Hacker News new | ask | show | jobs
by fatdog 3492 days ago
Great honeypot as well. If a malware analyst dumps one of their intelligence agency canary strings from one of their spyware packages, they can use it to track the discoverer.

If I were a spook, I would totally be releasing reversing tools that alerted on my encoded code words.

2 comments

That's why you fetch the ZIP from Github here: https://github.com/gchq/CyberChef/tree/gh-pages

Then you download it, and open it in a sandbox VM with no Internet access

If I were a spook doing this, I wouldn't release it on the official GCHQ github organisation.