http://www.slate.com/articles/news_and_politics/war_stories/...
Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
11–20 of 120 posts
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#12If the statement is true or not doesn't matter because this gem screams bullshit: it is in the national interest to responsibly disclose the vulnerability rather than to hold it for an investigative or intelligence purpose. Or to read that differently "The intelligence community would disclose 0days rather than use them as weapons".
"Any 0day has an obvious national security interest in being responsibly disclosed and fixed".
That's not a very direct affirmation though, merely an "interest"... the caveats show up at the end, but even that is at least honest.
You'd be crazy if you thought NSA would disclose a server 0day that e.g. affects only websites running under a Russian locale, when those websites are known to be used by the Russian armed forces bordering Ukraine. That's the type of thing which could be useful to NSA while having practically nil effect on U.S. infrastructure.
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#13Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#14As a bit of internal jargon, the NSA only considered information 'collected' when an analyst looked at it. So, they could record & store bulk data about all Americans, but still claim (with a secret wink) that they didn't intentionally "collect" data on Americans.
Maybe for them, 'vulnerability' means both "the bug exists" and "bad guys know enough to exploit it". After all, if a tree falls in the woods, and there's no one there to hear it, does it make a sound?
This definition even makes sense, if you have an advanced, economic and strategic understanding of security as something that's a matter of relative priorities and dynamically-changing situations. There are plenty of bugs, known and unknown, in all software. Perhaps they only count as 'vulnerabilities' when they're practically exploitable, and practical exploitation has as an absolute prerequisite, discovery by malicious actors. (On the other hand, when we, "the good guys", discover the bug, it's not a vulnerability: it's an asset! Search for [NOBUS NSA] for more reporting about this style of reasoning.)
Still, using such a fine-grained bit of internal jargon, even if it makes sense among people who share your terms, is deceptive if used to hoodwink the public and Congress, exactly as the 'collect' finesse definition was long used.
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#15So, should the NSA decide that there is a national security interest or law enforcement need, they will not disclose such vulnerabilities. Given their past behavior and explanations for what was considered acceptable compromise for national security, I am not particularly reassured by this statement.
Yes, it's good that they weren't hoarding this particular exploit. But, they have clearly not denied being in possession of other exploits; they've only said that the ones they might hold would be because of national security or law enforcement need.
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#16"The Federal government relies on OpenSSL to protect the privacy of users of government websites and other online services." This is my big point from the other thread. If NSA knew then not disclosing this type of serious bug should get someone's head to roll as it could imperil the security of other important USG communications. That still leaves open the question of why NSA wasn't able to find this bug themselves t…
Yeah, right.
"Oh, and we're under strict oversight, too!".
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#17If the statement is true or not doesn't matter because this gem screams bullshit: it is in the national interest to responsibly disclose the vulnerability rather than to hold it for an investigative or intelligence purpose. Or to read that differently "The intelligence community would disclose 0days rather than use them as weapons".
It's reads pretty obviously IMHO. "Any 0day has an obvious national security interest in being responsibly disclosed and fixed". That's not a very direct affirmation though, merely an "interest"... the caveats show up at the end, but even that is at least honest. You'd be crazy if you thought NSA would disclose a server 0day that e.g. affects only websites running under a Russian locale, when those websites are known…
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#18Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#19Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#20This statement isn't worth the memory it's stored in.