Live data from Hacker News

NSA Said to Exploit Heartbleed Bug for Intelligence for Years

bloomberg.com

151–160 of 192 posts

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#151
post #132
post #107

Earlier quoted context omitted.

Yeah NSA's job is to fix open source bugs, whatever. NSA is a spy agency, expecting them not to use vulnerabilities they find is like sending them into a gunfight with a pocketful of rocks. Ask the Palestinians how that works out in the long run. I think much of the NSA's surveillance is unconstitutional and should be rolled back by at least 2 orders of magnitude. That doesn't have to entail turning the world over to…

>>That doesn't have to entail turning the world over to Russian and Chinese hackers. Boogey man FUD, I'm not worried about any hackers from [Insert_forgein_country_elites_want_you_to_hate]. The USgov, NSA and corrupt law enforcement are the only terrorists I'm worried about.

Pretty interesting statement.

Why? Nations have track records of not killing/spying on each others?

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#152

Bloomberg really puts its bias on display: > The Heartbleed flaw, introduced in early 2012 in a minor adjustment to the OpenSSL protocol, highlights one of the failings of open source software development. And its discovery and resolution highlights one of the advantages of open-source software development.

One of the claimed advantages of open source is to produce higher quality, more secure software. "As a result, the open source model builds higher-quality, more secure, more easily integrated software. And it does it at a vastly accelerated pace, often at a lower cost." - http://www.redhat.com/about/whoisredhat/opensource.html for example. As an ideology, comparing this OpenSSL happening to the stated goals of strong…

This might seem like a nitpick, but I think you're confusing two distinct camps here: let's call them "Open Source" and "Free Software".

Open Source advocates -- such as Eric S. Raymond -- believe that it is superior on technical grounds, the "many eyes make all bugs shallow" theory. They tend to disregard ideology and instead believe OS is the rational decision of those who want technically better software. In my opinion this is not always true, as Heartbleed shows (but then again who knows how many undisclosed vulnerabilities are there in existing proprietary software! At least now we know about Heartbleed!)

Free Software advocates -- such as Richard Stallman and the FSF -- believe it's a matter of ideology. This has little to do with technical quality. They say "sure, if the software is better that's a plus, but freedom is a matter of principle to us".

I'm not a zealot but I tend to side with the Free Software camp, and I don't see how the OpenSSL fiasco undermines their ideology.

PS: I also take issue with the "paid security researcher" remark. Absolutely nothing in either Free or Open Source excludes paid personnel or private companies from the equation. Hobbyist programmers are not the only ones accepted. I don't understand why you see this as extraordinary.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#153
post #84

Earlier quoted context omitted.

Well, consider what that would look like. Given the way that the US Government has pursued Snowden and other whistleblowers for embarrassing them, if you had privileged information indicating that the government was deliberately leaving nearly all Americans' online information exposed, would you want your name attached to it?

I think lauradhamilton's point is that "familiar with the matter" is too subjective.

Oh, I totally get that, and agree. I'm just saying that even if these are bulletproof sources with deep insider knowledge, it would be incredibly risky for them to associate any credentials other than "familiar with the matter" with the story.

It's wiggle-room a mile wide, but I'm not sure if there's a better alternative given the current climate.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#154
post #146
post #38

Earlier quoted context omitted.

Exactly, I don't mind them having the capability for this kind of thing. What bothers me is the lack of due process and rule of law!

There's plenty of both. NSA is wrapped with layers upon layers of process and oversight both, which is something re-confirmed in the wake of Snowden's revelations. What people are shocked about is that they didn't understand what the law permitted, or how quickly mixing the law of induction with datacenters full of computers can led to global-level surveillance. With all that said, I would mind if it's true NSA knew…

The DoJ decided to ignore the law. https://www.eff.org/foia/section-215-usa-patriot-act The NSA secretly collects the private data of people they know are innocent, which is the opposite of due process.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#155
post #32

Earlier quoted context omitted.

American companies are vulnerable to literally hundreds of vulnerabilities NSA knows about; that's something that was widely known (public, in fact) almost a decade before Snowden. I agree that this bug is different, but that might have been a subtle case to make inside the organization.

The worst problem with the NSA knowing about Heartbleed is the total lack of accountability. If I were any US-based company CEO whose customers got hacked by Heartbleed exploits, I'd drag their corpses to the court if necessary. Sidenote: People have asked "Why are you doing JS-based cryptography on passwords if you have HTTPS?" - here we have the ideal answer. Encrypting the passwords using public-key crypto in addi…

It wasn't traffic that was revealed, it was server memory. Which could just have easily contained the decrypted passwords as the encrypted ones.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#157

The NSA is denying this report. > Statement: NSA was not aware of the recently identified Heartbleed vulnerability until it was made public. https://twitter.com/NSA_PAO/status/454720059156754434

Full statement: http://twitter.com/ajamlive/status/454724369429045248/photo/...

The NSA has a good history recently of lying through their teeth, and the bit at the end "Unless there is a clear national security or law enforcement need..." is a pretty damned large asterisk.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#158

> The SSL protocol has a history of security problems, Lewis said, and is not the primary form of protection governments and others use to transmit highly sensitive information. > “I knew hackers who could break it nearly 15 years ago,” Lewis said of the SSL protocol. Anyone know wtf he's talking about?

TLS has been subject to a lot of attacks:

http://en.wikipedia.org/wiki/Transport_Layer_Security#Attack...

Plus, since the whole thing is based on CAs, if you can get an intermediate cert (and does anything think the NSA can't?) and you have the means to MITM someone, that's as good as breaking it, too.

15 years ago, we were using keys with much lower entropy, as well, which may have simply been outpaced by computing power.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#159

Bloomberg really puts its bias on display: > The Heartbleed flaw, introduced in early 2012 in a minor adjustment to the OpenSSL protocol, highlights one of the failings of open source software development. And its discovery and resolution highlights one of the advantages of open-source software development.

In fairness, the "public good" nature of an Open Source security library does create an incentive problem that's well known in the literature, and is probably related in some way to the failure here.

You might have seen the story about how it gets $2000 in donations a year, which is supposed to be enough to marshal the expertise to prevent this kind of thing.

https://news.ycombinator.com/item?id=7575210

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#160
post #124
post #28

Earlier quoted context omitted.

> It's NSA's charter to stockpile these things, and, yeah, to use them against foreign adversaries. I don't see how leaving American companies vulnerable fulfills the NSA's charter.

Consider: what if the NSA's sensors are so extensive that they know the exact moment anyone other than them tries to exploit certain bugs? That changes the risks/rewards of early-patching quite a bit. They can be confident it's their own trump card for quite a while, and learn about (or strategically mislead) any teams that arrive later to the same knowledge. When it's really "burnt", and in use by the NSA's enemies,…

I don't see how that protects the people whose data was stolen.

"Here's the license plate number and home address of the guy who just ran over your grandma. Sorry for your loss."

Post reply on HN