Ghidra: Software reverse engineering suite developed by NSA
ghidra-sre.org
ghidra-sre.org
- https://github.com/NationalSecurityAgency
Prior HN coverage is here:
- https://hn.algolia.com/?q=https%3A%2F%2Fgithub.com%2FNationa...
I would be curious if anyone knows what their filter, reasoning, etc - for open sourcing X vs Y. In case of Ghidra, think its existence was originally revealed to the public via WikiLeaks in 2017; might be wrong, but think the software was posted too — for sure though was open sourced two years later in 2019.
NSA is both red team and blue team. This is a blue team tool used by reverse engineers to analyze malware, so it was NSA's little gift to researchers, an agency known for hoarding secrets for our 'security'.
It's also a red team tool for binary exploitation.
EDIT: The cynic in me posits it was used far more for exploit development than for analyzing malware, unless that had offensive applications too. But I don't know anything, I never worked there.
The obvious step 1) Lots of people use & improve ghidra, write plugins etc. It is good now, but in 5 years it could be best in class.
step 2) their biggest & bestest competitor IDA has massively accelerated the rate of their development, engagement & community responsiveness. IDA was this slow moving dinosaur that had good ideas and people that has been poked to life by a proper competitor.
If the NSA wants a robust RE scene, with experience engineers and good tools, then I think they've done themselves a massive favour by releasing and stewarding the development of ghidra as an OSS tool.
For everything I use it for IDA is still well ahead.
I only do x86 work, so maybe in other areas, but I doubt it? The decompiler is getting better, but still has quite a ways to go, the plugin support is way behind, etc etc.
Just as others have mentioned, it can be problematic to even buy IDA Pro, so if Jane Haqor is able to get started with Ghidra and then develops a passion for the space, then that makes Ghidra best for that class, also
> ... plugins that allow for additional functionality (Cryptanalysis, interaction with OllyDbg, the Ghidra Debugger).
We've got the debugger, but I don't think we have the OllyDbg plugin and certainly nothing with cryptanalysis.
Perhaps I lack imagination but I’m having trouble picturing what that could be good for or how it could even be hidden. This isn’t like a crypto constant that you can pretend is random but secretly has known factors.
Also there are only small percent of specialists who even know this tool exist let alone have know-how to use it. And since it heavily used for mailware reverse engineering it's gonna be laughtable to put any "secret backdoors and exploits" in it.
Might be worth it as hacker contest for finding good hiring candidates, but certainly not at spying attempt. No sane person who able to use this software gonna run it on PC containing some important secrets.
Either way, you probably don't want to do binary analysis on a networked computer.
Ghidra: A software reverse engineering suite of tools developed by the NSA - https://news.ycombinator.com/item?id=27818492 - July 2021 (142 comments)
Ghidra 9.2 - https://news.ycombinator.com/item?id=25086519 - Nov 2020 (78 comments)
Ghidra Decompiler Analysis Engine - https://news.ycombinator.com/item?id=19599314 - April 2019 (30 comments)
Ghidra Capabilities – Get Your Free NSA Reverse Engineering Tool [pdf] - https://news.ycombinator.com/item?id=19319385 - March 2019 (17 comments)
Ghidra, NSA's reverse-engineering tool - https://news.ycombinator.com/item?id=19315273 - March 2019 (405 comments)
Ghidra - https://news.ycombinator.com/item?id=19239727 - Feb 2019 (59 comments)
NSA to Release Their Reverse Engineering Framework GHIDRA to Public at RSA - https://news.ycombinator.com/item?id=18828083 - Jan 2019 (90 comments)
Also:
Patching an embedded synthesiser OS from 1996 with Ghidra - https://news.ycombinator.com/item?id=31144106 - April 2022 (32 comments)
Analysis of large binaries and games in Ghidra-SRE - https://news.ycombinator.com/item?id=27972308 - July 2021 (22 comments)
Ghidra Analyzer for UEFI Firmware - https://news.ycombinator.com/item?id=26819673 - April 2021 (23 comments)
Legalizing gay marriage in Crusader Kings III with Ghidra - https://news.ycombinator.com/item?id=26703404 - April 2021 (170 comments)
Using Ghidra to Reverse Engineer Super Monkey Ball for GameCube - https://news.ycombinator.com/item?id=26315368 - March 2021 (64 comments)
A first look at Ghidra’s Debugger – Game Boy Advance Edition - https://news.ycombinator.com/item?id=25553105 - Dec 2020 (14 comments)
Others?
https://github.com/AllsafeCyberSecurity/awesome-ghidra#readm... (and derivatives since GH awesome lists are only as awesome as PRs against them: https://github.com/AllsafeCyberSecurity/awesome-ghidra/netwo... )
1. Show everyone in reverse engineering and cybersecurity community what cool toys NSA have to play with.
2. Make sure there is huge pool of talent trained to work with NSA tools.
3. Get countless contributions towards processors / architecture support, etc.
I guess people who come up with conspiracy theories simply don't know that all around the world there might be like 10,000 good reverse engineering experts. Might be even less of them. It's very small talent pool and it does make sense for NSA to do everything to make hiring easier.
If the reasons presented were actually decisive can of course be questioned.
And yeah he does mention recruitment benefits on second slide.
I think thats part of the reason NSA open sourced the code for it so people could see no backdoor are in there. So in this particular case maybe less of a concern
For example, do they have a surveillance system that remotely monitors or can remotely every Apple’s device (they are all closed source)? If small companies can do it, surely nsa does it too!
Or a system through which they can login to anyone’s account linked to American companies (eg, existence of a software system through which they login to anyone’s Gmail or AWS account when needed, without subpoena or request to those companies).
This basic means complete mass or targeted surveillance. Encryption seems futile against such actors that can hack end points easily.
For mass surveillance, the problem is not technical but more legal. It is almost plain and clear illegal for any agency to do in US to do it on all data so they have to come up with loopholes for things like metadata or risk the agency.
https://www.eff.org/nsa-spying
https://www.washingtonpost.com/world/national-security/nsa-i...
This then brings up the question about intellectual property. How do weaker nations protect their IP on important technologies against more powerful nations such U.S. or China?
This seems to lead to a widening information gap between nations.
This is one of the reasons the 5 eyes nations are in bed together. I'll spy on you if you spy on me.
[0] https://citizenlab.ca/2022/10/new-pegasus-spyware-abuses-ide...