1) that part might be a little rhetorical, every AG likes good publicity.
NSA Said to Exploit Heartbleed Bug for Intelligence for Years
31–40 of 192 posts
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#32Earlier quoted context omitted.
I don't know how "disastrous" this really is. NSA knows approximately 1 zillion vulnerabilities we don't know about and won't know about. They range from RCE's in Windows and Apache to flaws in cryptographic hash functions. It's NSA's charter to stockpile these things, and, yeah, to use them against foreign adversaries. It's bad though, because this one was so easily exploitable. It's the kind of thing a reasonable o…
> It's NSA's charter to stockpile these things, and, yeah, to use them against foreign adversaries. I don't see how leaving American companies vulnerable fulfills the NSA's charter.
I agree that this bug is different, but that might have been a subtle case to make inside the organization.
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#33This looks like another case where the actions of the NSA are the opposite of what's in the best interest of US Citizens.
Was it though? The NSA's job is to spy on behalf of the country. While keeping the bug a secret put people at risk, there is an argument to be made that it was a useful tool. Law enforcement regularly makes the decision to allow low level criminals to continue to commit crimes in order to catch their leaders even though doing so puts people at risk. There are always tradeoffs.
Who gets to decide whether the risk is acceptable? To whom do we turn to when it's found that their risk assessment was flawed, and we require compensation for their recklessness and negligence?
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#34Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#35Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#36I'm wondering if any State Attorney Generals are tech savvy, don't like the current administration, and want some publicity[1] enough to start an investigation? I would imagine a subpoena asking for the financial records of the OpenSSL contributors would be a first step (to find Gov payments). I can see a very scary witch hunt. 1) that part might be a little rhetorical, every AG likes good publicity.
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#37Evidence? And if so, pretty much what we expected and exactly why this behaviour is terrible
(emphasis mine)
It's pretty weak IMHO but I don't really doubt it.
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#38No fucking way. This is disastrous PR stuff, second only to the Snowden revelations. It should be clear by now that the NSA does not restrict themselves from anything... and should be disbanded.
I don't know how "disastrous" this really is. NSA knows approximately 1 zillion vulnerabilities we don't know about and won't know about. They range from RCE's in Windows and Apache to flaws in cryptographic hash functions. It's NSA's charter to stockpile these things, and, yeah, to use them against foreign adversaries. It's bad though, because this one was so easily exploitable. It's the kind of thing a reasonable o…
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#39> The Heartbleed flaw, introduced in early 2012 in a minor adjustment to the OpenSSL protocol, highlights one of the failings of open source software development.
And its discovery and resolution highlights one of the advantages of open-source software development.