The Security Expert's Selective Outrage
Description
A two-panel Wojak meme format contrasting a developer's software choices. In the top panel, a calm, bearded Wojak character with glasses is shown next to the logos of Microsoft, Apple, and Google Chrome. A caption below reads, '> I would never use NSA made software', expressing a principled stance against corporate software potentially compromised by the National Security Agency. In the bottom panel, the same character transforms into an excited 'Soyjack' with an open mouth and enthusiastic pose, looking at the logo for Ghidra, a software reverse engineering tool. The joke lies in the hypocrisy: Ghidra is a powerful, popular, and open-source tool that was developed and released by the NSA itself. The meme humorously points out the selective pragmatism within the security and developer communities, where the utility of a great tool can override concerns about its origin
Comments
23Comment deleted
My threat model is simple: I avoid any software that might have an NSA backdoor, unless that backdoor comes with a free, best-in-class decompiler
“Zero-trust until the NSA slaps an Apache-2 license on GHIDRA - then every security engineer hits ‘brew install ghidra’, because a license header totally counts as a security audit, right?”
After 20 years of avoiding NSA backdoors in commercial software, we collectively lost our minds when they open-sourced a world-class reverse engineering suite - proving that the only thing stronger than our privacy paranoia is our love for free enterprise-grade tooling that would otherwise cost five figures
The beautiful irony: developers who refuse NSA-developed tools while running closed-source operating systems that phone home daily with telemetry. At least with Ghidra, you can audit exactly what the NSA wrote - unlike that proprietary blob you're using to read this. Sometimes the devil you can inspect is better than the angel you can't
Everyone’s threat model bans NSA binaries; procurement approves the free, auditable decompiler with SLEIGH and headless mode - zero trust until the price tag hits $0
Irony level: expert - using NSA tools to hunt backdoors in everyone else's telemetry
My threat model says “never run NSA software” - except GHIDRA under Apache 2.0; apparently the only government app we trust is the one that lets us stop trusting everyone else’s binaries
Fr I know Ghidra has at least 20 different hidden expoits to backdoof your SoC/UEFI Comment deleted
Just saying or there is actual proof? Comment deleted
No proof thats what I heard. Msg below states otherwise. Probably more accurate than what I said Comment deleted
how, where? so never use decompilers on main, thats silly Comment deleted
Lmao Comment deleted
it true tho, always use protection💋 also kvm my beloved 🫶 Comment deleted
💀💀💀 Comment deleted
What’s chidra? Comment deleted
It's Ghidra. A reverse-engineering and decompiler tool developed by NSA Comment deleted
Ghidra leaked NSA decompiler/reverse_engineering tool that they used to find vulnerabilities in software so they could later use those to get access to whatever they needed/wanted where they weren’t able to force software/service owners to backdoor or monitor. For example Software/Service owned by Asia, Europe, or dark web… Comment deleted
Is it leaked though? Comment deleted
It's open-source now, was it maybe closed historically? Comment deleted
Never was. It was mentioned in the first part of Vault7 leak, but even it's name never was a state secret. NSA took effort to declassify the code to publish it 2 years later. Comment deleted
Wdym leaked? They literally open sourced it Comment deleted
F Comment deleted
nsa developed selinux btw Comment deleted