HNHacker News
TopNewBestAskShowJobs

mumbel

4 karma · joined December 4, 2022

submissionscomments
mumbel··on The complex history of the Intel i960 RISC processor
https://github.com/mumbel/ghidra_i960

Added basic support for i960 in ghidra. Didn't have use myself, but some of the Sega model 2 seemed interested. To some degree I think they used it for some of the House of the Dead remake

mumbel··on The legend of “x86 CPUs decode instructions into RISC form internally” (2020)
And now MIPS, the company, makes RISC-V
mumbel··on The legend of “x86 CPUs decode instructions into RISC form internally” (2020)
Got interested in amd29k for about a week before finding something else to mess with. Quick attempt at ghidra support, but never really RE'd with it, so no clue how does on larger projects.

https://github.com/mumbel/ghidra_a29k

mumbel··on NSA Ghidra software reverse engineering framework
Compiler (gcc) and maybe assembler (as) are used. I think the other binutils executables are unused but still built-in to their logic. Due to it's age and being removed from gcc, I was unable to cleanly setup pcodetest for 80960 (had to hack it all together and scripted their java portion to work with hack), but was super useful for improving tricore (pcodetest wasn't released when I submitted original PR) and writing risc-v.
mumbel··on NSA Ghidra software reverse engineering framework
Pcodetest is more about validating the implementation of the instruction, sure it has to decode, but the benefit is most a base level set of logic that can be emulated. And definitely not a fan of the setup to get it going (also only helpful if you have a semi recent C compiler)
mumbel··on NSA Ghidra software reverse engineering framework
It's pretty dumb this continues to come up years later. You're the NSA delivering source code to the cyber security community. The exact community that: doesn't immediately trust NSA, knows how to find bugs, would love to find any sort of bug in their code (regardless if malicious), people you want to apply for your jobs, people you partner with (academia/other govt orgs/other country cyber security groups).

So your thinking is: yes, this is the crowd we'll attempt to insert backdoor java code.

Okay fine you still don't trust them? Run in a VM without network connection. What security risks/threat are you even talking about?

And yes people have heavily audited the source. You either trust the community catches thing or not. I'm the end of your still tin foil about it, don't use, nobody cares.