NSA Releases Security Research Tool But Can You Trust It?

4 min read
Curated from forbes.com →

In recent years it has become almost commonplace for leaked National Security Agency (NSA) hacking tools to hit the headlines thanks to being used in attacks such as WannaCry, NotPetya and even the Democratic National Committee (DNC) email breach during Hilary Clinton’s U.S. election campaign. But now the NSA has released an open-source, reverse-engineering, hacking tool, called Ghidra into the public domain itself. The question is, would you trust a security tool developed by spooks?

What is it for?

Perhaps it would be better to first explain what it isn’t for, and that’s hacking into stuff. Well, if that ‘stuff’ is hardware at any rate. This is a reverse-engineering platform so instead it allows security researchers and malware analysts to hack into the code behind the nasty software stuff. Think of it as a magic window into the binary world of software, all the zeros and ones, that translates that installed and compiled code into something that reveals exactly what the software actually does. As Lily Hay Newman, writing for Wired, puts it, security researchers using this tool to investigate malware can “understand how it works, what its capabilities are, and who wrote it or where it came from.” The big question though is can they trust it, given the nature of the NSA beast? During a speech at the annual RSA security conference in San Francisco this week, Senior Advisor for Cybersecurity Strategy to the Director of the NSA, Rob Joyce, insisted that there is no backdoor in Ghidra. “This is the last community you want to release something out to with a backdoor installed, to people who hunt for this stuff to tear apart” Joyce said. I decided to ask around amongst security professionals to see if they were in a trusting mood and, indeed, whether they would be using Ghidra.

Do you trust it, will you use it?

You might be forgiven for thinking, taking the plentiful opinions of security and privacy advocates regarding NSA surveillance techniques into account, that there might be little trust in such a tool from the cybersecurity profession. Forgiven, but wrong. The vast majority of those people I contacted were incredibly welcoming of the Ghidra public release. Take Ian Trump, head of security at AmTrust International, who told me that “there will be folks that will be turned off, it turns out infosec has trust issues, who would have guessed?” However, he also reckons that creating and giving away free professional tools is a non-political gesture which should be applauded and encouraged. “Whatever the case” Trump concluded “this is a gesture which I think is both bold and will be appreciated by the majority of the infosec community.” So, is he right? Chris Doman, security researcher at AT&T Cybersecurity, thinks so. His argument being that there really hasn’t been any competition to the main reverse-engineering tool, IDA Pro, which “can be cost prohibitive and there are hurdles to obtain.” Doman is hopeful that Ghidra may “level the reverse engineering playing field, enabling students and newer security researchers to use a high grade reverse engineering tool.”

The compliments and trust keep coming, this time from Dr Darren Williams, CEO and founder of cyber-security firm BlackFog, who told me that he “welcomes the assistance of the NSA to fight the global effort in identifying and removing bad actors from our devices.” Ghidra shows that the NSA is “serious in working together with industry to solve these very real and potentially very damaging problems” Williams insists. Adding yet another complimentary voice (with a touch of caution) is Ben Herzberg, director of threat research at Imperva. “While this is definitely a positive step from the NSA, we must remember that this release is just the tip of the iceberg” Herzberg says, adding “More importantly, this definitely does not mean that the agency is becoming a transparent organization.

Continue Reading

Enjoyed this summary? Read the complete article at the source:

Continue at forbes.com →

Yves Mulkers

Yves Mulkers is the founder of 7wData and a widely followed voice in the data and AI community. He curates the 7wData and AI Beat newsletters, reaching hundreds of thousands of data and AI professionals, and writes on data strategy, analytics, AI, and the evolving data ecosystem.