115 points modinfo 2 hours ago 21 comments

OsrsNeedsf2P 1 hour ago | parent

Oh I'll be trying this out for the OpenBFME project!

mb7733 1 hour ago | parent

> Copy this into your coding agent:

> Install REA and connect it to this coding agent using npx rea-agents@latest setup. Show me the setup plan for approval, then verify the installation.

We have achieved the next evolution of installation by `curl | bash`!

Neywiny 1 hour ago | parent

I mean to be fair right under it they give you the command if you want to run it on your own. But yeah

sergiotapia 1 hour ago | parent

You're right it's much safer to click next > next > next > next > finish.

carsoon 39 minutes ago | parent

Yeah installation has always been such a security issue. So many programs are just random links that download a file. You have to trust that the host has not been compromised all packages that were used to build it were not compromised etc.

With ai models getting better we may be able to do analysis on the actual underlying bytes of the files we download to properly scan them for malicious code patterns and build systems which sandbox programs and watch inbound and outbound traffic/ system level actions from them and flag suspicious requests for further analysis by smarter models.

REA shows that ai are very good at understanding low level code and reverse engineering it so this could potentially be applied to application level security aswell.

t-writescode 28 minutes ago | parent

A big difference between the safety of "next > next > next > finish" and "curl | bash" is one of them is dynamically loaded from an external source that could change between runs, and the other can be fully downloaded and vetted in a single check, and then once it's safe, it's probably safe 10 years from now.

nailer 5 minutes ago | parent

Every download of a piece of software could be unique.

ethin 1 hour ago | parent

I might be missing something but... How exactly is this better than telling Claude for example to "install and set up a full RE environment including Ghidra" on my local system and get to work? Like what does this do that my current RE methodology doesn't?

tptacek 1 hour ago | parent

Everybody has their own set of skills and specific scripts and tools to do this stuff. You might use Ghidra as the the kernel of those workflows, but you still want something more than just Claude freestyling, at least for now.

(Who knows if this'll be true 6 months from now.)

djmips 1 hour ago | parent

I don't think it is better than just doing it yourself in Claude Code (in fact worse) but some people like cute UI for everything I guess.

fwlr 36 minutes ago | parent

Probably it is not better. I think this is aimed at people who do not have a “current RE methodology”, do not know enough to specify things like Ghidra, etc., but who do have a desire to feel like they reverse-engineered and can reliably predict that a conversation with a chatbot will make them feel that way.

areoform 1 hour ago | parent

I love such work. I hope to roll it into a package that anyone can use in the future. This work is only going to get more important because frontier models getting locked down will make this a lot harder over time.

For example, I use Claude as a bouncing wall for my thoughts and I pointed out that,

    > GLM 5.2 was the only thing that helped HF while the agents were trying to access them. The "guardrails" stopped them from doing good. The Computer Fraud and Abuse Act exists. Courts exist. And computers and an internet connection have existed for a long time. There's also 17 USC 1201 provisions with the 1201 a 1 exemptions [Image #31] so in this case, a farmer should be able to work with you to access the tractor they own. Or... IDK... a kindle that's out of date? :) What is lawful and what isn't is rooted not within the act but within intent, purpose and mens rea. And this is something the law has been deciding for centuries now. At one end, your maker can't say that governments should decide while at the other end explicitly refusing to allow governments to be the ones who decide.
This was rejected for "Safety,"

    > Opus 5.5's safeguards flagged this session. You may be seeing this for the first time on an Opus model: Opus 5.5 is more capable and has stronger safeguards as a result, which can sometimes flag non-cybersecurity work. We're improving these safeguards to reduce the amount of incorrectly flagged messages. Edit and retry, or continue with Opus 4.8. Send feedback with /feedback or learn more: https://support.claude.com/en/articles/8106465 
    >
    > Details: "[cyber]'
Note, the image here was the Library of Congress' page on DMCA exceptions.

Fundamentally, the idea that you can't reverse engineer things, make things, learn about biology or physics without permission is strange to me. These machines have been trained on the sum intellectual output of humanity, the global intellectual commons, and are being used to close off that commons?

I would be OK with their right to create such restrictions if they weren't lobbying the Government to restrict others, thereby ensuring that they control humanity's intellectual commons well into the future.

Perhaps I'm naive, but I think it's better for humans and the machines if we can all think, learn and build. But then again, I'm the kind of person who rejects the doomer pill.

TheSamFischer 37 minutes ago | parent

Yay, all software will be open…Except the models.

LoganDark 7 minutes ago | parent

I wanted to see if CVP approval changed this response, but it appears that with the release of Opus 5.5, Anthropic silently dropped me from the program, and has some strict new criteria in place to apply again (such as being credited for a CVE). I was only approved last month, too -- sad!

MiroslavPokorny 1 hour ago | parent

Thanks for sharing and making this open source. Starred and followed

cedws 52 minutes ago | parent

What makes this better than just giving an agent radare2?

epsteingpt 32 minutes ago | parent

Morluto is a legend.

Started in the repoprompt (https://repoprompt.com/) community.

Good stuff.

rvz 20 minutes ago | parent

Now there is no excuses to reverse engineer the most notorious closed source binaries out there including from Nintendo's software to CUDA from Nvidia and make it all "open source".

The only problem is the lawyers from all those companies will be readying their lawsuits, and given they have tons of money; they do not care.

nirav72 12 minutes ago | parent

I wonder if this is why I've seen a lot videos popping up on my youtube feed related to vibe coded clones of various commercial apps in the past few days. Everything from clones of flagship products from Adob to Microsoft Office.

Adobe product clones like Photoshop and Illustrator: https://www.youtube.com/watch?v=eFB79TYI-Vw

Adobe after effects clone: https://www.youtube.com/watch?v=5mi_tYSdkWQ

MS Office suite clone: https://www.youtube.com/watch?v=U_jTYMOlXio

socializer 4 minutes ago | parent

Probably not, there's relatively little secret sauce to something like Photoshop. It's just a lot of grungy work that, I guess, you can now delegate to an agent if you have enough money and time.

As an aside, I've heard a lot of hot takes about how this is the end of Adobe, but I'm pretty sure it misses the point. The main reason people pay Adobe is because it's a familiar line of stable, well-supported, interoperable, and actively-developed products. There's already plenty of cheaper or free alternatives (Davinci Resolve for video, Capture One / Darktable for raw, Affinity for photo editing and vector drawing, etc), and if Adobe survived that, I sincerely doubt they're going to lose pro customers to a vibecoded app where half the stuff is probably subtly broken or left as a TODO, and that will be abandoned in a week.

nailer 6 minutes ago | parent

Ooh it can recreate old games from executables, I wondering if it can do Motorola MC68010, I want to play Stun Runner in 4K.

https://www.youtube.com/watch?v=tByxdDiRdPM