Live data from Hacker News

NSA Said to Exploit Heartbleed Bug for Intelligence for Years

bloomberg.com

91–100 of 192 posts

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#91
post #33

Earlier quoted context omitted.

Where do we draw the line? When millions die and billions of dollars in irrecoverable damage is done? Who gets to decide whether the risk is acceptable? To whom do we turn to when it's found that their risk assessment was flawed, and we require compensation for their recklessness and negligence?

One could make the argument that given the depth of the NSA's capabilities they were in an unique position to know who, if anyone, also knew of the bug.

[deleted]

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#92
post #61

Earlier quoted context omitted.

Was it though? The NSA's job is to spy on behalf of the country. While keeping the bug a secret put people at risk, there is an argument to be made that it was a useful tool. Law enforcement regularly makes the decision to allow low level criminals to continue to commit crimes in order to catch their leaders even though doing so puts people at risk. There are always tradeoffs.

Their job is not to spy on behalf of the country. Their job is to keep us safe. Letting us all run around with humungous holes in our security for years was a risk to our national security. How do you think the Chinese were able to clone our weapons systems so well? Shit like this.

POSIWID.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#93
post #59

Earlier quoted context omitted.

>> The U.S. National Security Agency knew for at least two years about a flaw in the way that many websites send sensitive information, now dubbed the Heartbleed bug, and regularly used it to gather critical intelligence, two people familiar with the matter said. (emphasis mine) It's pretty weak IMHO but I don't really doubt it.

Probability that story is true | Bloomberg reporting it == Probability that the sources are right * Probability that Bloomberg isn't lying about having sources ~= 80%. The sources could be lying for many reasons. As a prank, to discredit Bloomberg when they report on other NSA stories, because they're embarrassed the NSA didn't know earlier, etc. But Bloomberg knows this and presumably required some evidence to satis…

Why do you think Bloomberg was any more thorough in its Heartbleed investigation than Newsweek was in outing Dorian Nakamoto as the author of Bitcoin?

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#94

Bloomberg really puts its bias on display: > The Heartbleed flaw, introduced in early 2012 in a minor adjustment to the OpenSSL protocol, highlights one of the failings of open source software development. And its discovery and resolution highlights one of the advantages of open-source software development.

> And its discovery and resolution highlights one of the advantages of open-source software development. I wouldn't say that its discovery (two years later) says anything good about open source development.

I might be completely wrong but I don't see much difference between open source and closed source in this case. If I were biased I might say that it might have taken substantially longer to discover such a bug in closed source software but that seems to be as much sensible as saying that open source has less security bugs because more people look at the same code.

In the end software is written by people and people make mistakes. I'm pretty sure there are a lot of software be it open or closed source that had absolutely terrible security bugs. Judging open source as a whole by looking at a single project sounds a little bit like overgeneralization. Also, they are obviously in need of help though, I hear a lot of complaints from people about the OpenSSL code.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#95

Your friends tell you about your flaws and shortcomings. The people who keep quiet or even exploit your flaws? They are not your friends. So, what's to keep some organization that runs a package repo from publishing OpenSSL packages that claim to be like OpenSSL 1.0.1g but actually display the heartbleed bug? I also ask myself, would the NSA seek to implement such a thing? They would, though that is an entirely diffe…

This is why you can, on Debian/xbuntu, always run a apt-build from the source and verify the patch is present in the code. Or on Gentoo, it's building from source anyways.

(Or just use Debian in the Gentoo flavour from the beginning)

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#96
While there's no evidence (yet) that the NSA knew about or exploited this bug, I would not be the least bit surprised if they did. Honestly, my first thought when reading about Heartbleed was "I wonder how much the NSA paid the contributor. Or did they just threaten his family?" It seems there have been a lot of "oops" errors being found in critical security systems these days, and every single one of them is directly beneficial to the NSA and its mission to "h4ck the plan37!"

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#97
post #83

Earlier quoted context omitted.

One could make the argument that given the depth of the NSA's capabilities they were in an unique position to know who, if anyone, also knew of the bug.

So we should just blindly trust an agency that has repeatedly been shown to have abused that very trust for self-serving and hypocritical ends?

All governments are hypocritical. We have nukes, but you can't have them; we can spy on you, but don't spy on us; etc. It's the nature of self-interest.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#98

I'm wondering if any State Attorney Generals are tech savvy, don't like the current administration, and want some publicity[1] enough to start an investigation? I would imagine a subpoena asking for the financial records of the OpenSSL contributors would be a first step (to find Gov payments). I can see a very scary witch hunt. 1) that part might be a little rhetorical, every AG likes good publicity.

"Financial records of the OpenSSL contributors"? How extremely silly. Knowing about Heartbleed? Easy to see. Not sharing Heartbleed? Easy to see. Deliberately introducing a vulnerability that every single US adversary could trivially find? Beyond unlikely.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#100
post #3

This looks like another case where the actions of the NSA are the opposite of what's in the best interest of US Citizens.

Are there any cases where the actions of the NSA are in any way beneficial to US citizens? Can they show that they have ever done anything positive at all? Have they saved a single life? Stopped a single threat? Or are they too busy jerking it to sexting pics and playing WoW (seriously? Come on, guys) to actually do anything useful with the BILLIONS of dollars of money that they get to play with?
Post reply on HN