Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
31–40 of 120 posts
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#32What if they have a unique definition of 'vulnerability', much like they had a unique definition of 'collect'? As a bit of internal jargon, the NSA only considered information 'collected' when an analyst looked at it. So, they could record & store bulk data about all Americans, but still claim (with a secret wink) that they didn't intentionally "collect" data on Americans. Maybe for them, 'vulnerability' means both "…
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#33What if they have a unique definition of 'vulnerability', much like they had a unique definition of 'collect'? As a bit of internal jargon, the NSA only considered information 'collected' when an analyst looked at it. So, they could record & store bulk data about all Americans, but still claim (with a secret wink) that they didn't intentionally "collect" data on Americans. Maybe for them, 'vulnerability' means both "…
Wouldn't be the first time.
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#34I see numerous disclosures from technology companies, security researchers in industry and academia... but for the life of me, I can't recount an instance in which a disclosure came from intelligence-community researchers. Is there any historical evidence of disclosures from the NSA to the open-source community?
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#35Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#36It does seem like a judgement call is unavoidable. If they discover exploits that are extremely difficult to use, and extremely unlikely to have been discovered by others, it might make sense to use them. But it also seems clear that they should have an obligation to find and make public exploits similar in nature to Heartbleed. Sitting on a bug like this should be a criminal offense.
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#37Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#38In other news, NSA thinks responsible disclosure is the way to go but apparently has no 0days to responsibly disclose. I didn't know TAO sucked so hard. Can't see how any one will buy this.
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#39How come, so far, only one person has thus far come forward with ANY evidence that might demonstrate a knowledge of this bug before it was discovered?
I just find it depressing how ready the media is to jump on the NSA for things they may not have done. There's plenty to work with in the realm of things they did do, why draw conclusions before there's evidence? So far I've yet to see a static analysis tool that would have caught this, and I don't have any reason to believe the NSA is hand-searching code for vulnerabilities.
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#40What if they have a unique definition of 'vulnerability', much like they had a unique definition of 'collect'? As a bit of internal jargon, the NSA only considered information 'collected' when an analyst looked at it. So, they could record & store bulk data about all Americans, but still claim (with a secret wink) that they didn't intentionally "collect" data on Americans. Maybe for them, 'vulnerability' means both "…
Or perhaps the "private sector cybersecurity report" was a IRC chat two years ago for l33t haxors.