Live data from Hacker News

NSA Said to Exploit Heartbleed Bug for Intelligence for Years

bloomberg.com

131–140 of 192 posts

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#131
post #3

This looks like another case where the actions of the NSA are the opposite of what's in the best interest of US Citizens.

Are there any cases where the actions of the NSA are in any way beneficial to US citizens? Can they show that they have ever done anything positive at all? Have they saved a single life? Stopped a single threat? Or are they too busy jerking it to sexting pics and playing WoW (seriously? Come on, guys) to actually do anything useful with the BILLIONS of dollars of money that they get to play with?

The NSA has done a lot of beneficial things, such as helping design more secure crypto primitives (e.g. strengthening DES against differential cryptanalysis, fixing SHA-0 to produce SHA-1) and helping build secure software (e.g. SE Linux).

I assume what you really mean is whether their dragnet surveillance in particular is ever beneficial to US citizens, and that certainly seems to be a "no".

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#132
post #107
post #61

Earlier quoted context omitted.

Their job is not to spy on behalf of the country. Their job is to keep us safe. Letting us all run around with humungous holes in our security for years was a risk to our national security. How do you think the Chinese were able to clone our weapons systems so well? Shit like this.

Yeah NSA's job is to fix open source bugs, whatever. NSA is a spy agency, expecting them not to use vulnerabilities they find is like sending them into a gunfight with a pocketful of rocks. Ask the Palestinians how that works out in the long run. I think much of the NSA's surveillance is unconstitutional and should be rolled back by at least 2 orders of magnitude. That doesn't have to entail turning the world over to…

>>That doesn't have to entail turning the world over to Russian and Chinese hackers.

Boogey man FUD, I'm not worried about any hackers from [Insert_forgein_country_elites_want_you_to_hate]. The USgov, NSA and corrupt law enforcement are the only terrorists I'm worried about.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#133
post #70
post #68

Earlier quoted context omitted.

[deleted]

The same amount of time: it was apparently found with a fuzzer.

I didn't know about fuzzers before this whole imbroglio -- not denoted as such, at least.

If you know `crashme` you already know one fuzzer, which "intended to test the robustness of Unix and Unix-like operating systems by executing random machine instructions." See https://en.wikipedia.org/wiki/Fuzz_testing

As a good app-sec'er you seem to need to be deeply steeped in fuzzer lore. Matasano: "We'll have you write a fuzzer. Everyone here writes fuzzers." http://www.matasano.com/careers/

(I'm obviously not replying to tptacek, just highlighting a bit. ... And basking in the good glow, yes.)

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#134
post #47

> highlights one of the failings of open source software development. Sorry? Paid programmers writing closed code with probably less review and auditing have been shown to create less bugs? What are they trying to say?

What data did you use to estimate the probability of code review? Would be interesting to see if anyone has studied this.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#135
post #59

Earlier quoted context omitted.

>> The U.S. National Security Agency knew for at least two years about a flaw in the way that many websites send sensitive information, now dubbed the Heartbleed bug, and regularly used it to gather critical intelligence, two people familiar with the matter said. (emphasis mine) It's pretty weak IMHO but I don't really doubt it.

Probability that story is true | Bloomberg reporting it == Probability that the sources are right * Probability that Bloomberg isn't lying about having sources ~= 80%. The sources could be lying for many reasons. As a prank, to discredit Bloomberg when they report on other NSA stories, because they're embarrassed the NSA didn't know earlier, etc. But Bloomberg knows this and presumably required some evidence to satis…

Don't forget the priors.

As soon as I thought about Heartbleed and the NSA (well before this story), I figured there was about a 99% chance that the NSA had found it and had been actively exploiting it for a decent portion of the time it was in the wild.

Stacked against that, Bloomberg's reliability doesn't really matter at all. If the sources are good, great! If the story is crap, it's still probably right by accident.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#136

No fucking way. This is disastrous PR stuff, second only to the Snowden revelations. It should be clear by now that the NSA does not restrict themselves from anything... and should be disbanded.

It is? It would be shocking if the NSA didn't use Heartbleed. This is basically the equivalent of doing a news story about an alcoholic who drinks the beer they have in their refrigerator. It's exactly what you'd expect them to do.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#137
post #114
post #110

Earlier quoted context omitted.

[deleted]

>> Well, if you were keeping all the code to yourself you presumably wouldn't be accepting poorly reviewed patches from random people. How does this follow? You can just as easily hire "random people" to make mistakes as you can accept mistakes from people you don't pay. The problem is poorly reviewed code either way. Not the license.

[deleted]

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#138
This is according to "two people familiar with the matter". While nobody would be surprised that the NSA had exploited heartbleed, this article gives no compelling proof.

I wish newspaper articles had a bit of metadata that indicated whether the sources are verifiable. Then we wouldn't have to waste any time reading them when they aren't.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#139

I don't know if Heartbleed could reach this point, but I think probably the only possibility for getting average citizens up in arms about this kind of thing is for them to start seeing major personal detrimental effects (like oops, all my email has been stolen and deleted and my bank account's empty), and then learn that the NSA could have easily prevented it if they weren't having so much fun being super-hackers in…

I don't think average people (so to speak) really care about their email.

You know, even my bank has a special warning up about Heartbleed. I also saw it as #1 on BBC News at some point, fed to my Android phone's news, etc. It's a surprisingly big deal.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#140
post #53

Earlier quoted context omitted.

They don't until either they lose all of their email, or they lose their email account.

You are right, I could have been more specific, they do often care about maintaining control of their account. I don't think they care very much about their message history though, and there is at least some segment of the population that considers email accounts entirely disposable.

You'd be surprised about the number of emails I've received from people who apparently don't care about their email/website asking if it was vulnerable to the heartbleed/heartbug/heartbeetle/heartblood malware/virus/bug/issue/exploit in the past week.

Though I must say I find it funny all the different names/what exactly it is I've seen.

Post reply on HN