00. All of that said, I agree that the inconsistency with all other units is weird and unnecessary, but languages just are that way sometimes.
[1] https://publications.europa.eu/code/en/en-370303.htm#positio...
Crackers are using those tools for sure, but there are many legit use-cases, like security research and malware analysis. Heck, I also use IDA as a debugger for my own programs sometimes, as they tend to give a lot more information with very little configuration compared to GDB/LLDB.
And then I did it a couple more times for other people.
So evil. I should be ashamed of myself!
In all of those cases modifying the disassembled executables is not an option (both legal and must work with original installs), but was invaluable in creating workarounds on the server side. It would be simpler to submit patches to the original vendors but enterprise companies generally ignore them or put them on the back-burner for some unspecified future release.
When I was into that stuff many years ago, it was a bit of "rite of passage" to crack IDA yourself.