Live data from Hacker News

Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

icontherecord.tumblr.com

61–70 of 120 posts

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#61

Is this even a legit website? The NSA makes announcements via their Tumblr now? Doesn't that strike anyone else as strange?

It appears the answer to the first question is yes: http://www.odni.gov/index.php/carousel-items/916-the-intelli...

As for the second question, yes, it does seem strange.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#62
post #48

Sincere question: is the NSA on record for having responsibly disclosed any previous security holes? Is there some track record of them having actively help close security holes in software?

The most famous example is the DES S-boxes, where the NSA made a change that nobody else understood - until years later, when it was discovered that they had made the algorithm more secure against cryptanalysis techniques that had just been "discovered", but which had evidently been known to NSA long before.

To expand on the DES example, the S-boxes are essentially large 'random' lookup tables. The NSA took the S-boxes, and replaced them with their own tables. At the time, it was not clear if this was to protect against an unknown attack, or to introduce an unknown attack (which may involve knowing some secret key used to generate the S-boxes).

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#64
I haven't seen this mentined in this thread yet, so I just want to remind everyone of the Suxnet virus that contained four 0day vulnerabilities and was in active deployment from anywhere between two to five years. If you believe that they were the originators of this virus then this directly contradicts the claim that 0days are responsibly disclosed in a timely manner.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#65
post #19

In other news, NSA thinks responsible disclosure is the way to go but apparently has no 0days to responsibly disclose. I didn't know TAO sucked so hard. Can't see how any one will buy this.

I was actually inclined to give them the benefit of the doubt, but your point actually sort of makes sense. I don't like this feeling of not knowing where the boundary between wacko conspiracy theory and ... y'know ... real life ... begins and ends.

If they're not lying, that's arguably worse!

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#67
That the Bloomberg report resulted in a denial so quickly demonstrates the defensive position of US intelligence services today.

Strong suspicion that the a federal agency would withhold vital info about Heartbleed is a direct result of the shocking revelations of mass-surveillance.

I believe the sentiment expressed around this issue is not entirely contained to Heartbleed.

This is about distrust of the federal government to make good administrative decisions around highly technical issues that affect the public. Keep in mind Kathleen Sebelius just resigned largely due to optics around IT management failures.

Widespread distrust of federal organizations ability to manage technology appropriately will only erode faith in federal government as a whole. That's not a good problem to have.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#68

Just keep in mind that the NSA routinely lies... even in direct testimony under oath to Congress. http://www.slate.com/articles/news_and_politics/war_stories/...

we need to begin putting government officials in prison for this.

I agree! I don't think anything will change until doing such crimes results in jail.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#70

Last sentence reads: "Unless there is a clear national security or law enforcement need, this process is biased toward responsibly disclosing such vulnerabilities." So, should the NSA decide that there is a national security interest or law enforcement need, they will not disclose such vulnerabilities. Given their past behavior and explanations for what was considered acceptable compromise for national security, I am…

I suppose "need" is synonymous with "desire" or "usefulness".
Post reply on HN