Skip to content
DevMeme
5433 of 7590
Security Post #5956 · source on Telegram

The Security Expert's Selective Outrage

Description

A two-panel Wojak meme format contrasting a developer's software choices. In the top panel, a calm, bearded Wojak character with glasses is shown next to the logos of Microsoft, Apple, and Google Chrome. A caption below reads, '> I would never use NSA made software', expressing a principled stance against corporate software potentially compromised by the National Security Agency. In the bottom panel, the same character transforms into an excited 'Soyjack' with an open mouth and enthusiastic pose, looking at the logo for Ghidra, a software reverse engineering tool. The joke lies in the hypocrisy: Ghidra is a powerful, popular, and open-source tool that was developed and released by the NSA itself. The meme humorously points out the selective pragmatism within the security and developer communities, where the utility of a great tool can override concerns about its origin

Comments

23
Anonymous ★ Top Pick My threat model is simple: I avoid any software that might have an NSA backdoor, unless that backdoor comes with a free, best-in-class decompiler
  1. Anonymous ★ Top Pick

    My threat model is simple: I avoid any software that might have an NSA backdoor, unless that backdoor comes with a free, best-in-class decompiler

  2. Anonymous

    “Zero-trust until the NSA slaps an Apache-2 license on GHIDRA - then every security engineer hits ‘brew install ghidra’, because a license header totally counts as a security audit, right?”

  3. Anonymous

    After 20 years of avoiding NSA backdoors in commercial software, we collectively lost our minds when they open-sourced a world-class reverse engineering suite - proving that the only thing stronger than our privacy paranoia is our love for free enterprise-grade tooling that would otherwise cost five figures

  4. Anonymous

    The beautiful irony: developers who refuse NSA-developed tools while running closed-source operating systems that phone home daily with telemetry. At least with Ghidra, you can audit exactly what the NSA wrote - unlike that proprietary blob you're using to read this. Sometimes the devil you can inspect is better than the angel you can't

  5. Anonymous

    Everyone’s threat model bans NSA binaries; procurement approves the free, auditable decompiler with SLEIGH and headless mode - zero trust until the price tag hits $0

  6. Anonymous

    Irony level: expert - using NSA tools to hunt backdoors in everyone else's telemetry

  7. Anonymous

    My threat model says “never run NSA software” - except GHIDRA under Apache 2.0; apparently the only government app we trust is the one that lets us stop trusting everyone else’s binaries

  8. @ZgGPuo8dZef58K6hxxGVj3Z2 2y

    Fr I know Ghidra has at least 20 different hidden expoits to backdoof your SoC/UEFI

    1. @Saeid025 2y

      Just saying or there is actual proof?

      1. @ZgGPuo8dZef58K6hxxGVj3Z2 2y

        No proof thats what I heard. Msg below states otherwise. Probably more accurate than what I said

    2. @endisn16h 2y

      how, where? so never use decompilers on main, thats silly

      1. @ZgGPuo8dZef58K6hxxGVj3Z2 2y

        Lmao

        1. @endisn16h 2y

          it true tho, always use protection💋 also kvm my beloved 🫶

          1. @ZgGPuo8dZef58K6hxxGVj3Z2 2y

            💀💀💀

  9. @anatoli26 2y

    What’s chidra?

    1. @purplesyringa 2y

      It's Ghidra. A reverse-engineering and decompiler tool developed by NSA

    2. @ZgGPuo8dZef58K6hxxGVj3Z2 2y

      Ghidra leaked NSA decompiler/reverse_engineering tool that they used to find vulnerabilities in software so they could later use those to get access to whatever they needed/wanted where they weren’t able to force software/service owners to backdoor or monitor. For example Software/Service owned by Asia, Europe, or dark web…

      1. @purplesyringa 2y

        Is it leaked though?

        1. @purplesyringa 2y

          It's open-source now, was it maybe closed historically?

        2. @chupasaurus 2y

          Never was. It was mentioned in the first part of Vault7 leak, but even it's name never was a state secret. NSA took effort to declassify the code to publish it 2 years later.

      2. dev_meme 2y

        Wdym leaked? They literally open sourced it

        1. @ZgGPuo8dZef58K6hxxGVj3Z2 2y

          F

  10. @endisn16h 2y

    nsa developed selinux btw

Use J and K for navigation