Live data from Hacker News

Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

icontherecord.tumblr.com

101–110 of 120 posts

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#101

Earlier quoted context omitted.

Clapper couldn't divulge the existence of a classified program in an open session hearing. If they really wanted answers vs. trying to grill the NSA in a public forum they could have asked the question in a closed session with only participants who've met the proper clearance level for said program disclosures. Unfortunately on HN anything NSA related is going to devolve into conspiracy theory groupthink these days v…

Clapper always had the option to decline answering a question. Choosing instead to lie means something.

Interesting to note that in Asian languages there is actually a word for "neither yes nor no":

http://en.wikipedia.org/wiki/Mu_(negative)#.22Unasking.22_th...

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#102

Earlier quoted context omitted.

Clapper couldn't divulge the existence of a classified program in an open session hearing. If they really wanted answers vs. trying to grill the NSA in a public forum they could have asked the question in a closed session with only participants who've met the proper clearance level for said program disclosures. Unfortunately on HN anything NSA related is going to devolve into conspiracy theory groupthink these days v…

Clapper always had the option to decline answering a question. Choosing instead to lie means something.

Declining is the same as acknowledging in this context, which he couldn't do.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#103
post #93
post #75

Earlier quoted context omitted.

They went on to: "Reports that NSA or any other part of the government were aware of the so-called Heartbleed vulnerability before April 2014 are wrong." so there's no weasel-wording going on here.

That could mean anything from "there was a typo" to "there were factual omissions that were unknown to the author".

Or, it could mean you're just be pedantic.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#104

Earlier quoted context omitted.

Clapper couldn't divulge the existence of a classified program in an open session hearing. If they really wanted answers vs. trying to grill the NSA in a public forum they could have asked the question in a closed session with only participants who've met the proper clearance level for said program disclosures. Unfortunately on HN anything NSA related is going to devolve into conspiracy theory groupthink these days v…

The list of questions was pre-approved. When he made the decision to approve that question, he made the decision to perjure himself. Edited to add: Or at least, the decision to break the law. Which law may have been decided later.

There was nothing pre-approved about the question. Senator Wyden said he sent notice a day in advance that he would be asking the question. The ODNI General Counsel said that Clapper hadn't seen the question prior to the Senate hearing, and tried to correct it after the fact. [1]

Keep in mind that this was a program that everyone on the intelligence committee had already been briefed on. You could make the argument that he misled the American public, but not Congress. Also note that since the intelligence committee knew about the program, any one of the members could have also issued a public statement clarifying the situation, but they didn't.

People liked to harp on Clapper, but Wyden was the one who, instead of just telling his constituents himself (he wouldn't be subject to prosecution, but might have been kicked off the intelligence committee) or putting forth legislation restricting Section 215 collection, decided to put the DNI in the position of either violating the law by disclosing a classified program or telling the American public the "least untruthful" statement.

[1] http://mobile.nytimes.com/2014/01/04/opinion/testimony-of-th...

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#105
post #19

In other news, NSA thinks responsible disclosure is the way to go but apparently has no 0days to responsibly disclose. I didn't know TAO sucked so hard. Can't see how any one will buy this.

Is it possible that they've quietly disclosed to affected organizations/teams, but that those organizations don't want to publicly credit the NSA as their source?

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#106
Why is there a scarcity of comments here questioning the Bloomberg article? For that matter, why was there a scarcity of discussion questioning Reuters' December '13 article about RSA and Dual EC? Neither provided any evidence for their claims, and I presume that, in both cases, the information was obtained from anonymous sources who could not provide documentation a' la Snowden.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#107
The NSA has already proven that its willing to lie to the public, not just omit information or mislead, when its talking about something the agency considers related to National security. Of course it's still possible they could be telling the truth in this instance, and Bloomberg could have failed to properly vet its sources. However, taking the recent past into account I think most people would agree it is far more likely that Bloomberg is providing accurate information and the NSA is not.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#108
post #14

What if they have a unique definition of 'vulnerability', much like they had a unique definition of 'collect'? As a bit of internal jargon, the NSA only considered information 'collected' when an analyst looked at it. So, they could record & store bulk data about all Americans, but still claim (with a secret wink) that they didn't intentionally "collect" data on Americans. Maybe for them, 'vulnerability' means both "…

The NSA doesn't need to redefine "Vulnerability" or use any other jargon. When it comes to issues the government considers related to national security, they don't bother to hide behind convoluted language or misleading information, the NSA has already demonstrated it's willing to flat out lie to the public regarding such matters.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#109
post #47

Earlier quoted context omitted.

Unfortunately that "we" is the government officials themselves.

Clapper couldn't divulge the existence of a classified program in an open session hearing. If they really wanted answers vs. trying to grill the NSA in a public forum they could have asked the question in a closed session with only participants who've met the proper clearance level for said program disclosures. Unfortunately on HN anything NSA related is going to devolve into conspiracy theory groupthink these days v…

Either you're allowed to lie to congress when you're under oath or you're not. You can't have shades of grey or the law becomes utterly useless.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#110
post #47

Earlier quoted context omitted.

Unfortunately that "we" is the government officials themselves.

Clapper couldn't divulge the existence of a classified program in an open session hearing. If they really wanted answers vs. trying to grill the NSA in a public forum they could have asked the question in a closed session with only participants who've met the proper clearance level for said program disclosures. Unfortunately on HN anything NSA related is going to devolve into conspiracy theory groupthink these days v…

The files Snowden leaked seem to imply that the NSA is both all knowing AND incompetent.
Post reply on HN