Ask HN: Is there any defense against LLM-based reverse engineering?

Recent news headlines [1] about LLM-based reverse engineering make it seem that anyone with a monthly subscription is capable of translating any executable into an equivalent source code representation.

If this is true, then how can one guard against having their source code essentially unveiled with the correct semantic meaning of the underlying algorithms by someone with an extremely low amount of effort? I bet that using obfuscators would still not be enough.

I'm distinguishing between recreating the source code of your software vs vibe coding an inexact clone without knowing your source code (which is not exactly reverse engineering).

Example: Imagine it would be possible to faithfully recreate the source code of the firmware running on a foreign military device, even with correct semantic meaning of variables, functions and of the whole algorithm. On the other hand, vibe coding a clone would require that you know the underlying algorithm (or at least that you have a high-level idea of how does it work), which you don't have for such device.

Does it mean that companies like Denuvo are now out of business (assuming anything can be reverse engineered with the correct semantic meaning)?

[1] https://news.ycombinator.com/item?id=50028275

2 points | by semidror 1 hour ago

3 comments

  • ThrowawayR2 47 minutes ago
    For the firmware case specifically, some embedded processors support encrypted, signed firmware and encrypted memory. The physical defenses of the processor would need to be defeated to recover the unencrypted binary. That's not impossible (defeat of protections on game consoles being an example) but it would take physical access to the hardware and specialized tooling to even attempt.

    Maybe that's a possible future? Chips are not that expensive compared to the price of an app so each app can come on its own SOM in a cartridge to run its core logic. The computer just serves as a terminal and auxiliary compute server to the app cartridge.

  • ben_w 1 hour ago
    Patents and copyright.

    Turning a binary into source code that would compile into an identical-to-the-bit binary seems like it would be a copyright violation (caveat: IANAL).

    Even an imperfect copy would (again, IANAL) sound to me like a patent law question.

  • toomuchtodo 1 hour ago
    Interested and following as someone wanting to maximize reverse engineering capabilities.
    • semidror 1 hour ago
      IMO it's a double-edged sword. What if, as a direct consequence of the new RE capabilities, there eventually won't be any new "juicy" binaries to decompile because every important piece of software will run on a company's server while you will have just a thin client (as someone pointed in [1])?
      • ben_w 1 hour ago
        Even remotely.

        At a certain point, an AI looks at what the software does and figures out what functions would produce the observed results.

        If it turns out to be different to the original, but stil gets the job done, how often will the distinction matter?

        • toomuchtodo 1 hour ago
          This is the way.

          “Computah, replicate target system. Use whatever resources are required to build requirements and specs, ship to software factory when necessary.” Whenever models and harnesses improve, improve reverse engineering accordingly.