Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Has anyone RE'd ghidra using another decompiler to determine whether it hides NSA backdoors etc?


> RE'd ghidra

What, like, read the source code [1] or reverse engineered a binary? Would be easy(ish) to tell if the code in the binary was different from the source, probably.

[1]: https://github.com/NationalSecurityAgency/ghidra


Being a large open source project is an even lower standard of transparency than a formal NIST review of a very small codebase, from which the NSA was able to hide at least one backdoor. It wasn't until use in the wild for decades revealed the ECC magic number that this vulnerability was uncovered [0].

Similarly RE has a way of investigating the actual functioning of code in a way more thorough than a human tasked with hunting for an intentionally obfuscated defect (if even any human has undergone that process)

[0] https://jiggerwit.wordpress.com/2013/09/25/the-nsa-back-door...


Its open source. No RE necessary.


Plenty of encryption algorithms created by the NSA were also public and contained backdoors.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: