Live data from Hacker News

NSA Said to Exploit Heartbleed Bug for Intelligence for Years

bloomberg.com

61–70 of 192 posts

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#61
post #3

This looks like another case where the actions of the NSA are the opposite of what's in the best interest of US Citizens.

Was it though? The NSA's job is to spy on behalf of the country. While keeping the bug a secret put people at risk, there is an argument to be made that it was a useful tool. Law enforcement regularly makes the decision to allow low level criminals to continue to commit crimes in order to catch their leaders even though doing so puts people at risk. There are always tradeoffs.

Their job is not to spy on behalf of the country.

Their job is to keep us safe.

Letting us all run around with humungous holes in our security for years was a risk to our national security. How do you think the Chinese were able to clone our weapons systems so well? Shit like this.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#62
post #3

This looks like another case where the actions of the NSA are the opposite of what's in the best interest of US Citizens.

Was it though? The NSA's job is to spy on behalf of the country. While keeping the bug a secret put people at risk, there is an argument to be made that it was a useful tool. Law enforcement regularly makes the decision to allow low level criminals to continue to commit crimes in order to catch their leaders even though doing so puts people at risk. There are always tradeoffs.

"The NSA's job is to spy on behalf of the country."

Spying on the country and spying on behalf of the country are not really the same thing.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#63
post #6
post #2

Yeah, that's not good.

[deleted]

Cloudflare's challenge is specific to nginx's implementation of OpenSSL. They hypothesize that stealing keys from Apache is unlikely, but possible.

http://blog.cloudflare.com/answering-the-critical-question-c...

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#64
post #33

Earlier quoted context omitted.

Was it though? The NSA's job is to spy on behalf of the country. While keeping the bug a secret put people at risk, there is an argument to be made that it was a useful tool. Law enforcement regularly makes the decision to allow low level criminals to continue to commit crimes in order to catch their leaders even though doing so puts people at risk. There are always tradeoffs.

Where do we draw the line? When millions die and billions of dollars in irrecoverable damage is done? Who gets to decide whether the risk is acceptable? To whom do we turn to when it's found that their risk assessment was flawed, and we require compensation for their recklessness and negligence?

One could make the argument that given the depth of the NSA's capabilities they were in an unique position to know who, if anyone, also knew of the bug.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#66
post #3

This looks like another case where the actions of the NSA are the opposite of what's in the best interest of US Citizens.

Was it though? The NSA's job is to spy on behalf of the country. While keeping the bug a secret put people at risk, there is an argument to be made that it was a useful tool. Law enforcement regularly makes the decision to allow low level criminals to continue to commit crimes in order to catch their leaders even though doing so puts people at risk. There are always tradeoffs.

I doubt such subtlety entered into the decision. The NSA plays offense, and this was a win from that point of view.

The only way to get a different result is to re-allocate resources away from NSA and build an agency from the ground up that is geared toward securing systems.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#67
post #53

Earlier quoted context omitted.

I don't think average people (so to speak) really care about their email.

They don't until either they lose all of their email, or they lose their email account.

You are right, I could have been more specific, they do often care about maintaining control of their account. I don't think they care very much about their message history though, and there is at least some segment of the population that considers email accounts entirely disposable.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#68

Bloomberg really puts its bias on display: > The Heartbleed flaw, introduced in early 2012 in a minor adjustment to the OpenSSL protocol, highlights one of the failings of open source software development. And its discovery and resolution highlights one of the advantages of open-source software development.

> And its discovery and resolution highlights one of the advantages of open-source software development. I wouldn't say that its discovery (two years later) says anything good about open source development.

[deleted]

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#70
post #68

Earlier quoted context omitted.

> And its discovery and resolution highlights one of the advantages of open-source software development. I wouldn't say that its discovery (two years later) says anything good about open source development.

[deleted]

The same amount of time: it was apparently found with a fuzzer.
Post reply on HN