I don't know if Heartbleed could reach this point, but I think probably the only possibility for getting average citizens up in arms about this kind of thing is for them to start seeing major personal detrimental effects (like oops, all my email has been stolen and deleted and my bank account's empty), and then learn that the NSA could have easily prevented it if they weren't having so much fun being super-hackers in…
I don't think average people (so to speak) really care about their email.
NSA Said to Exploit Heartbleed Bug for Intelligence for Years
81–90 of 192 posts
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#82Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#83Earlier quoted context omitted.
Where do we draw the line? When millions die and billions of dollars in irrecoverable damage is done? Who gets to decide whether the risk is acceptable? To whom do we turn to when it's found that their risk assessment was flawed, and we require compensation for their recklessness and negligence?
One could make the argument that given the depth of the NSA's capabilities they were in an unique position to know who, if anyone, also knew of the bug.
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#84It certainly seems believable, but do we have anything more concrete to go on than "two people familiar with the matter?" Is that even two people with top-secret clearance at the NSA?
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#85Earlier quoted context omitted.
[deleted]
The same amount of time: it was apparently found with a fuzzer.
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#86So, what's to keep some organization that runs a package repo from publishing OpenSSL packages that claim to be like OpenSSL 1.0.1g but actually display the heartbleed bug? I also ask myself, would the NSA seek to implement such a thing? They would, though that is an entirely different question from if they have.
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#87Earlier quoted context omitted.
The same amount of time: it was apparently found with a fuzzer.
What about the relative ease and speed with which the bug was fixed? Fuzz testing could certainly find the bug in closed source software, but patching it is a different story, especially if the person or group that controls the source code is slow, uncooperative, or extinct.
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#88The NSA protected us by not disclosing to us a serious security vulnerability in our software. It is hard for me to wrap my brain around reasoning of the intelligence agencies.
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#89Earlier quoted context omitted.
> It's NSA's charter to stockpile these things, and, yeah, to use them against foreign adversaries. I don't see how leaving American companies vulnerable fulfills the NSA's charter.
American companies are vulnerable to literally hundreds of vulnerabilities NSA knows about; that's something that was widely known (public, in fact) almost a decade before Snowden. I agree that this bug is different, but that might have been a subtle case to make inside the organization.
If I were any US-based company CEO whose customers got hacked by Heartbleed exploits, I'd drag their corpses to the court if necessary.
Sidenote: People have asked "Why are you doing JS-based cryptography on passwords if you have HTTPS?" - here we have the ideal answer. Encrypting the passwords using public-key crypto in addition to HTTPS and doing the decryption in RoR/PHP/nodejs would at least have spared the users from the need to change their passwords.
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#90Evidence? And if so, pretty much what we expected and exactly why this behaviour is terrible
>> The U.S. National Security Agency knew for at least two years about a flaw in the way that many websites send sensitive information, now dubbed the Heartbleed bug, and regularly used it to gather critical intelligence, two people familiar with the matter said. (emphasis mine) It's pretty weak IMHO but I don't really doubt it.