Live data from Hacker News

Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

icontherecord.tumblr.com

111–120 of 120 posts

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#111
post #88
post #34

"If the Federal government, including the intelligence community, had discovered this vulnerability prior to last week, it would have been disclosed to the community responsible for OpenSSL." I see numerous disclosures from technology companies, security researchers in industry and academia... but for the life of me, I can't recount an instance in which a disclosure came from intelligence-community researchers. Is th…

Depends on whether things like this are a security disclosure or not (seems not to me, but I'm not a vuln developer): http://lists.x.org/archives/xorg-devel/2010-August/012207.ht... I don't know of better examples though.

I'm also not a vuln developer, but this looks like someone else reported it, and an NSA-affiliated researcher created the patch to fix it.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#112
Well ... that's disappointing!

As a top-notch surveillance organization in a top-notch surveillance state, I've come to expect more from the NSA. If their job is to protect my wimpy life from those rowdy terrorists, they should be at the forefront of all hacking activities and it's really disconcerting that they didn't introduce the bug into the code in the first place. A vulnerability that big deserves a big brother to protect it.

On a more serious note, the NSA is segmented and unaccountable ... I doubt anyone including the director can make a blanket statement guaranteeing that it has or has not done something. In the next installment of the NSA saga, a reporter with access to the Snowden documents will find proof that this is a lie.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#113

Earlier quoted context omitted.

The list of questions was pre-approved. When he made the decision to approve that question, he made the decision to perjure himself. Edited to add: Or at least, the decision to break the law. Which law may have been decided later.

There was nothing pre-approved about the question. Senator Wyden said he sent notice a day in advance that he would be asking the question. The ODNI General Counsel said that Clapper hadn't seen the question prior to the Senate hearing, and tried to correct it after the fact. [1] Keep in mind that this was a program that everyone on the intelligence committee had already been briefed on. You could make the argument t…

That's contrary to what I'd heard, but if it's in fact the case then that does change things a little.

Note that there is again a flagrant lie in the GC's writing there - "Mr. Clapper [...] focused his mind on the collection of the content of Americans’ communications. In that context, his answer was and is accurate." We know now that this is only close to true in any sense with the disingenuous and misleading definition of "collect" the NSA uses - which has no place in ordinary English and deserves no place in legal opinions. Of course, lying in a letter to the editor to the NY Times isn't a crime, but if the GC has no compunctions about wilfully misleading the reader I'm highly skeptical of their other claims.

It's more than a little odd that he wouldn't have looked at the questions in advance - he knew this was a public forum, in which providing the most correct information while not leaking anything seems an important part of his job, and is likely to take some care and forethought.

"Keep in mind that this was a program that everyone on the intelligence committee had already been briefed on. You could make the argument that he misled the American public, but not Congress."

Most of Congress is not on either intelligence committee. Whether misleading them is correct is a deeper discussion, but if the answer is "no" then I think it's fair to say he mislead Congress as well as the American public.

In any case, I agree that Wyden's approach here has been a little odd, though I at least appreciate the direction he's been pushing.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#115

Last sentence reads: "Unless there is a clear national security or law enforcement need, this process is biased toward responsibly disclosing such vulnerabilities." So, should the NSA decide that there is a national security interest or law enforcement need, they will not disclose such vulnerabilities. Given their past behavior and explanations for what was considered acceptable compromise for national security, I am…

It's unfortunate that they have chosen an interpretation base on any current or future need. That wildcard approach means that pretty much everything qualifies.

The law should restrict things to "any current specific known need". Need should be singular and said need must be related to a specific issue or case already under investigation or surveillance. Any language more loose than that leaves open far too much room for interpretation.

They should literally maintain a list of targets they want to infiltrate and that list of targets needs to be open to being audited at some point in the future shortly after the related mission for a target is complete. They should not be allow to apply the vulnerability to any new target identified after the date upon which vulnerability was discovered. These countermeasures would go a long way to prevent abuse since they can't now look at it as a weapon in their arsenal to exploit as they see fit for any future mission.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#116
post #92

Earlier quoted context omitted.

That's immaterial though. The questioner knew the answer was classified, so it's not as if that was a surprise, because the questioner was a member of the Select Committee on Intelligence. In other words, he wasn't asking for his own edification, he was asking in order to force Clapper to either lie or break his oath by divulging the secret. Even saying "I can't answer that" would be an admission for the same exact r…

It's entirely material as to whether it was forced. Clapper knowingly permitted himself to be in a situation where his only options were to break one of two laws. He can't then use that as an excuse. He chose to break one of those laws when he chose (when reviewing the questions) that he was going to permit the question, and he's plainly guilty of breaking the law. "And since Wyden and Udall both knew the actual answ…

> Clapper knowingly permitted himself to be in a situation where his only options were to break one of two laws.

That makes no sense whatsoever. One does not simply refuse to show up to testify to Congress! I mean, if you want to talk about things which are disastrous for a democracy, having the Executive routinely ignore their responsibility to testify on their actions to the Legislature would be right up near the top of the list!

> That still does not change the fact that Clapper is guilty, though.

Of course not, that was the whole idea. If he had told the truth you'd be able to rightly say "That still does not change the fact that Clapper violated his oath, though". There's a reason that he isn't being charged with anything, unlike Helms before him.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#117

Earlier quoted context omitted.

