Has the NSA Been Using the Heartbleed Bug?
1–10 of 23 posts
Re: Has the NSA Been Using the Heartbleed Bug?
#2Re: Has the NSA Been Using the Heartbleed Bug?
#3Re: Has the NSA Been Using the Heartbleed Bug?
#4Re: Has the NSA Been Using the Heartbleed Bug?
#5Yeah, having to collect and process all that random data... I'm sure they gave up after a couple weeks.
Re: Has the NSA Been Using the Heartbleed Bug?
#6Re: Has the NSA Been Using the Heartbleed Bug?
#7Has the NSA ever used a 0day to access a machine they were interested in?
Are the people that work for the NSA likely to be smart enough to realise the NSA's upside in finding security flaws and not telling people about them?
Will the NSA have ever done a security review of popular opensource libraries?
I'm not begging the question. What we know is incomplete. However, answer those questions yourself and then imagine how you might answer those questions if you were rich, liked playing dirty, full of smart people, and in a position of power. That's as good a bet as any on what might have been going on.
My two cents: all that is needed is a small crack in security. I wouldn't bet on the internet being secure, because men and women are fallible and security is complex.
Re: Has the NSA Been Using the Heartbleed Bug?
#8Can you imagine those guys doing anything remotely evil, like extracting metadata and data of anything they could get their hands on?
Re: Has the NSA Been Using the Heartbleed Bug?
#9This is a fundamentally different situation than a backdoor in a parameterized encryption standard, such as ECDSA (which is often referenced in these discussions): there, only the people who built the backdoor can use the backdoor. Here, the backdoor exists in a shared resource, waiting for others--including your enemies--to take advantage of; that's quite a risk, and unless you've been seeing some weird behavior--such as the NSA distributing heartbeat-disabled builds of OpenSSL for any potential government usage--I think it is a horrible stretch to believe that they've been sitting on this bug (or even having themselves planted the bug), using it as the long-term surveillance means that some people seem to be want to believe.
Frankly, the fact that they've been logging SSL traffic is enough: for systems without perfect forward security, if they don't already have the keys through other means, they just wait for an opportunity like yesterday and then attempt to quickly get the keys they want. I would almost go so far as to claim the NSA was being negligent in their strategy (not that I like this strategy, mind you) if they didn't follow through to that point. But I just don't see it as being rational to believe the NSA is willing to make our own country's secrets less secure if they are seeing benefits using the bug against others; if anything, I could see them trying to secretly (so as not to tip their hand as having had any advanced notice) fix the bug (after using it for a short time period to pull a bunch of keys, of course ;P).