Live data from Hacker News

Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

icontherecord.tumblr.com

41–50 of 120 posts

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#41
post #33
post #14

What if they have a unique definition of 'vulnerability', much like they had a unique definition of 'collect'? As a bit of internal jargon, the NSA only considered information 'collected' when an analyst looked at it. So, they could record & store bulk data about all Americans, but still claim (with a secret wink) that they didn't intentionally "collect" data on Americans. Maybe for them, 'vulnerability' means both "…

Or they straight out lied. Wouldn't be the first time.

Or they didn't.

See, now we have complete set of possible answers! So, what does it means when NSA officially announces something? I'd say, it means nothing.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#42
post #14

What if they have a unique definition of 'vulnerability', much like they had a unique definition of 'collect'? As a bit of internal jargon, the NSA only considered information 'collected' when an analyst looked at it. So, they could record & store bulk data about all Americans, but still claim (with a secret wink) that they didn't intentionally "collect" data on Americans. Maybe for them, 'vulnerability' means both "…

Maybe they are just being "least untruthful".

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#43

> Unless there is a clear national security or law enforcement need, this process is biased toward responsibly disclosing such vulnerabilities. wow, those two caveats are broad enough to remove any real meaning from the process.

The cool part is that you can actually measure how weasely are those weasel words: As other security experts have pointed out here, the NSA's hoard of zero-days is numbers in the thousands. How many times have they practiced "responsible disclosure?"

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#44
post #33
post #14

What if they have a unique definition of 'vulnerability', much like they had a unique definition of 'collect'? As a bit of internal jargon, the NSA only considered information 'collected' when an analyst looked at it. So, they could record & store bulk data about all Americans, but still claim (with a secret wink) that they didn't intentionally "collect" data on Americans. Maybe for them, 'vulnerability' means both "…

Or they straight out lied. Wouldn't be the first time.

Or they just didn't know. Seriously, if you divide the world into the NDA and the non-NSA, then why would the former be much better than the latter at finding vulnerabilities in open source software?

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#45
post #34

"If the Federal government, including the intelligence community, had discovered this vulnerability prior to last week, it would have been disclosed to the community responsible for OpenSSL." I see numerous disclosures from technology companies, security researchers in industry and academia... but for the life of me, I can't recount an instance in which a disclosure came from intelligence-community researchers. Is th…

> Is there any historical evidence of disclosures from the NSA to the open-source community?

I would suspect that NSA would want to conceal the fact that the disclosure came from them.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#46
post #33

Earlier quoted context omitted.

Or they straight out lied. Wouldn't be the first time.

Or they just didn't know. Seriously, if you divide the world into the NDA and the non-NSA, then why would the former be much better than the latter at finding vulnerabilities in open source software?

Budget, mission, and legal privileges.

For the money they get, and the supposed "Cyber Command" mission, they should have a team of great auditors, and advanced tools, that's much larger and more competent than the volunteer OpenSSL team itself. This group should go over all similar code multiple times with a magnifying glass.

Otherwise, what's the point of the NSA & Cyber Command, on its own stated terms?

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#47

Just keep in mind that the NSA routinely lies... even in direct testimony under oath to Congress. http://www.slate.com/articles/news_and_politics/war_stories/...

we need to begin putting government officials in prison for this.

Unfortunately that "we" is the government officials themselves.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#48

Sincere question: is the NSA on record for having responsibly disclosed any previous security holes? Is there some track record of them having actively help close security holes in software?

The most famous example is the DES S-boxes, where the NSA made a change that nobody else understood - until years later, when it was discovered that they had made the algorithm more secure against cryptanalysis techniques that had just been "discovered", but which had evidently been known to NSA long before.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#49

If this is true, and the NSA knew about the Heartbleed vulnerability, then how come the EFF hasn't been getting more log data showing the vulnerability being exploited against sites? How come, so far, only one person has thus far come forward with ANY evidence that might demonstrate a knowledge of this bug before it was discovered? I just find it depressing how ready the media is to jump on the NSA for things they ma…

>>If this is true, and the NSA knew about the Heartbleed vulnerability, then how come the EFF hasn't been getting more log data showing the vulnerability being exploited against sites?

So, I have no idea if the NSA knew about this before or not but your typically configured webserver won't store these in access.log. Also, all the network stuff in between typically won't log SSL traffic(since it's just binary blobs without the private key)

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#50

Sincere question: is the NSA on record for having responsibly disclosed any previous security holes? Is there some track record of them having actively help close security holes in software?

Yes, they helped improve DES

http://arstechnica.com/security/2013/09/the-nsas-work-to-mak...

Post reply on HN