|
|
|
|
|
by Grothendank
1173 days ago
|
|
Is ghidra safe to use if you consider the NSA an adversary? Every person I've asked this question has had their noses so far up the NSA's pooper that they could not imagine considering the NSA an adversary. But suppose you were running a malware honeypot operation for the CCP. Would you still use Ghidra? Why or why not? And please don't pass the buck and say, "I probably wouldn't be allowed to use ghidra" or "I'd probably use whatever my CCP handler told me to use" or "I wouldn't be working for the CCP in the first place." That does not inform me about the security risks of using ghidra with the NSA as an adversary. |
|
So your thinking is: yes, this is the crowd we'll attempt to insert backdoor java code.
Okay fine you still don't trust them? Run in a VM without network connection. What security risks/threat are you even talking about?
And yes people have heavily audited the source. You either trust the community catches thing or not. I'm the end of your still tin foil about it, don't use, nobody cares.