Do people trust Ghidra? How come it’s been developed by the NSA? From an outsider perspective, that sounds so weird!

Thanks in advance to anyone able to enlighten me!

  • Skull giver
    link
    fedilink
    720 days ago

    I think the NSA would be rather foolish to distribute their malware to the exact target audience that’d be the first to figure out they’re infected.

    The NSA serves to protect the USA, and giving security researchers the tools necessary to identify and reverse engineer malware fits perfectly within that goal. You can try to region lock that stuff, but the NSA isn’t stupid enough to think that’ll help.

    If they want to hack you, they have much less obvious ways to get in. This is the organisation that adds PCBs to shipped computers and reflashes motherboard chips to hack targets.

    Their real targets wouldn’t be running NSA software anyway, not without a deep dive into the closed off parts of the program.

    Also, there’s no real alternative. There’s radare2 and IDA, and that’s about it really. Radare is an open source project that the could just as easily insert malware into, and IDA costs a ridiculous amount of money.