Live data from Hacker News

Has the NSA Been Using the Heartbleed Bug?

wired.com

11–20 of 23 posts

Re: Has the NSA Been Using the Heartbleed Bug?

#11
post #9

One point that sometimes comes up in these conversations--but frankly I think not often enough--is that the NSA does not have a monopoly on the world's brightest engineers and mathematicians: if the NSA knows of a bug, one has to wonder if China, or Russia, also has access to the same bug. The ramifications of this would be the NSA not only being able to see other people's secure traffic, but the potential for our tr…

Uhm, as NSA and other agencies are responsible for "secure" internal comm, they have methods for that. Sometimes they get broken, probably, but thats their mission to find out, and sometimes let the enemy continue thinking their breakin is effective.

Its the same methods as in 1940, that is, classic intel methods.

Security does not just mean strong crypto algorithms.

If you find your enemy has found a flaw in openssl or some other methods which you are using to communicate - the best way forward is to continue using that - keep the enemy thinking its all good information when its in fact worthless, and move to another method for the real secure stuff, such as steganography or pidgeons.

Anyway, there probably isnt much "really highly, this kills the cat"-type of information goin on the internets, I guess one point of NSA would also be to keep highly classified information to a minimum. Think thats one reason why Navy and others have their own networks parallel to the internet. Where much secrets flow - isolate.

Re: Has the NSA Been Using the Heartbleed Bug?

#12

I would think that the NSA would be opening themselves up to quite a firestorm if they were found to be exploiting this bug without saying a word about it. I very much doubt they were making use of this for the simple fact that, by not disclosing, they'd be allowing this gaping hole to potentially be used by "enemy" governments, which is the exact opposite of what they want.

If they knew about this, they used it, and they told or by other means deactivated heartbeat for sensitive systems of USA, and using honeypots to see if the Russians and Chinese have figured it out too.

Then when their honeypots attract alot of bees, is time to tell Google to seal the hole, to protect all the medium sensitivity networks and info.

Re: Has the NSA Been Using the Heartbleed Bug?

#14
Why bother? There are a million different ways to own servers available to the security services that require little to no expertise, from compromising the engineers, the physical servers, the CAs, or plain legal intimidation. Even if the NSA had heartbleed they wouldn't have needed to use it.

Re: Has the NSA Been Using the Heartbleed Bug?

#15
For the sake of argument, swap out 'NSA' for any large state actor - it's silly to ask this specifically of the NSA and most of the attention is around them because of the Snowden leaks.

Now, would a large state actor involved in offensive black hat hacking have known of heartbleed? I think the answer is likely yes.

Any decently funded team with a dozen good auditors to commit to the project would be watching popular open source projects like openssl, linux, chromium, firefox, apache, nginx, gnupg, openssh, boost, gmp, berkeley db, qt, gtk, etc.

For this part of the project, you only have to grep for low hanging fruit in each new patch that is released for each project, that is usage of: gets, scanf, strncpy, strncat, memcpy etc (or the equivalents for each project that has wrappers or handling functions).

Any large state actor with any decent team running such a project would have discovered heartbleed within days of it being committed. They also would have discovered a lot of other bugs that we either don't know about yet or have fixed.

With heartbleed the state actors are kicking themselves either way: either because they didn't know about the bug and missed it, or they did know about the bug and now can no longer use it as effectively.

"They" (and you can include black hat groups that don't disclose in this as well) combined likely have more resources dedicated to uncovering these bugs than what the open community does, and it might be an order of magnitude larger.

When you think about this further, you realize that the state actors having discovered heartbleed or not doesn't matter - what does matter is that they do have a lot of exploits that we don't know about and it has been confirmed that they are not only looking for these bugs and have a lot of people working on it, but are actively discovering them, using them and purchasing them on the market.

The response to this shouldn't be heartbleed specific - it should be what do "we" do to stop "them" from discovering and using exploits from open source and projects. There needs to be a heck of a lot more effort or a whole new approach to defeat the level resources that are out there dedicated to uncovering and not disclosing these exploits.

