Live data from Hacker News

NSA Said to Exploit Heartbleed Bug for Intelligence for Years

bloomberg.com

81–90 of 192 posts

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#81

I don't know if Heartbleed could reach this point, but I think probably the only possibility for getting average citizens up in arms about this kind of thing is for them to start seeing major personal detrimental effects (like oops, all my email has been stolen and deleted and my bank account's empty), and then learn that the NSA could have easily prevented it if they weren't having so much fun being super-hackers in…

I don't think average people (so to speak) really care about their email.

I don't know about that. Yesterday, my sister (a person who has no interest in tech, government, and is downright afraid of both) asked me about Heartbleed and stated it was the topic of discussion during breaks at work. I was pleasantly surprised.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#83
post #33

Earlier quoted context omitted.

Where do we draw the line? When millions die and billions of dollars in irrecoverable damage is done? Who gets to decide whether the risk is acceptable? To whom do we turn to when it's found that their risk assessment was flawed, and we require compensation for their recklessness and negligence?

One could make the argument that given the depth of the NSA's capabilities they were in an unique position to know who, if anyone, also knew of the bug.

So we should just blindly trust an agency that has repeatedly been shown to have abused that very trust for self-serving and hypocritical ends?

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#84

It certainly seems believable, but do we have anything more concrete to go on than "two people familiar with the matter?" Is that even two people with top-secret clearance at the NSA?

Well, consider what that would look like. Given the way that the US Government has pursued Snowden and other whistleblowers for embarrassing them, if you had privileged information indicating that the government was deliberately leaving nearly all Americans' online information exposed, would you want your name attached to it?

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#85
post #70
post #68

Earlier quoted context omitted.

[deleted]

The same amount of time: it was apparently found with a fuzzer.

What about the relative ease and speed with which the bug was fixed? Fuzz testing could certainly find the bug in closed source software, but patching it is a different story, especially if the person or group that controls the source code is slow, uncooperative, or extinct.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#86
Your friends tell you about your flaws and shortcomings. The people who keep quiet or even exploit your flaws? They are not your friends.

So, what's to keep some organization that runs a package repo from publishing OpenSSL packages that claim to be like OpenSSL 1.0.1g but actually display the heartbleed bug? I also ask myself, would the NSA seek to implement such a thing? They would, though that is an entirely different question from if they have.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#87
post #85
post #70

Earlier quoted context omitted.

The same amount of time: it was apparently found with a fuzzer.

What about the relative ease and speed with which the bug was fixed? Fuzz testing could certainly find the bug in closed source software, but patching it is a different story, especially if the person or group that controls the source code is slow, uncooperative, or extinct.

It was definitely easier to fix because it was open.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#88
post #75

The NSA protected us by not disclosing to us a serious security vulnerability in our software. It is hard for me to wrap my brain around reasoning of the intelligence agencies.

To be fair to the NSA, it's not just them. Many other government agencies operate under the assumption that society is better off if people are protected from themselves. It's why we have FCC censorship and the war on drugs. Questioning this core assumption is verboten in these organizations because it is equivalent to questioning their reason for existing. So when they take criticism from the public they naturally retreat to their core assumptions and values, even if they have to dress it up with doublespeak.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#89
post #32
post #28

Earlier quoted context omitted.

> It's NSA's charter to stockpile these things, and, yeah, to use them against foreign adversaries. I don't see how leaving American companies vulnerable fulfills the NSA's charter.

American companies are vulnerable to literally hundreds of vulnerabilities NSA knows about; that's something that was widely known (public, in fact) almost a decade before Snowden. I agree that this bug is different, but that might have been a subtle case to make inside the organization.

The worst problem with the NSA knowing about Heartbleed is the total lack of accountability.

If I were any US-based company CEO whose customers got hacked by Heartbleed exploits, I'd drag their corpses to the court if necessary.

Sidenote: People have asked "Why are you doing JS-based cryptography on passwords if you have HTTPS?" - here we have the ideal answer. Encrypting the passwords using public-key crypto in addition to HTTPS and doing the decryption in RoR/PHP/nodejs would at least have spared the users from the need to change their passwords.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#90

Evidence? And if so, pretty much what we expected and exactly why this behaviour is terrible

>> The U.S. National Security Agency knew for at least two years about a flaw in the way that many websites send sensitive information, now dubbed the Heartbleed bug, and regularly used it to gather critical intelligence, two people familiar with the matter said. (emphasis mine) It's pretty weak IMHO but I don't really doubt it.

The bug only existed in the wild for two years and less than a month. I’m not sure what the “at least two years” means in that context. The NSA can’t have known this bug for a lot longer and “at least two years” implies to me “at least 24 months and possibly many more”, not “at least 24 months, at most 25”.
Post reply on HN