Live data from Hacker News

Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

icontherecord.tumblr.com

71–80 of 120 posts

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#71
post #47

Earlier quoted context omitted.

Unfortunately that "we" is the government officials themselves.

Clapper couldn't divulge the existence of a classified program in an open session hearing. If they really wanted answers vs. trying to grill the NSA in a public forum they could have asked the question in a closed session with only participants who've met the proper clearance level for said program disclosures. Unfortunately on HN anything NSA related is going to devolve into conspiracy theory groupthink these days v…

Only in your books would not accepting an official position qualify as groupthink. It's kind of hilarious. Oh, and Clapper lied because they made him, and thinking otherwise makes you a wacky conspiratard. Real mature..

Edit: Question for you - do you think there isn't a conspiracy here? Do you think the public has all the information about the legality of the executive branches activities? Because it sounds like Clapper was lying to cover his ass - but that's just conspiracy think.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#72

If this is true, and the NSA knew about the Heartbleed vulnerability, then how come the EFF hasn't been getting more log data showing the vulnerability being exploited against sites? How come, so far, only one person has thus far come forward with ANY evidence that might demonstrate a knowledge of this bug before it was discovered? I just find it depressing how ready the media is to jump on the NSA for things they ma…

> If this is true, and the NSA knew about the Heartbleed vulnerability, then how come the EFF hasn't been getting more log data showing the vulnerability being exploited against sites?

I don't know how common the "extensive TLS-layer traffic logs" the EFF is soliciting are. I know I don't collect these.

I'd imagine the NSA would use such things fairly sparingly so as to not blunt their swords. Using it willy-nilly increases the chances of someone going "huh, that's odd traffic" and discovering it.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#73

First, tumblr? Really? Second: "When Federal agencies discover a new vulnerability in commercial and open source software – a so-called “Zero day” vulnerability because the developers of the vulnerable software have had zero days to fix it – it is in the national interest to responsibly disclose the vulnerability rather than to hold it for an investigative or intelligence purpose." This is demonstrably false. That's…

"First, tumblr? Really?"

That was my first reaction too. I'm probably late to the party on this, but when I saw the tumblr domain I thought it was some kind of satire at first.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#75
post #40
post #14

What if they have a unique definition of 'vulnerability', much like they had a unique definition of 'collect'? As a bit of internal jargon, the NSA only considered information 'collected' when an analyst looked at it. So, they could record & store bulk data about all Americans, but still claim (with a secret wink) that they didn't intentionally "collect" data on Americans. Maybe for them, 'vulnerability' means both "…

NSA was not aware of the recently identified vulnerability in OpenSSL, the so-called Heartbleed vulnerability, until it was made public in a private sector cybersecurity report Or perhaps the "private sector cybersecurity report" was a IRC chat two years ago for l33t haxors.

They went on to: "Reports that NSA or any other part of the government were aware of the so-called Heartbleed vulnerability before April 2014 are wrong." so there's no weasel-wording going on here.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#76
post #25

It does seem like a judgement call is unavoidable. If they discover exploits that are extremely difficult to use, and extremely unlikely to have been discovered by others, it might make sense to use them. But it also seems clear that they should have an obligation to find and make public exploits similar in nature to Heartbleed. Sitting on a bug like this should be a criminal offense.

Use the bug for what purpose? The NSA constantly lies, and also just spies on non-terrorist organizations because terrorism: http://techcrunch.com/2014/04/08/snowden-council-of-europe-t... . They are so beyond deserving the benefit of any doubt.

For spying. No one, least of all Snowden, is calling for an end to the NSA's spying days.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#77
post #75
post #40

Earlier quoted context omitted.

NSA was not aware of the recently identified vulnerability in OpenSSL, the so-called Heartbleed vulnerability, until it was made public in a private sector cybersecurity report Or perhaps the "private sector cybersecurity report" was a IRC chat two years ago for l33t haxors.

They went on to: "Reports that NSA or any other part of the government were aware of the so-called Heartbleed vulnerability before April 2014 are wrong." so there's no weasel-wording going on here.

No, just straight out lying.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#78
I find it a stretch to believe that some part of the NSA didn't know about, and/or have a hand in introducing, Heartbleed. There has to be an NSA team dedicated to both causing and exploiting issues with very popular open source software. If there isn't, the NSA isn't living up to its reputation.

The reality is that we'll never get the truth out of them, and it doesn't matter anyway because nothing they say can be believed. They might as well never say anything. Assume that they have intercepted all of your traffic and have dumps of your RAM, and act accordingly.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#79
post #59

Last sentence reads: "Unless there is a clear national security or law enforcement need, this process is biased toward responsibly disclosing such vulnerabilities." So, should the NSA decide that there is a national security interest or law enforcement need, they will not disclose such vulnerabilities. Given their past behavior and explanations for what was considered acceptable compromise for national security, I am…

Their statement would carry much more weight if they could point to one example of an exploitable zero-day they've actually disclosed. I don't particularly trust the NSA, but this example probably exists.

With regard to the Linux kernel, for example, their policy was to not look for vulnerabilities and only contribute features:

Did you try to fix any vulnerabilities?

No, we did not look for or find any vulnerabilities in the course of our work. We only changed enough to add our new mechanisms.

http://www.nsa.gov/research/selinux/faqs.shtml#I16

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#80
post #9

"The Federal government relies on OpenSSL to protect the privacy of users of government websites and other online services." This is my big point from the other thread. If NSA knew then not disclosing this type of serious bug should get someone's head to roll as it could imperil the security of other important USG communications. That still leaves open the question of why NSA wasn't able to find this bug themselves t…

Has this actually verified? It was only newish versions of OpenSSL that were vulnerable. Websites that ran on IIS and other platforms were not vulnerable. Does anyone have a historical list of critical government websites and their web server versions? An old nmap list would suffice to show that high-priority sites were vulnerable or not.

Many parts of government run Linux, including NSA themselves, other military platforms, and advanced research/development labs. Certainly there's tons of MS, but govvy is just so big that even OpenSSL being rare would still be highly concerning for USG security.
Post reply on HN