I don't know if Heartbleed could reach this point, but I think probably the only possibility for getting average citizens up in arms about this kind of thing is for them to start seeing major personal detrimental effects (like oops, all my email has been stolen and deleted and my bank account's empty), and then learn that the NSA could have easily prevented it if they weren't having so much fun being super-hackers in…
NSA Said to Exploit Heartbleed Bug for Intelligence for Years
41–50 of 192 posts
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#42Earlier quoted context omitted.
Because NSA didn't try to get Lavabit's keys at all; DOJ did. Two very different organizations. Not as incestuously linked as people think they are. Also, worth mentioning: it's not particularly easy to get private keys out of servers with the bug.
That makes sense, I guess. I'm not American so I don't know much about the inner workings of these institutions. Is it unlikely for FBI to ask NSA's help?
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#43This looks like another case where the actions of the NSA are the opposite of what's in the best interest of US Citizens.
Was it though? The NSA's job is to spy on behalf of the country. While keeping the bug a secret put people at risk, there is an argument to be made that it was a useful tool. Law enforcement regularly makes the decision to allow low level criminals to continue to commit crimes in order to catch their leaders even though doing so puts people at risk. There are always tradeoffs.
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#44Evidence? And if so, pretty much what we expected and exactly why this behaviour is terrible
>> The U.S. National Security Agency knew for at least two years about a flaw in the way that many websites send sensitive information, now dubbed the Heartbleed bug, and regularly used it to gather critical intelligence, two people familiar with the matter said. (emphasis mine) It's pretty weak IMHO but I don't really doubt it.
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#45Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#46This looks like another case where the actions of the NSA are the opposite of what's in the best interest of US Citizens.
Was it though? The NSA's job is to spy on behalf of the country. While keeping the bug a secret put people at risk, there is an argument to be made that it was a useful tool. Law enforcement regularly makes the decision to allow low level criminals to continue to commit crimes in order to catch their leaders even though doing so puts people at risk. There are always tradeoffs.
Why do we let awful people like this be in charge of our well being? Is power too entrenched that no matter what happens, we can't do anything about it?
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#47Sorry? Paid programmers writing closed code with probably less review and auditing have been shown to create less bugs? What are they trying to say?
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#48Strangely what I find most troubling with that article is the idiotic dig about opensource, it's like dismissing peer-review, which makes me even more skeptical about this whole article.
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#49I'm wondering if any State Attorney Generals are tech savvy, don't like the current administration, and want some publicity[1] enough to start an investigation? I would imagine a subpoena asking for the financial records of the OpenSSL contributors would be a first step (to find Gov payments). I can see a very scary witch hunt. 1) that part might be a little rhetorical, every AG likes good publicity.
Presumably, any State Attorney General will have gone to law school, and will thus know that the Federal Government is immune to suits from the states.
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#50My first thought: if this is the case, then why did they try so hard (and get "trolled" in the progress) to get the SSL keys from Lavabit?
As an example from history, see the story about the zimmerman telegram http://en.wikipedia.org/wiki/Zimmermann_Telegram and the british interception and decryption. They faked a theft to hide the fact that they were reading the traffic with the help of Room 40.