“It flies in the face of the agency’s comments that defense comes first” The NSA needs to be dissolved. It is a costly liability whose actions work against the nations interests as a whole.
NSA Said to Exploit Heartbleed Bug for Intelligence for Years
121–130 of 192 posts
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#122As much as Snowden has shown us the amount of effort NSA puts into this kind of stuff, I think we need more evidence than this article is giving.
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#123Earlier quoted context omitted.
I don't think average people (so to speak) really care about their email.
Even n00bs understand that if their email gets jacked, that can be used to reset all their other passwords and jack those accounts.
No, they emphatically do not, at least until you explain that to them. And even then, it was "well, I don't really do anything important online anyway..."
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#124Earlier quoted context omitted.
I don't know how "disastrous" this really is. NSA knows approximately 1 zillion vulnerabilities we don't know about and won't know about. They range from RCE's in Windows and Apache to flaws in cryptographic hash functions. It's NSA's charter to stockpile these things, and, yeah, to use them against foreign adversaries. It's bad though, because this one was so easily exploitable. It's the kind of thing a reasonable o…
> It's NSA's charter to stockpile these things, and, yeah, to use them against foreign adversaries. I don't see how leaving American companies vulnerable fulfills the NSA's charter.
That changes the risks/rewards of early-patching quite a bit. They can be confident it's their own trump card for quite a while, and learn about (or strategically mislead) any teams that arrive later to the same knowledge. When it's really "burnt", and in use by the NSA's enemies, then they can help US companies patch... and possibly even assure them exactly how much damage (if any) occurred.
(In the extreme, with say a big friend-of-NSA telecom or defense contractor, that could even be: "Hi, American BigCo. In the 48 hours between the beginning of enemy exploitation and your patching, we saw about 13,000 suspicious heartbeats directed at your servers. If you don't have raw traffic logs to do your own audit of exactly what server memory was lost, we can share our copy with you. It's a pleasure doing business with you.")
In fact, perhaps the reason for the synchronized reveal from US and non-US discoverers just now is that the first non-NSA probing (by either malicious actors or researchers) was just recently detected, starting the race to patch.
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#125Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#126It certainly seems believable, but do we have anything more concrete to go on than "two people familiar with the matter?" Is that even two people with top-secret clearance at the NSA?
Well, consider what that would look like. Given the way that the US Government has pursued Snowden and other whistleblowers for embarrassing them, if you had privileged information indicating that the government was deliberately leaving nearly all Americans' online information exposed, would you want your name attached to it?
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#127Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#128> The agency found the Heartbleed glitch shortly after its introduction, according to one of the people familiar with the matter, Presumably if the anonymous sources here were discovered, they'd be in big criminal trouble, right? I am curious how far the government goes to try and discover them. And I think there is no way these anonymous sources would have contacted the journalists without Snowden going first, to es…
You may think it's awful that the NSA knew for 2 years, and didn't push fixes... but their funders and overseers, in Congress and the DoD, would be more likely angry if, given the NSA's massive budget and mission, the NSA didn't know about this bug right away via code audit/analysis. Knowing vulnerabilities first is the whole job of the "Cyber Command".
And, the best defense isn't necessarily a panicked fire-drill of preemptive patching ASAP, if you're sure you're the only ones who know. It could make tactical and economic sense to simply prepare contingency plans, and wait for the first evidence of a 2nd-discoverer.
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#129Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#130Bloomberg really puts its bias on display: > The Heartbleed flaw, introduced in early 2012 in a minor adjustment to the OpenSSL protocol, highlights one of the failings of open source software development. And its discovery and resolution highlights one of the advantages of open-source software development.
It doesn't excuse a misunderstanding of his subject matter, but an accusation of bias is likely an over-analysis.