There was nothing pre-approved about the question. Senator Wyden said he sent notice a day in advance that he would be asking the question. The ODNI General Counsel said that Clapper hadn't seen the question prior to the Senate hearing, and tried to correct it after the fact. [1] Keep in mind that this was a program that everyone on the intelligence committee had already been briefed on. You could make the argument t…

That's contrary to what I'd heard, but if it's in fact the case then that does change things a little. Note that there is again a flagrant lie in the GC's writing there - "Mr. Clapper [...] focused his mind on the collection of the content of Americans’ communications. In that context, his answer was and is accurate." We know now that this is only close to true in any sense with the disingenuous and misleading defini…

I don't think it's necessarily odd that he wouldn't have seen the question if it was sent only a day ahead of time. Was there a list of questions that all of the Senators had compiled, or was this just one question independently sent from Sen Wyden's office? Was it sent in the morning or afternoon? What was Clapper doing that day? Was he in his office? Was he out in meetings/briefings all day? If it sat in his inbox for a week I'd be less likely to give him the benefit of the doubt, but there's probably a whole host of reasons that something sent the day prior could have been overlooked.

Was his answer misleading? I definitely agree with you there. Was it a lie? That would imply that it was deliberate, which is tough to prove. He's gone on the record saying that he misunderstood the question and tried to correct it after the fact[1]. If it was deliberate, why lie directly to people that he knows know the truth?

I don't see a flagrant lie in the GC's writing. That quote goes back into the content/metadata issue. There hasn't been any leak so far showing content collection of Americans' communications. All of the debate in Congress regarding these programs has centered around bulk metadata collection. The issue everyone brings up when they accuse Clapper of perjury is the content/metadata issue, not the definition of collection. I haven't seen any government official denying that the NSA collects American cell phone metadata (besides this one instance with Clapper, which he admitted was erroneous).

[1] http://www.lawfareblog.com/wp-content/uploads/2013/07/2013-0...

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#118
post #116

Earlier quoted context omitted.

It's entirely material as to whether it was forced. Clapper knowingly permitted himself to be in a situation where his only options were to break one of two laws. He can't then use that as an excuse. He chose to break one of those laws when he chose (when reviewing the questions) that he was going to permit the question, and he's plainly guilty of breaking the law. "And since Wyden and Udall both knew the actual answ…

> Clapper knowingly permitted himself to be in a situation where his only options were to break one of two laws. That makes no sense whatsoever. One does not simply refuse to show up to testify to Congress! I mean, if you want to talk about things which are disastrous for a democracy, having the Executive routinely ignore their responsibility to testify on their actions to the Legislature would be right up near the t…

"That makes no sense whatsoever. One does not simply refuse to show up to testify to Congress! I mean, if you want to talk about things which are disastrous for a democracy, having the Executive routinely ignore their responsibility to testify on their actions to the Legislature would be right up near the top of the list!"

Of course it makes sense. If the questions were pre-approved as I stated, he would not have had to refuse to show up in order to avoid being put in this situation. He would simply have had to not approve the question - which would have been the most in line with his obligations and least misleading to the rest of congress and the American people.

There is apparently some dispute as to whether the questions were, in fact, pre-approved. But as you hadn't contested it, I think it's fair that it remain the assumption for this sub-thread.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#119

Earlier quoted context omitted.

That's contrary to what I'd heard, but if it's in fact the case then that does change things a little. Note that there is again a flagrant lie in the GC's writing there - "Mr. Clapper [...] focused his mind on the collection of the content of Americans’ communications. In that context, his answer was and is accurate." We know now that this is only close to true in any sense with the disingenuous and misleading defini…

I don't think it's necessarily odd that he wouldn't have seen the question if it was sent only a day ahead of time. Was there a list of questions that all of the Senators had compiled, or was this just one question independently sent from Sen Wyden's office? Was it sent in the morning or afternoon? What was Clapper doing that day? Was he in his office? Was he out in meetings/briefings all day? If it sat in his inbox…

"That quote goes back into the content/metadata issue. There hasn't been any leak so far showing content collection of Americans' communications. All of the debate in Congress regarding these programs has centered around bulk metadata collection."

First, the metadata distinction is absurd in this context. The question asked was "Does the NSA collect any kind of data at all on millions or hundreds of millions of Americans." Data on whether I call my mother every Friday is clearly data about me.

Second, even granting the metadata distinction, it's still false using any reasonable definition of "collect". Garbage men collect my trash by putting it into trucks and dumping it in a big pile. Numerous programs have been revealed under which the NSA is reading content of the communications of Americans and storing it in a database. Using "collects", precisely defined, in a way different than the rest of the world uses it in legal opinions and internal memos is possibly iffy but I don't think clearly unacceptable; using it that way with no clarification or definition in a communication directed at people predominately unfamiliar with the distinction you're drawing is nothing but a lie. "Honey, I wasn't lying when I said I didn't cheat on you. I know I slept with my secretary, but the way I use the word 'cheat' it only applies if I cook her breakfast afterwards." The testimony at the congressional hearing may have been such a communication; the opinion letter in the NYT was clearly so.

Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”

#120
post #19

In other news, NSA thinks responsible disclosure is the way to go but apparently has no 0days to responsibly disclose. I didn't know TAO sucked so hard. Can't see how any one will buy this.

Is it possible that they've quietly disclosed to affected organizations/teams, but that those organizations don't want to publicly credit the NSA as their source?

Likely not. For the past year direct disclosure would be a god send for the NSA and US Gov's reputation. So I doubt it.
Post reply on HN