Live data from Hacker News

NSA Said to Exploit Heartbleed Bug for Intelligence for Years

bloomberg.com

121–130 of 192 posts

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#123
post #55

Earlier quoted context omitted.

I don't think average people (so to speak) really care about their email.

Even n00bs understand that if their email gets jacked, that can be used to reset all their other passwords and jack those accounts.

I had a fifteen minute conversation with a relative about this yesterday.

No, they emphatically do not, at least until you explain that to them. And even then, it was "well, I don't really do anything important online anyway..."

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#124
post #28
post #20

Earlier quoted context omitted.

I don't know how "disastrous" this really is. NSA knows approximately 1 zillion vulnerabilities we don't know about and won't know about. They range from RCE's in Windows and Apache to flaws in cryptographic hash functions. It's NSA's charter to stockpile these things, and, yeah, to use them against foreign adversaries. It's bad though, because this one was so easily exploitable. It's the kind of thing a reasonable o…

> It's NSA's charter to stockpile these things, and, yeah, to use them against foreign adversaries. I don't see how leaving American companies vulnerable fulfills the NSA's charter.

Consider: what if the NSA's sensors are so extensive that they know the exact moment anyone other than them tries to exploit certain bugs?

That changes the risks/rewards of early-patching quite a bit. They can be confident it's their own trump card for quite a while, and learn about (or strategically mislead) any teams that arrive later to the same knowledge. When it's really "burnt", and in use by the NSA's enemies, then they can help US companies patch... and possibly even assure them exactly how much damage (if any) occurred.

(In the extreme, with say a big friend-of-NSA telecom or defense contractor, that could even be: "Hi, American BigCo. In the 48 hours between the beginning of enemy exploitation and your patching, we saw about 13,000 suspicious heartbeats directed at your servers. If you don't have raw traffic logs to do your own audit of exactly what server memory was lost, we can share our copy with you. It's a pleasure doing business with you.")

In fact, perhaps the reason for the synchronized reveal from US and non-US discoverers just now is that the first non-NSA probing (by either malicious actors or researchers) was just recently detected, starting the race to patch.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#126
post #84

It certainly seems believable, but do we have anything more concrete to go on than "two people familiar with the matter?" Is that even two people with top-secret clearance at the NSA?

Well, consider what that would look like. Given the way that the US Government has pursued Snowden and other whistleblowers for embarrassing them, if you had privileged information indicating that the government was deliberately leaving nearly all Americans' online information exposed, would you want your name attached to it?

I think lauradhamilton's point is that "familiar with the matter" is too subjective.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#128

> The agency found the Heartbleed glitch shortly after its introduction, according to one of the people familiar with the matter, Presumably if the anonymous sources here were discovered, they'd be in big criminal trouble, right? I am curious how far the government goes to try and discover them. And I think there is no way these anonymous sources would have contacted the journalists without Snowden going first, to es…

Not necessarily, this might actually be an approved ass-covering leak.

You may think it's awful that the NSA knew for 2 years, and didn't push fixes... but their funders and overseers, in Congress and the DoD, would be more likely angry if, given the NSA's massive budget and mission, the NSA didn't know about this bug right away via code audit/analysis. Knowing vulnerabilities first is the whole job of the "Cyber Command".

And, the best defense isn't necessarily a panicked fire-drill of preemptive patching ASAP, if you're sure you're the only ones who know. It could make tactical and economic sense to simply prepare contingency plans, and wait for the first evidence of a 2nd-discoverer.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#130

Bloomberg really puts its bias on display: > The Heartbleed flaw, introduced in early 2012 in a minor adjustment to the OpenSSL protocol, highlights one of the failings of open source software development. And its discovery and resolution highlights one of the advantages of open-source software development.

This is a Washington-based reporter, meaning he's most likely more policy-oriented than technology-oriented (got his start chasing stories on the Hill, not in Silicon Valley).

It doesn't excuse a misunderstanding of his subject matter, but an accusation of bias is likely an over-analysis.

Post reply on HN