Live data from Hacker News

Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

icontherecord.tumblr.com

51–60 of 120 posts

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#51

Is this even a legit website? The NSA makes announcements via their Tumblr now? Doesn't that strike anyone else as strange?

They want haters to DDOS Tumblr instead of the .gov. No doubt it is strange and as always with the NSA there is a reason for it.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#53

If this is true, and the NSA knew about the Heartbleed vulnerability, then how come the EFF hasn't been getting more log data showing the vulnerability being exploited against sites? How come, so far, only one person has thus far come forward with ANY evidence that might demonstrate a knowledge of this bug before it was discovered? I just find it depressing how ready the media is to jump on the NSA for things they ma…

> I just find it depressing how ready the media is to jump on the NSA for things they may not have done.

I don't like journalism and such, but I think it's OK in this case and I don't find it a bit depressing, maybe even otherwise. Why? Because we should be aware. Always. There's no sense in blaming NSA for something. It's stupid to blame spies for spying. There's no sense in saying something they do is immoral, because it couldn't stop them from doing it. So if you care about them doing something wrong the only way to stop it is to make it impossible. If you don't want NSA to know some data that belong to you — you are enemies, because NSA wants to know anything. And it's OK. It's what they are for.

You obviously cannot prevent what already happened, you can only try to fix the consequences and be more careful in the future. So it's always sensible to assume NSA knew about any single security bug discovered for a long time. And nobody can possibly know if something is true about NSA's knowledge (maybe even not NSA themselves). So even if it's not true — spreading rumors about it is completely fine I guess.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#54

Is this even a legit website? The NSA makes announcements via their Tumblr now? Doesn't that strike anyone else as strange?

If this is "legit," then it's one of the weirdest things ever. I can't see why any official statement wouldn't be under a .gov.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#55

Is this even a legit website? The NSA makes announcements via their Tumblr now? Doesn't that strike anyone else as strange?

No doubt this is part of their PR strategy. "Look, we use Tumblr just like you. We don't have any fancy blogging platform. In fact, we don't have any fancy tool at all. All we do is boring administrative work."

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#56

Last sentence reads: "Unless there is a clear national security or law enforcement need, this process is biased toward responsibly disclosing such vulnerabilities." So, should the NSA decide that there is a national security interest or law enforcement need, they will not disclose such vulnerabilities. Given their past behavior and explanations for what was considered acceptable compromise for national security, I am…

[deleted]

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#58
First, tumblr? Really?

Second:

"When Federal agencies discover a new vulnerability in commercial and open source software – a so-called “Zero day” vulnerability because the developers of the vulnerable software have had zero days to fix it – it is in the national interest to responsibly disclose the vulnerability rather than to hold it for an investigative or intelligence purpose."

This is demonstrably false. That's not even a point of debate, by their own admission.

The whole statement is worthless.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#59

Last sentence reads: "Unless there is a clear national security or law enforcement need, this process is biased toward responsibly disclosing such vulnerabilities." So, should the NSA decide that there is a national security interest or law enforcement need, they will not disclose such vulnerabilities. Given their past behavior and explanations for what was considered acceptable compromise for national security, I am…

Their statement would carry much more weight if they could point to one example of an exploitable zero-day they've actually disclosed.

I don't particularly trust the NSA, but this example probably exists.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#60
post #47

Earlier quoted context omitted.

we need to begin putting government officials in prison for this.

Unfortunately that "we" is the government officials themselves.

Clapper couldn't divulge the existence of a classified program in an open session hearing. If they really wanted answers vs. trying to grill the NSA in a public forum they could have asked the question in a closed session with only participants who've met the proper clearance level for said program disclosures.

Unfortunately on HN anything NSA related is going to devolve into conspiracy theory groupthink these days vs. actual rational discussion that the NSA is not all knowing (unlike every other government agency which is apparently incompetent).

Post reply on HN