Live data from Hacker News

Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

icontherecord.tumblr.com

91–100 of 120 posts

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#91
post #4

Letting a bug/vuln this broad go unpatched for years for the NSA's own benefit is beyond negligent concerning our nation's security.

Practically treasonous. As they say, lots of important things protected by OpenSSL, and if the NSA did know about it two years ago, when did similar organizations in other governments spot it?

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#92
post #83

Earlier quoted context omitted.

Either way Clapper would be breaking the law. In this case was placed between the choice of breaking his SF-182 NDA (which actually does have criminal implications... just ask Snowden) or lying to Congress in response to a question that the Congressman asking knew the answer to, but didn't want to take the risk of putting into the record himself. An interesting take on the matter is at http://joelbrenner.com/clapper-…

The questions were pre-approved. He could have objected to it beforehand, in private.

That's immaterial though. The questioner knew the answer was classified, so it's not as if that was a surprise, because the questioner was a member of the Select Committee on Intelligence. In other words, he wasn't asking for his own edification, he was asking in order to force Clapper to either lie or break his oath by divulging the secret. Even saying "I can't answer that" would be an admission for the same exact reason hacktivists give a shit about warrant canaries.

But whether Clapper objected or not, Sen. Feinstein apparently got an inkling the question would be asked, as she made clear at the start of the session that there would be a closed hearing immediately afterward for questions that couldn't be discussed in an open forum.

And since Wyden and Udall both knew the actual answer, if they were so convinced the answer should be made public then either could have simply put it in the Senate record thanks to their Constitutional privilege and taken the risk that would come with that. Instead the risk was shifted entirely onto the public servant who didn't have Constitutional immunity from prosecution.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#93
post #75
post #40

Earlier quoted context omitted.

NSA was not aware of the recently identified vulnerability in OpenSSL, the so-called Heartbleed vulnerability, until it was made public in a private sector cybersecurity report Or perhaps the "private sector cybersecurity report" was a IRC chat two years ago for l33t haxors.

They went on to: "Reports that NSA or any other part of the government were aware of the so-called Heartbleed vulnerability before April 2014 are wrong." so there's no weasel-wording going on here.

That could mean anything from "there was a typo" to "there were factual omissions that were unknown to the author".

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#94
post #47

Earlier quoted context omitted.

we need to begin putting government officials in prison for this.

Unfortunately that "we" is the government officials themselves.

Isn't separation of powers meant to prevent such things?

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#95
post #92

Earlier quoted context omitted.

The questions were pre-approved. He could have objected to it beforehand, in private.

That's immaterial though. The questioner knew the answer was classified, so it's not as if that was a surprise, because the questioner was a member of the Select Committee on Intelligence. In other words, he wasn't asking for his own edification, he was asking in order to force Clapper to either lie or break his oath by divulging the secret. Even saying "I can't answer that" would be an admission for the same exact r…

It's entirely material as to whether it was forced. Clapper knowingly permitted himself to be in a situation where his only options were to break one of two laws. He can't then use that as an excuse. He chose to break one of those laws when he chose (when reviewing the questions) that he was going to permit the question, and he's plainly guilty of breaking the law.

"And since Wyden and Udall both knew the actual answer, if they were so convinced the answer should be made public then either could have simply put it in the Senate record thanks to their Constitutional privilege and taken the risk that would come with that."

Agreed, and I would think more highly of them if they had. I'm not sure what the game was. That still does not change the fact that Clapper is guilty, though.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#96
post #75
post #40

Earlier quoted context omitted.

NSA was not aware of the recently identified vulnerability in OpenSSL, the so-called Heartbleed vulnerability, until it was made public in a private sector cybersecurity report Or perhaps the "private sector cybersecurity report" was a IRC chat two years ago for l33t haxors.

They went on to: "Reports that NSA or any other part of the government were aware of the so-called Heartbleed vulnerability before April 2014 are wrong." so there's no weasel-wording going on here.

Perhaps they're using the etymological root of aware, which is "wary", and they mean they were unconcerned with its existence as they were unwary/unaware of any possible dangers with it since it was unknown to hostile forces.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#97
post #41
post #33

Earlier quoted context omitted.

Or they straight out lied. Wouldn't be the first time.

Or they didn't. See, now we have complete set of possible answers! So, what does it means when NSA officially announces something? I'd say, it means nothing.

If they did know, they would not admit it.

Maybe they didn't know. But we certainly do not have the right to know if they did know or not. This means something.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#98
post #47

Earlier quoted context omitted.

Unfortunately that "we" is the government officials themselves.

Clapper couldn't divulge the existence of a classified program in an open session hearing. If they really wanted answers vs. trying to grill the NSA in a public forum they could have asked the question in a closed session with only participants who've met the proper clearance level for said program disclosures. Unfortunately on HN anything NSA related is going to devolve into conspiracy theory groupthink these days v…

Clapper always had the option to decline answering a question. Choosing instead to lie means something.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#99

Earlier quoted context omitted.

http://www.odni.gov/index.php/carousel-items/916-the-intelli...

You just can't make this sh*t up: the "No Fear Act".

Or "Notification and Federal Employee Antidiscrimination and Retaliation Act".

Does legislation that can't be summarized in a clumsy acronym ever get passed? I can just imagine cabinet meetings: "Sure, world peace is a nice idea, but we can't think of terrible enough acronym for it, so we've decided against it."

Post reply on HN