Live data from Hacker News

NSA Said to Exploit Heartbleed Bug for Intelligence for Years

bloomberg.com

101–110 of 192 posts

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#101
> The agency found the Heartbleed glitch shortly after its introduction, according to one of the people familiar with the matter,

Presumably if the anonymous sources here were discovered, they'd be in big criminal trouble, right? I am curious how far the government goes to try and discover them.

And I think there is no way these anonymous sources would have contacted the journalists without Snowden going first, to establish the context and interest. Snowden's actions continue to benefit us all, cascading.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#102
> The SSL protocol has a history of security problems, Lewis said, and is not the primary form of protection governments and others use to transmit highly sensitive information.

> “I knew hackers who could break it nearly 15 years ago,” Lewis said of the SSL protocol.

Anyone know wtf he's talking about?

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#103
Now would be the time to start looking up the backgrounds of the people who implemented heartbeat support. For instance, the same guy responsible for the Heartbeat spec was the author of the OpenSSL implementation.

While we do not want to make this into a witch hunt, now that the NSA is involved in Heartbleed, we should definitely rule out malice by checking for direct ties between contributors of known flawed/malicious code related to the implementation of Heartbeat.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#104
post #98

I'm wondering if any State Attorney Generals are tech savvy, don't like the current administration, and want some publicity[1] enough to start an investigation? I would imagine a subpoena asking for the financial records of the OpenSSL contributors would be a first step (to find Gov payments). I can see a very scary witch hunt. 1) that part might be a little rhetorical, every AG likes good publicity.

"Financial records of the OpenSSL contributors"? How extremely silly. Knowing about Heartbleed? Easy to see. Not sharing Heartbleed? Easy to see. Deliberately introducing a vulnerability that every single US adversary could trivially find? Beyond unlikely.

My personal opinion is that I doubt the NSA introduced it, but if it allowed other countries to exploit US citizens and the NSA knew about it, then that is indefensible behavior.

That being said, it would be a pretty standard tactic for an AG to look at who paid the people who did the work. It is a pattern in a lot of different types of investigations and familiar to an AG. Will they find anything? Doubtful. Will that really matter? Doubtful.

I should at this point say that I am thinking of a scenario that would occur to an AG (the pattern happens a lot). I am not advocating such behavior. It would have a huge chilling effect on public source code of any type and probably generate some seriously evil legislation (certifications or liability insurance). These concerns have never been part of most politicians concerns.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#105
post #20

Earlier quoted context omitted.

I don't know how "disastrous" this really is. NSA knows approximately 1 zillion vulnerabilities we don't know about and won't know about. They range from RCE's in Windows and Apache to flaws in cryptographic hash functions. It's NSA's charter to stockpile these things, and, yeah, to use them against foreign adversaries. It's bad though, because this one was so easily exploitable. It's the kind of thing a reasonable o…

Eventually, the bad guys will find all of these bugs. And do massive amounts of damage (in this case, potentially billions of people who should change their password, and hundreds of thousands of administrators having to swap certificates). And all the time, the NSA had the capability and knowledge to prevent this damage. What a great service they did to their country, indeed.

Eventually, the bad guys will find all of these bugs

That's not really true. The NSA has incredible resources that other bad guys do not.

I think a critical step on this logic chain is "once we find all the bugs, we will be safe." Given that step, you would obviously want the NSA to tell the vendors about every single bug they find.

But it's really not the case that we will ever "find all the bugs." Even if the vast resources required were needed to be spent to find all the bugs in version 3.1415, there would be new bugs in 3.1416.

I can kinda-sorta buy the full-disclosure argument that "if an independent researcher can find X then so can the bad guys." That argument doesn't apply to the NSA. They have a much better reason to believe "we found this exploit, and it will take a long time for someone else to find it out."

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#106
post #85
post #70

Earlier quoted context omitted.

The same amount of time: it was apparently found with a fuzzer.

What about the relative ease and speed with which the bug was fixed? Fuzz testing could certainly find the bug in closed source software, but patching it is a different story, especially if the person or group that controls the source code is slow, uncooperative, or extinct.

However, the software being open source aided those who may have rushed out to take advantage of still-vulnerable systems. It's a mixed bag both ways, lets not put blinders on for ideological reasons.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#107
post #61

Earlier quoted context omitted.

Was it though? The NSA's job is to spy on behalf of the country. While keeping the bug a secret put people at risk, there is an argument to be made that it was a useful tool. Law enforcement regularly makes the decision to allow low level criminals to continue to commit crimes in order to catch their leaders even though doing so puts people at risk. There are always tradeoffs.

Their job is not to spy on behalf of the country. Their job is to keep us safe. Letting us all run around with humungous holes in our security for years was a risk to our national security. How do you think the Chinese were able to clone our weapons systems so well? Shit like this.

Yeah NSA's job is to fix open source bugs, whatever.

NSA is a spy agency, expecting them not to use vulnerabilities they find is like sending them into a gunfight with a pocketful of rocks. Ask the Palestinians how that works out in the long run.

I think much of the NSA's surveillance is unconstitutional and should be rolled back by at least 2 orders of magnitude. That doesn't have to entail turning the world over to Russian and Chinese hackers.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#108
post #98

Earlier quoted context omitted.

"Financial records of the OpenSSL contributors"? How extremely silly. Knowing about Heartbleed? Easy to see. Not sharing Heartbleed? Easy to see. Deliberately introducing a vulnerability that every single US adversary could trivially find? Beyond unlikely.

My personal opinion is that I doubt the NSA introduced it, but if it allowed other countries to exploit US citizens and the NSA knew about it, then that is indefensible behavior. That being said, it would be a pretty standard tactic for an AG to look at who paid the people who did the work. It is a pattern in a lot of different types of investigations and familiar to an AG. Will they find anything? Doubtful. Will tha…

I think it's hilarious to see people who are ostensibly zealous advocates of privacy lobbying to get prosecutors to subpoena the financial records of the people who invest their free time in building privacy-protecting software.

I am at the same time comfortable filing this under "things that will never happen".

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#109

Earlier quoted context omitted.

Eventually, the bad guys will find all of these bugs. And do massive amounts of damage (in this case, potentially billions of people who should change their password, and hundreds of thousands of administrators having to swap certificates). And all the time, the NSA had the capability and knowledge to prevent this damage. What a great service they did to their country, indeed.

Eventually, the bad guys will find all of these bugs That's not really true. The NSA has incredible resources that other bad guys do not. I think a critical step on this logic chain is "once we find all the bugs, we will be safe." Given that step, you would obviously want the NSA to tell the vendors about every single bug they find. But it's really not the case that we will ever "find all the bugs." Even if the vast…

Problem is that "the bad guys" also includes Chinese and Israel intelligence agencies. The Israelis are known to have massive cyber ops going on (Stuxnet is said to have a large Israel contribution), and the Chinese cyber-ops exposed (iirc) one year ago only learned from their uncovering.

I would not be surprised at all if Israel and China didn't also know about Heartbleed.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#110

Earlier quoted context omitted.

> And its discovery and resolution highlights one of the advantages of open-source software development. I wouldn't say that its discovery (two years later) says anything good about open source development.

And I also wouldn't say that the existence of a bug was caused by the license that was used. It's not like me keeping all the code to myself would make me a better programmer.

[deleted]
Post reply on HN