Evidence? And if so, pretty much what we expected and exactly why this behaviour is terrible
>> The U.S. National Security Agency knew for at least two years about a flaw in the way that many websites send sensitive information, now dubbed the Heartbleed bug, and regularly used it to gather critical intelligence, two people familiar with the matter said. (emphasis mine) It's pretty weak IMHO but I don't really doubt it.
NSA Said to Exploit Heartbleed Bug for Intelligence for Years
71–80 of 192 posts
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#72Earlier quoted context omitted.
[deleted]
Cloudflare's challenge is specific to nginx's implementation of OpenSSL. They hypothesize that stealing keys from Apache is unlikely, but possible. http://blog.cloudflare.com/answering-the-critical-question-c...
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#73I'm wondering if any State Attorney Generals are tech savvy, don't like the current administration, and want some publicity[1] enough to start an investigation? I would imagine a subpoena asking for the financial records of the OpenSSL contributors would be a first step (to find Gov payments). I can see a very scary witch hunt. 1) that part might be a little rhetorical, every AG likes good publicity.
Presumably, any State Attorney General will have gone to law school, and will thus know that the Federal Government is immune to suits from the states.
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#74Earlier quoted context omitted.
Presumably, any State Attorney General will have gone to law school, and will thus know that the Federal Government is immune to suits from the states.
[deleted]
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#75Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#76Bloomberg really puts its bias on display: > The Heartbleed flaw, introduced in early 2012 in a minor adjustment to the OpenSSL protocol, highlights one of the failings of open source software development. And its discovery and resolution highlights one of the advantages of open-source software development.
> And its discovery and resolution highlights one of the advantages of open-source software development. I wouldn't say that its discovery (two years later) says anything good about open source development.
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#77In case you haven't made the time yet -- ACLU's interview of Snowden at SXSW was excellent and dives into the implications of this: https://www.youtube.com/watch?v=UIhS9aB-qgU
On another (ironic) note this PSA from the US government is about 2 years late: http://www.bbc.com/news/technology-26985818
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#78This looks like another case where the actions of the NSA are the opposite of what's in the best interest of US Citizens.
Was it though? The NSA's job is to spy on behalf of the country. While keeping the bug a secret put people at risk, there is an argument to be made that it was a useful tool. Law enforcement regularly makes the decision to allow low level criminals to continue to commit crimes in order to catch their leaders even though doing so puts people at risk. There are always tradeoffs.
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#79I'm wondering if any State Attorney Generals are tech savvy, don't like the current administration, and want some publicity[1] enough to start an investigation? I would imagine a subpoena asking for the financial records of the OpenSSL contributors would be a first step (to find Gov payments). I can see a very scary witch hunt. 1) that part might be a little rhetorical, every AG likes good publicity.
Presumably, any State Attorney General will have gone to law school, and will thus know that the Federal Government is immune to suits from the states.
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#80Earlier quoted context omitted.
They are not actually immune, states sue the federal government (or at least departments) all the time. Look at the ACA cases for an example. They can also go after the individual people involved as long as they are not serving in the government.
The states can presumably go to court to keep from being compelled to comply with an unconstitutional law. They cannot sue the state for damages.
I never said anything about damages.