Live data from Hacker News

Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

icontherecord.tumblr.com

31–40 of 120 posts

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#32
post #14

What if they have a unique definition of 'vulnerability', much like they had a unique definition of 'collect'? As a bit of internal jargon, the NSA only considered information 'collected' when an analyst looked at it. So, they could record & store bulk data about all Americans, but still claim (with a secret wink) that they didn't intentionally "collect" data on Americans. Maybe for them, 'vulnerability' means both "…

[deleted]

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#33
post #14

What if they have a unique definition of 'vulnerability', much like they had a unique definition of 'collect'? As a bit of internal jargon, the NSA only considered information 'collected' when an analyst looked at it. So, they could record & store bulk data about all Americans, but still claim (with a secret wink) that they didn't intentionally "collect" data on Americans. Maybe for them, 'vulnerability' means both "…

Or they straight out lied.

Wouldn't be the first time.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#34
"If the Federal government, including the intelligence community, had discovered this vulnerability prior to last week, it would have been disclosed to the community responsible for OpenSSL."

I see numerous disclosures from technology companies, security researchers in industry and academia... but for the life of me, I can't recount an instance in which a disclosure came from intelligence-community researchers. Is there any historical evidence of disclosures from the NSA to the open-source community?

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#36
post #25

It does seem like a judgement call is unavoidable. If they discover exploits that are extremely difficult to use, and extremely unlikely to have been discovered by others, it might make sense to use them. But it also seems clear that they should have an obligation to find and make public exploits similar in nature to Heartbleed. Sitting on a bug like this should be a criminal offense.

Use the bug for what purpose? The NSA constantly lies, and also just spies on non-terrorist organizations because terrorism: http://techcrunch.com/2014/04/08/snowden-council-of-europe-t.... They are so beyond deserving the benefit of any doubt.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#38
post #19

In other news, NSA thinks responsible disclosure is the way to go but apparently has no 0days to responsibly disclose. I didn't know TAO sucked so hard. Can't see how any one will buy this.

I was actually inclined to give them the benefit of the doubt, but your point actually sort of makes sense. I don't like this feeling of not knowing where the boundary between wacko conspiracy theory and ... y'know ... real life ... begins and ends.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#39
If this is true, and the NSA knew about the Heartbleed vulnerability, then how come the EFF hasn't been getting more log data showing the vulnerability being exploited against sites?

How come, so far, only one person has thus far come forward with ANY evidence that might demonstrate a knowledge of this bug before it was discovered?

I just find it depressing how ready the media is to jump on the NSA for things they may not have done. There's plenty to work with in the realm of things they did do, why draw conclusions before there's evidence? So far I've yet to see a static analysis tool that would have caught this, and I don't have any reason to believe the NSA is hand-searching code for vulnerabilities.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#40
post #14

What if they have a unique definition of 'vulnerability', much like they had a unique definition of 'collect'? As a bit of internal jargon, the NSA only considered information 'collected' when an analyst looked at it. So, they could record & store bulk data about all Americans, but still claim (with a secret wink) that they didn't intentionally "collect" data on Americans. Maybe for them, 'vulnerability' means both "…

NSA was not aware of the recently identified vulnerability in OpenSSL, the so-called Heartbleed vulnerability, until it was made public in a private sector cybersecurity report

Or perhaps the "private sector cybersecurity report" was a IRC chat two years ago for l33t haxors.

Post reply on HN