Live data from Hacker News

Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

icontherecord.tumblr.com

11–20 of 120 posts

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#12
post #3

If the statement is true or not doesn't matter because this gem screams bullshit: it is in the national interest to responsibly disclose the vulnerability rather than to hold it for an investigative or intelligence purpose. Or to read that differently "The intelligence community would disclose 0days rather than use them as weapons".

It's reads pretty obviously IMHO.

"Any 0day has an obvious national security interest in being responsibly disclosed and fixed".

That's not a very direct affirmation though, merely an "interest"... the caveats show up at the end, but even that is at least honest.

You'd be crazy if you thought NSA would disclose a server 0day that e.g. affects only websites running under a Russian locale, when those websites are known to be used by the Russian armed forces bordering Ukraine. That's the type of thing which could be useful to NSA while having practically nil effect on U.S. infrastructure.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#13
I don't think I have ever upvoted so many comments in one HN thread. The NSA earned every ounce of distrust that is currently being pointed at them. I just wish people were investing as much time in OpenSSL as they are in discounting NSA statements.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#14
What if they have a unique definition of 'vulnerability', much like they had a unique definition of 'collect'?

As a bit of internal jargon, the NSA only considered information 'collected' when an analyst looked at it. So, they could record & store bulk data about all Americans, but still claim (with a secret wink) that they didn't intentionally "collect" data on Americans.

Maybe for them, 'vulnerability' means both "the bug exists" and "bad guys know enough to exploit it". After all, if a tree falls in the woods, and there's no one there to hear it, does it make a sound?

This definition even makes sense, if you have an advanced, economic and strategic understanding of security as something that's a matter of relative priorities and dynamically-changing situations. There are plenty of bugs, known and unknown, in all software. Perhaps they only count as 'vulnerabilities' when they're practically exploitable, and practical exploitation has as an absolute prerequisite, discovery by malicious actors. (On the other hand, when we, "the good guys", discover the bug, it's not a vulnerability: it's an asset! Search for [NOBUS NSA] for more reporting about this style of reasoning.)

Still, using such a fine-grained bit of internal jargon, even if it makes sense among people who share your terms, is deceptive if used to hoodwink the public and Congress, exactly as the 'collect' finesse definition was long used.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#15
Last sentence reads: "Unless there is a clear national security or law enforcement need, this process is biased toward responsibly disclosing such vulnerabilities."

So, should the NSA decide that there is a national security interest or law enforcement need, they will not disclose such vulnerabilities. Given their past behavior and explanations for what was considered acceptable compromise for national security, I am not particularly reassured by this statement.

Yes, it's good that they weren't hoarding this particular exploit. But, they have clearly not denied being in possession of other exploits; they've only said that the ones they might hold would be because of national security or law enforcement need.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#16
post #9

"The Federal government relies on OpenSSL to protect the privacy of users of government websites and other online services." This is my big point from the other thread. If NSA knew then not disclosing this type of serious bug should get someone's head to roll as it could imperil the security of other important USG communications. That still leaves open the question of why NSA wasn't able to find this bug themselves t…

That's such a weak argument from them at this point. "Hey, we're the NSA - we're entrusted to protect US infrastructure. We'd never do something like that!"

Yeah, right.

"Oh, and we're under strict oversight, too!".

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#17
post #12
post #3

If the statement is true or not doesn't matter because this gem screams bullshit: it is in the national interest to responsibly disclose the vulnerability rather than to hold it for an investigative or intelligence purpose. Or to read that differently "The intelligence community would disclose 0days rather than use them as weapons".

It's reads pretty obviously IMHO. "Any 0day has an obvious national security interest in being responsibly disclosed and fixed". That's not a very direct affirmation though, merely an "interest"... the caveats show up at the end, but even that is at least honest. You'd be crazy if you thought NSA would disclose a server 0day that e.g. affects only websites running under a Russian locale, when those websites are known…

I would agree with you except that they added the "rather than". It is a debate between the 0days value as a weapon through holding secret vs value of release to everyone else. If there was any merit to them holding any bias toward the latter we would see at least ONE public disclosure of a vulnerability by them.
Post reply on HN