logoalt Hacker News

dataflowtoday at 1:11 AM1 replyview on HN

Sounds dubious, do you have a citation? The disassembly looks very straightforward for a lot of Windows code.


Replies

sedatktoday at 2:19 AM

They're not encoded, but the code blocks are shuffled. That's why disassembly does look straightforward, but it used to thwart BinDiff at the time.

show 3 replies