This looks like another case where the actions of the NSA are the opposite of what's in the best interest of US Citizens.
Was it though? The NSA's job is to spy on behalf of the country. While keeping the bug a secret put people at risk, there is an argument to be made that it was a useful tool. Law enforcement regularly makes the decision to allow low level criminals to continue to commit crimes in order to catch their leaders even though doing so puts people at risk. There are always tradeoffs.
NSA Said to Exploit Heartbleed Bug for Intelligence for Years
51–60 of 192 posts
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#52I don't know if Heartbleed could reach this point, but I think probably the only possibility for getting average citizens up in arms about this kind of thing is for them to start seeing major personal detrimental effects (like oops, all my email has been stolen and deleted and my bank account's empty), and then learn that the NSA could have easily prevented it if they weren't having so much fun being super-hackers in…
I don't think average people (so to speak) really care about their email.
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#53I don't know if Heartbleed could reach this point, but I think probably the only possibility for getting average citizens up in arms about this kind of thing is for them to start seeing major personal detrimental effects (like oops, all my email has been stolen and deleted and my bank account's empty), and then learn that the NSA could have easily prevented it if they weren't having so much fun being super-hackers in…
I don't think average people (so to speak) really care about their email.
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#54Earlier quoted context omitted.
>> The U.S. National Security Agency knew for at least two years about a flaw in the way that many websites send sensitive information, now dubbed the Heartbleed bug, and regularly used it to gather critical intelligence, two people familiar with the matter said. (emphasis mine) It's pretty weak IMHO but I don't really doubt it.
[deleted]
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#55I don't know if Heartbleed could reach this point, but I think probably the only possibility for getting average citizens up in arms about this kind of thing is for them to start seeing major personal detrimental effects (like oops, all my email has been stolen and deleted and my bank account's empty), and then learn that the NSA could have easily prevented it if they weren't having so much fun being super-hackers in…
I don't think average people (so to speak) really care about their email.
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#56Earlier quoted context omitted.
[deleted]
The real crazy bit about Heartbleed was that it was worse than a man-in-the-middle attack. It's a "give an unrelated third party on the side your plaintext" attack, rendering your SSL connection less secure than an encrypted connection.
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#57Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#58Bloomberg really puts its bias on display: > The Heartbleed flaw, introduced in early 2012 in a minor adjustment to the OpenSSL protocol, highlights one of the failings of open source software development. And its discovery and resolution highlights one of the advantages of open-source software development.
I wouldn't say that its discovery (two years later) says anything good about open source development.
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#59Evidence? And if so, pretty much what we expected and exactly why this behaviour is terrible
>> The U.S. National Security Agency knew for at least two years about a flaw in the way that many websites send sensitive information, now dubbed the Heartbleed bug, and regularly used it to gather critical intelligence, two people familiar with the matter said. (emphasis mine) It's pretty weak IMHO but I don't really doubt it.
The sources could be lying for many reasons. As a prank, to discredit Bloomberg when they report on other NSA stories, because they're embarrassed the NSA didn't know earlier, etc. But Bloomberg knows this and presumably required some evidence to satisfy themselves before reporting. So the deciding factor is really Bloomberg's reliability.
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#60Earlier quoted context omitted.
Presumably, any State Attorney General will have gone to law school, and will thus know that the Federal Government is immune to suits from the states.
They are not actually immune, states sue the federal government (or at least departments) all the time. Look at the ACA cases for an example. They can also go after the individual people involved as long as they are not serving in the government.