The best thing that could have happen did happen: heartbleed was discovered and it was disclosed, and a hell of a lot of people are now more aware of just how frail some of this infrastructure is and what the risks are.

Re: Has the NSA Been Using the Heartbleed Bug?

#16
The answer is, they are still using it. The spoil is not over. Even old keys are good. They can be used with the data they have already there in the basement.

Disclaimer: All characters and events appearing in my comment are fictitious. Any resemblance to real events or persons, living or dead, is purely coincidental.

Re: Has the NSA Been Using the Heartbleed Bug?

#17
post #11
post #9

One point that sometimes comes up in these conversations--but frankly I think not often enough--is that the NSA does not have a monopoly on the world's brightest engineers and mathematicians: if the NSA knows of a bug, one has to wonder if China, or Russia, also has access to the same bug. The ramifications of this would be the NSA not only being able to see other people's secure traffic, but the potential for our tr…

Uhm, as NSA and other agencies are responsible for "secure" internal comm, they have methods for that. Sometimes they get broken, probably, but thats their mission to find out, and sometimes let the enemy continue thinking their breakin is effective. Its the same methods as in 1940, that is, classic intel methods. Security does not just mean strong crypto algorithms. If you find your enemy has found a flaw in openssl…

These are fair points, but I think the GP comment above was referring as much to political economy type espionage.

Say, for example, china wants to spy on a military contractor. Unless the NSA is sharing its secure pigeon network with every US defense contractor (and many of them, large and small) some pretty important US national security assets might be in play. So, perhaps not "state secrets" but things like technology inside of some tactical weapons guidance systems, or similar. The downside for the NSA of sharing any secret-pigeon networks would op-sec goes down as info dispersal goes up.

* Also for companies like a tesla or a space-x who may have purely industrial know how.

Re: Has the NSA Been Using the Heartbleed Bug?

#18
post #4

I would take anyone for a fool who thought the NSA hasn't been using heartbleed.

I take anyone as a fool who thinks the NSA is the only spy agency that does such things.

It's not an exclusive statement. The safe bet is that both the NSA and other spy agencies around the world have been using the openSSL hole.

If the NSA has not, they're incompetent.

Re: Has the NSA Been Using the Heartbleed Bug?

#19
post #15

For the sake of argument, swap out 'NSA' for any large state actor - it's silly to ask this specifically of the NSA and most of the attention is around them because of the Snowden leaks. Now, would a large state actor involved in offensive black hat hacking have known of heartbleed? I think the answer is likely yes. Any decently funded team with a dozen good auditors to commit to the project would be watching popular…

Excellent response Nik. I write from Laos, where one of the TPB guys apparently lives in exile, next door to where another was extradited, and next door to where lots of exploits apparently get sold (according to certain media reports and personal interactions). This whole thing is invisible to normal people. The bigger question is how can we educate the masses without reliance upon government. I think a global network of free wifi with knowledge libraries people can access on their cellphones would be a good start. Off the internet.

Re: Has the NSA Been Using the Heartbleed Bug?

#20
post #9

One point that sometimes comes up in these conversations--but frankly I think not often enough--is that the NSA does not have a monopoly on the world's brightest engineers and mathematicians: if the NSA knows of a bug, one has to wonder if China, or Russia, also has access to the same bug. The ramifications of this would be the NSA not only being able to see other people's secure traffic, but the potential for our tr…

I mostly agree with this analysis - "this hole is too big for them to have sat on". Though it just occurred to me - it's possible to pick out exploit of this hole in captured encrypted traffic by examining sizes of inbound vs outbound heartbeat packets, right? In that case, with the NSA eavesdropping on everything they could possibly have been using it themselves while listening for examples of anyone else using it, which I still don't like (in terms of approval or likelihoods) but seems less flagrantly unacceptable than sitting on this and just leaving everyone's traffic and keys exposed to the world.
Post reply on HN