Live data from Hacker News

Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

icontherecord.tumblr.com

1–10 of 120 posts

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#2
The third paragraph flatly says it is in the national interest to disclose zero-days.

The fourth paragraph says there is a "reinvigorated" process for deciding whether it is or not.

Obviously the fourth paragraph is more correct -- is the third paragraph just there for an easy inaccurate quote?

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#3
If the statement is true or not doesn't matter because this gem screams bullshit:

    it is in the national interest to responsibly disclose 
    the vulnerability rather than to hold it for an
    investigative or intelligence purpose.
Or to read that differently "The intelligence community would disclose 0days rather than use them as weapons".

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#9
"The Federal government relies on OpenSSL to protect the privacy of users of government websites and other online services."

This is my big point from the other thread. If NSA knew then not disclosing this type of serious bug should get someone's head to roll as it could imperil the security of other important USG communications.

That still leaves open the question of why NSA wasn't able to find this bug themselves though -- you'd think they'd be looking for bugs related to the introduction of new features into OpenSSL.

Post reply on HN