Live data from Hacker News

NSA Said to Exploit Heartbleed Bug for Intelligence for Years

bloomberg.com

51–60 of 192 posts

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#51
post #3

This looks like another case where the actions of the NSA are the opposite of what's in the best interest of US Citizens.

Was it though? The NSA's job is to spy on behalf of the country. While keeping the bug a secret put people at risk, there is an argument to be made that it was a useful tool. Law enforcement regularly makes the decision to allow low level criminals to continue to commit crimes in order to catch their leaders even though doing so puts people at risk. There are always tradeoffs.

It would require the assumption that, for example, the NSA knew about it but other foreign authorities - who no doubt attempt to spy on various Americans and US corporations - did not know about it. I don't like those odds.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#52

I don't know if Heartbleed could reach this point, but I think probably the only possibility for getting average citizens up in arms about this kind of thing is for them to start seeing major personal detrimental effects (like oops, all my email has been stolen and deleted and my bank account's empty), and then learn that the NSA could have easily prevented it if they weren't having so much fun being super-hackers in…

I don't think average people (so to speak) really care about their email.

You are very wrong.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#53

I don't know if Heartbleed could reach this point, but I think probably the only possibility for getting average citizens up in arms about this kind of thing is for them to start seeing major personal detrimental effects (like oops, all my email has been stolen and deleted and my bank account's empty), and then learn that the NSA could have easily prevented it if they weren't having so much fun being super-hackers in…

I don't think average people (so to speak) really care about their email.

They don't until either they lose all of their email, or they lose their email account.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#54
post #44

Earlier quoted context omitted.

>> The U.S. National Security Agency knew for at least two years about a flaw in the way that many websites send sensitive information, now dubbed the Heartbleed bug, and regularly used it to gather critical intelligence, two people familiar with the matter said. (emphasis mine) It's pretty weak IMHO but I don't really doubt it.

[deleted]

Lol, exactly. If this was on The Intercept [0] I'd feel differently but "two people familiar with the matter" doesn't inspire much confidence.

[0] https://firstlook.org/theintercept/

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#55

I don't know if Heartbleed could reach this point, but I think probably the only possibility for getting average citizens up in arms about this kind of thing is for them to start seeing major personal detrimental effects (like oops, all my email has been stolen and deleted and my bank account's empty), and then learn that the NSA could have easily prevented it if they weren't having so much fun being super-hackers in…

I don't think average people (so to speak) really care about their email.

Even n00bs understand that if their email gets jacked, that can be used to reset all their other passwords and jack those accounts.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#56
post #6

Earlier quoted context omitted.

[deleted]

The real crazy bit about Heartbleed was that it was worse than a man-in-the-middle attack. It's a "give an unrelated third party on the side your plaintext" attack, rendering your SSL connection less secure than an encrypted connection.

HN, I'm sorry to have deleted my comment before noticing this reply. For the record it said something about 1) being put at ease by the Cloudflare challenge, suggesting to me no MITM attack was possible, 2) and then bemoaning the fact that the NSA "is the man in the middle"

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#58

Bloomberg really puts its bias on display: > The Heartbleed flaw, introduced in early 2012 in a minor adjustment to the OpenSSL protocol, highlights one of the failings of open source software development. And its discovery and resolution highlights one of the advantages of open-source software development.

> And its discovery and resolution highlights one of the advantages of open-source software development.

I wouldn't say that its discovery (two years later) says anything good about open source development.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#59

Evidence? And if so, pretty much what we expected and exactly why this behaviour is terrible

>> The U.S. National Security Agency knew for at least two years about a flaw in the way that many websites send sensitive information, now dubbed the Heartbleed bug, and regularly used it to gather critical intelligence, two people familiar with the matter said. (emphasis mine) It's pretty weak IMHO but I don't really doubt it.

Probability that story is true | Bloomberg reporting it == Probability that the sources are right * Probability that Bloomberg isn't lying about having sources ~= 80%.

The sources could be lying for many reasons. As a prank, to discredit Bloomberg when they report on other NSA stories, because they're embarrassed the NSA didn't know earlier, etc. But Bloomberg knows this and presumably required some evidence to satisfy themselves before reporting. So the deciding factor is really Bloomberg's reliability.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#60
post #36

Earlier quoted context omitted.

Presumably, any State Attorney General will have gone to law school, and will thus know that the Federal Government is immune to suits from the states.

They are not actually immune, states sue the federal government (or at least departments) all the time. Look at the ACA cases for an example. They can also go after the individual people involved as long as they are not serving in the government.

The states can presumably go to court to keep from being compelled to comply with an unconstitutional law. They cannot sue the state for damages.
Post reply on HN