Live data from Hacker News

Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

icontherecord.tumblr.com

21–30 of 120 posts

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#21
post #9

"The Federal government relies on OpenSSL to protect the privacy of users of government websites and other online services." This is my big point from the other thread. If NSA knew then not disclosing this type of serious bug should get someone's head to roll as it could imperil the security of other important USG communications. That still leaves open the question of why NSA wasn't able to find this bug themselves t…

Has this actually verified? It was only newish versions of OpenSSL that were vulnerable. Websites that ran on IIS and other platforms were not vulnerable.

Does anyone have a historical list of critical government websites and their web server versions? An old nmap list would suffice to show that high-priority sites were vulnerable or not.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#22

Just keep in mind that the NSA routinely lies... even in direct testimony under oath to Congress. http://www.slate.com/articles/news_and_politics/war_stories/...

we need to begin putting government officials in prison for this.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#23
post #19

In other news, NSA thinks responsible disclosure is the way to go but apparently has no 0days to responsibly disclose. I didn't know TAO sucked so hard. Can't see how any one will buy this.

"NSA thinks responsible disclosure is the way to go but apparently has no 0days to responsibly disclose".

Very nice! In just one sentence you have completely discredited the ODNI release.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#24

I don't think I have ever upvoted so many comments in one HN thread. The NSA earned every ounce of distrust that is currently being pointed at them. I just wish people were investing as much time in OpenSSL as they are in discounting NSA statements.

Lol. I was thinking the same thing. Almost all current comments in this thread have value.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#25
It does seem like a judgement call is unavoidable. If they discover exploits that are extremely difficult to use, and extremely unlikely to have been discovered by others, it might make sense to use them. But it also seems clear that they should have an obligation to find and make public exploits similar in nature to Heartbleed. Sitting on a bug like this should be a criminal offense.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#27

Last sentence reads: "Unless there is a clear national security or law enforcement need, this process is biased toward responsibly disclosing such vulnerabilities." So, should the NSA decide that there is a national security interest or law enforcement need, they will not disclose such vulnerabilities. Given their past behavior and explanations for what was considered acceptable compromise for national security, I am…

the problem is that they will always claim a need

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#28
Aren't the utilization of the 0-day exploits in Stuxnet proof that DoD and the intelligence community generally don't care about responsible disclosure? I'm sure Microsoft would've liked to know about those. I'm also pretty sure many US government systems were vulnerable to many of the exploits, including the MOF file one.

I suppose the NSA counts that as "a clear national security or law enforcement need."

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#30

Just keep in mind that the NSA routinely lies... even in direct testimony under oath to Congress. http://www.slate.com/articles/news_and_politics/war_stories/...

we need to begin putting government officials in prison for this.

Pretty sure the laws / etc in place right now make sure no individuals can be held responsible for that kinda thing; do (former) presidents get charged with mass murder for wars in Iraq / Afghanistan, for example? Government is different from common sense of law and right and wrong.
Post reply on HN