Live data from Hacker News

NSA Said to Exploit Heartbleed Bug for Intelligence for Years

bloomberg.com

11–20 of 192 posts

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#12
post #4

My first thought: if this is the case, then why did they try so hard (and get "trolled" in the progress) to get the SSL keys from Lavabit?

Get the proof via nefarious ways and then construct a "legitimate" way of obtaining the information you already have.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#15
post #4

My first thought: if this is the case, then why did they try so hard (and get "trolled" in the progress) to get the SSL keys from Lavabit?

As an example from history, see the story about the zimmerman telegram http://en.wikipedia.org/wiki/Zimmermann_Telegram and the british interception and decryption. They faked a theft to hide the fact that they were reading the traffic with the help of Room 40.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#16
post #13

Do we have anything that leads us to believe the NSA was aware of heartbleed at all before we found out, other than speculation because of their resources?

Why would you give them the benefit of the doubt? If anything, the base assumption should be the reverse.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#20

No fucking way. This is disastrous PR stuff, second only to the Snowden revelations. It should be clear by now that the NSA does not restrict themselves from anything... and should be disbanded.

I don't know how "disastrous" this really is.

NSA knows approximately 1 zillion vulnerabilities we don't know about and won't know about. They range from RCE's in Windows and Apache to flaws in cryptographic hash functions.

It's NSA's charter to stockpile these things, and, yeah, to use them against foreign adversaries.

It's bad though, because this one was so easily exploitable. It's the kind of thing a reasonable organization finds out about and wants fixed ASAP.

Post reply on HN