Is this even a legit website? The NSA makes announcements via their Tumblr now? Doesn't that strike anyone else as strange?
As for the second question, yes, it does seem strange.
61–70 of 120 posts
Is this even a legit website? The NSA makes announcements via their Tumblr now? Doesn't that strike anyone else as strange?
As for the second question, yes, it does seem strange.
Sincere question: is the NSA on record for having responsibly disclosed any previous security holes? Is there some track record of them having actively help close security holes in software?
The most famous example is the DES S-boxes, where the NSA made a change that nobody else understood - until years later, when it was discovered that they had made the algorithm more secure against cryptanalysis techniques that had just been "discovered", but which had evidently been known to NSA long before.
Are we sure this isn't a parody?
In other news, NSA thinks responsible disclosure is the way to go but apparently has no 0days to responsibly disclose. I didn't know TAO sucked so hard. Can't see how any one will buy this.
I was actually inclined to give them the benefit of the doubt, but your point actually sort of makes sense. I don't like this feeling of not knowing where the boundary between wacko conspiracy theory and ... y'know ... real life ... begins and ends.
I sure hope Mr. Snowden has evidence to the contrary.
Strong suspicion that the a federal agency would withhold vital info about Heartbleed is a direct result of the shocking revelations of mass-surveillance.
I believe the sentiment expressed around this issue is not entirely contained to Heartbleed.
This is about distrust of the federal government to make good administrative decisions around highly technical issues that affect the public. Keep in mind Kathleen Sebelius just resigned largely due to optics around IT management failures.
Widespread distrust of federal organizations ability to manage technology appropriately will only erode faith in federal government as a whole. That's not a good problem to have.
Just keep in mind that the NSA routinely lies... even in direct testimony under oath to Congress. http://www.slate.com/articles/news_and_politics/war_stories/...
we need to begin putting government officials in prison for this.
Last sentence reads: "Unless there is a clear national security or law enforcement need, this process is biased toward responsibly disclosing such vulnerabilities." So, should the NSA decide that there is a national security interest or law enforcement need, they will not disclose such vulnerabilities. Given their past behavior and explanations for what was considered acceptable compromise for national security, I am…