Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
icontherecord.tumblr.com
Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
1–10 of 120 posts
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#2The third paragraph flatly says it is in the national interest to disclose zero-days.
The fourth paragraph says there is a "reinvigorated" process for deciding whether it is or not.
Obviously the fourth paragraph is more correct -- is the third paragraph just there for an easy inaccurate quote?
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#3If the statement is true or not doesn't matter because this gem screams bullshit:
it is in the national interest to responsibly disclose
the vulnerability rather than to hold it for an
investigative or intelligence purpose.
Or to read that differently "The intelligence community would disclose 0days rather than use them as weapons".Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#4Letting a bug/vuln this broad go unpatched for years for the NSA's own benefit is beyond negligent concerning our nation's security.
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#5> Unless there is a clear national security or law enforcement need, this process is biased toward responsibly disclosing such vulnerabilities.
wow, those two caveats are broad enough to remove any real meaning from the process.
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#6Oh so now the NSA publicly comments on allegations about its operations?
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#7Now who do we believe... an anonymous source or an official press release (from an agency with both motivation to lie and a history of misleading statements). Both seem fairly unsubstantiated to me.
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#8While the ambiguity in later paragraphs is par for the course, the directness of the initial statement is refreshing.
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#9"The Federal government relies on OpenSSL to protect the privacy of users of government websites and other online services."
This is my big point from the other thread. If NSA knew then not disclosing this type of serious bug should get someone's head to roll as it could imperil the security of other important USG communications.
That still leaves open the question of why NSA wasn't able to find this bug themselves though -- you'd think they'd be looking for bugs related to the introduction of new features into OpenSSL.
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#10[deleted]