Live data from Hacker News

NSA Director Says Agency Shares Vast Majority of Bugs It Finds

threatpost.com

1–10 of 62 posts

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#2
In the video of that discussion[1] he also says that NSA developed the Heartbleed patch after hearing about the vulnerability on April 7 and shared with the private sector on April 8.

Interesting to compare with timeline: http://www.smh.com.au/it-pro/security-it/heartbleed-disclosu...

[1] https://www.youtube.com/watch?v=yhwy2ZWi_y8

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#3
That must be an interesting decision to make. Presumably, they'd only keep quiet about bugs they were fairly confident that unfriendly governments weren't also likely to find and exploit. I assume they'd also launch a big honeypot, so if someone else started to exploit it they could could change strategies.

It's the New New Great Game.

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#4
post #2

In the video of that discussion[1] he also says that NSA developed the Heartbleed patch after hearing about the vulnerability on April 7 and shared with the private sector on April 8. Interesting to compare with timeline: http://www.smh.com.au/it-pro/security-it/heartbleed-disclosu... [1] https://www.youtube.com/watch?v=yhwy2ZWi_y8

> Facebook and Microsoft donate $US15,000 to Neel Mehta via the Internet Bug Bounty program for finding the OpenSSL bug.

Hm. I didn't know that MS would be involved in this as well since they're not really affected by this.

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#5
post #4
post #2

In the video of that discussion[1] he also says that NSA developed the Heartbleed patch after hearing about the vulnerability on April 7 and shared with the private sector on April 8. Interesting to compare with timeline: http://www.smh.com.au/it-pro/security-it/heartbleed-disclosu... [1] https://www.youtube.com/watch?v=yhwy2ZWi_y8

> Facebook and Microsoft donate $US15,000 to Neel Mehta via the Internet Bug Bounty program for finding the OpenSSL bug. Hm. I didn't know that MS would be involved in this as well since they're not really affected by this.

They run a bunch of Linux servers (Azure), so they were affected.

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#6
post #2

In the video of that discussion[1] he also says that NSA developed the Heartbleed patch after hearing about the vulnerability on April 7 and shared with the private sector on April 8. Interesting to compare with timeline: http://www.smh.com.au/it-pro/security-it/heartbleed-disclosu... [1] https://www.youtube.com/watch?v=yhwy2ZWi_y8

Google's Adam Langley: Nope - https://twitter.com/agl__/status/530004568784916480

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#9
So, the NSA are, to a person, lying sacks of shit. After their director's performance in front on congress -- the "least untruthful answer possible" -- don't trust a damn word.

So when they say they share, with whom? And what priority? Ooh, you found a documentation bug; is that the one you chose to share? The more severe a bug is, the more useful to them.

There's a million ways to parse this bullshit that come down to mean they're doing what they did all along but better at lying in public.

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#10
post #2

In the video of that discussion[1] he also says that NSA developed the Heartbleed patch after hearing about the vulnerability on April 7 and shared with the private sector on April 8. Interesting to compare with timeline: http://www.smh.com.au/it-pro/security-it/heartbleed-disclosu... [1] https://www.youtube.com/watch?v=yhwy2ZWi_y8

I'd say this is a case of non-technical people being told by coworkers the "issue was fixed and the patch is public" on April 8th [after OpenSSL patches it] and confuses it with his coworkers creating the solution.

I'm just depressed because I suspect many people will start claiming the NSA solved Heartbleed. :/

Post reply on HN