Live data from Hacker News

NSA Said to Exploit Heartbleed Bug for Intelligence for Years

bloomberg.com

71–80 of 192 posts

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#71

Evidence? And if so, pretty much what we expected and exactly why this behaviour is terrible

>> The U.S. National Security Agency knew for at least two years about a flaw in the way that many websites send sensitive information, now dubbed the Heartbleed bug, and regularly used it to gather critical intelligence, two people familiar with the matter said. (emphasis mine) It's pretty weak IMHO but I don't really doubt it.

I've heard of the NSA, and I've read that xkcd comic on how Heartbleed works. Can I be quoted as a person "familiar with the matter"?

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#72
post #63
post #6

Earlier quoted context omitted.

[deleted]

Cloudflare's challenge is specific to nginx's implementation of OpenSSL. They hypothesize that stealing keys from Apache is unlikely, but possible. http://blog.cloudflare.com/answering-the-critical-question-c...

Thanks for the extra info. While I don't find it encouraging, I appreciate having a better understanding of the issue at hand.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#73
post #36

I'm wondering if any State Attorney Generals are tech savvy, don't like the current administration, and want some publicity[1] enough to start an investigation? I would imagine a subpoena asking for the financial records of the OpenSSL contributors would be a first step (to find Gov payments). I can see a very scary witch hunt. 1) that part might be a little rhetorical, every AG likes good publicity.

Presumably, any State Attorney General will have gone to law school, and will thus know that the Federal Government is immune to suits from the states.

[deleted]

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#74
post #73
post #36

Earlier quoted context omitted.

Presumably, any State Attorney General will have gone to law school, and will thus know that the Federal Government is immune to suits from the states.

[deleted]

Again: they can challenge compulsion to adhere to unconstitutional laws. Note that MA didn't sue the USG for damages.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#76

Bloomberg really puts its bias on display: > The Heartbleed flaw, introduced in early 2012 in a minor adjustment to the OpenSSL protocol, highlights one of the failings of open source software development. And its discovery and resolution highlights one of the advantages of open-source software development.

> And its discovery and resolution highlights one of the advantages of open-source software development. I wouldn't say that its discovery (two years later) says anything good about open source development.

And I also wouldn't say that the existence of a bug was caused by the license that was used. It's not like me keeping all the code to myself would make me a better programmer.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#77
Here we observe a side affect of the NSA/GHCQ operating in a manner which always gives offensive capability precedence over the defense of civilian systems.

In case you haven't made the time yet -- ACLU's interview of Snowden at SXSW was excellent and dives into the implications of this: https://www.youtube.com/watch?v=UIhS9aB-qgU

On another (ironic) note this PSA from the US government is about 2 years late: http://www.bbc.com/news/technology-26985818

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#78
post #3

This looks like another case where the actions of the NSA are the opposite of what's in the best interest of US Citizens.

Was it though? The NSA's job is to spy on behalf of the country. While keeping the bug a secret put people at risk, there is an argument to be made that it was a useful tool. Law enforcement regularly makes the decision to allow low level criminals to continue to commit crimes in order to catch their leaders even though doing so puts people at risk. There are always tradeoffs.

I think you missed the part where the NSA claimed it prioritized protecting the data of Americans and American companies. Nobody denies that exploiting the bug would be useful for the NSA.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#79
post #36

I'm wondering if any State Attorney Generals are tech savvy, don't like the current administration, and want some publicity[1] enough to start an investigation? I would imagine a subpoena asking for the financial records of the OpenSSL contributors would be a first step (to find Gov payments). I can see a very scary witch hunt. 1) that part might be a little rhetorical, every AG likes good publicity.

Presumably, any State Attorney General will have gone to law school, and will thus know that the Federal Government is immune to suits from the states.

Who said anything about suing the USG, unless you are already assuming someone contributing to OpenSSL was hired by the USG in some relevant capacity. I don't see what would shield contributors to OpenSSL from a criminal investigation.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#80
post #60

Earlier quoted context omitted.

They are not actually immune, states sue the federal government (or at least departments) all the time. Look at the ACA cases for an example. They can also go after the individual people involved as long as they are not serving in the government.

The states can presumably go to court to keep from being compelled to comply with an unconstitutional law. They cannot sue the state for damages.

The states can go for a variety of reasons when the feel the federal government is overstepping their bounds or has committed a constitutional violation. They can open investigations into federal behavior.

I never said anything about damages.

Post reply on HN