Live data from Hacker News

NSA Director Says Agency Shares Vast Majority of Bugs It Finds

threatpost.com

11–20 of 62 posts

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#12
So they share a "vast majority," but still keep many to themselves because they don't think anyone else is persistent enough to find them ("How likely are others to find it?"), in addition to telling a lie about developing the fix for Heartbleed. Nothing new here.

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#13
post #5
post #4

Earlier quoted context omitted.

> Facebook and Microsoft donate $US15,000 to Neel Mehta via the Internet Bug Bounty program for finding the OpenSSL bug. Hm. I didn't know that MS would be involved in this as well since they're not really affected by this.

They run a bunch of Linux servers (Azure), so they were affected.

How come that MS runs Linux on some Azure serves?

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#15
post #13
post #5

Earlier quoted context omitted.

They run a bunch of Linux servers (Azure), so they were affected.

How come that MS runs Linux on some Azure serves?

Because some people want Linux and will pay them for Linux hosting

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#16
post #13
post #5

Earlier quoted context omitted.

They run a bunch of Linux servers (Azure), so they were affected.

How come that MS runs Linux on some Azure serves?

MS's customers can run Linux on Azure. Although I'm sure somewhere out there MS must have had a Linux server affected by this..

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#18
post #2

In the video of that discussion[1] he also says that NSA developed the Heartbleed patch after hearing about the vulnerability on April 7 and shared with the private sector on April 8. Interesting to compare with timeline: http://www.smh.com.au/it-pro/security-it/heartbleed-disclosu... [1] https://www.youtube.com/watch?v=yhwy2ZWi_y8

So, this is going to sound like I'm determined to find a reason to hate the NSA, but.. this doesn't make them look good either. It's the most accessible and widely-deployed memory disclosure bug of recent years, if not ever. Surely there are at least 1000 vulnerable (at the time) servers they'd specifically love to have this window into, for intelligence on the "bad guys." Surely they know the "bad guys" would love to look into and attack American servers the same way. Exploiting and defending this kind of thing is exactly what the NSA is supposedly for, but they're telling us they didn't know about it.

I guess all their good talent and money was tied up in domestic call metadata social graph analysis. But at least they had someone smart enough to do the trivial patch once the vulnerability was known![0]

P.S. I also notice they didn't mention "Shellshock". Why not?

[0] https://twitter.com/agl__/status/530004568784916480

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#19
post #13
post #5

Earlier quoted context omitted.

They run a bunch of Linux servers (Azure), so they were affected.

How come that MS runs Linux on some Azure serves?

Astonishingly, they cater to the needs of their customers and fully support linux.

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#20
post #5
post #4

Earlier quoted context omitted.

> Facebook and Microsoft donate $US15,000 to Neel Mehta via the Internet Bug Bounty program for finding the OpenSSL bug. Hm. I didn't know that MS would be involved in this as well since they're not really affected by this.

They run a bunch of Linux servers (Azure), so they were affected.

There were extremely few instances where Microsoft was affected by Heartbleed and was running very few Linux servers (in noncritical functions). These very few instances were enumerated and closed almost immediately. There is only one team I know of that was affected - however a scan was done to confirm this.

Patching for customers in Azure can be done through normal OS channels, though patches can be forced and base images an be modified to close holes (this was done).

Post reply on HN