Live data from Hacker News

NSA Said to Exploit Heartbleed Bug for Intelligence for Years

bloomberg.com

141–150 of 192 posts

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#141
post #3

This looks like another case where the actions of the NSA are the opposite of what's in the best interest of US Citizens.

Are there any cases where the actions of the NSA are in any way beneficial to US citizens? Can they show that they have ever done anything positive at all? Have they saved a single life? Stopped a single threat? Or are they too busy jerking it to sexting pics and playing WoW (seriously? Come on, guys) to actually do anything useful with the BILLIONS of dollars of money that they get to play with?

> Are there any cases where the actions of the NSA are in any way beneficial to US citizens? Can they show that they have ever done anything positive at all?

Yes, and quite easily.

If that's your only testing criteria for whether a government agency is useful then NSA will pass with flying colors.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#142

Whether it's true or not, I think the correct thing for the NSA to do would be to say that they knew about it for years and exploited it. That is their job, after all.

NSA has two jobs:

1. Gain signals intelligence on specified foreign targets. 2. Protect U.S. signals from having the same done to the U.S. by other states.

The second responsibility is why there are things like SELinux, NSA "Suite B" cryptography, etc. It has also led to security bugfixes to open source code (such as X.org) used by NSA or within government.

The reason that both duties are held in NSA is because the best way to defend against the best SIGINT hackers in the world is to have the expertise of the best SIGINT hackers in the world. It's why NFL teams have their offense practice against their own defense and vice versa.

In this case the flaw is so completely egregious (and relatively easy to spot for other states' spy agencies reviewing commit diffs) that the duty of NSA would quite clearly to have been to get OpenSSL fixed, if only because so much government IT could be affected by this.

The bug was introduced pre-Snowden as well, so it's not like NSA didn't have other cyber weapons to use to achieve the effects they need. So if it's true that NSA knew about the bug and let it remain open to protect "methods and sources" then they definitely chose wrong and someone needs to explain how they came to that choice...

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#143
post #93
post #59

Earlier quoted context omitted.

Probability that story is true | Bloomberg reporting it == Probability that the sources are right * Probability that Bloomberg isn't lying about having sources ~= 80%. The sources could be lying for many reasons. As a prank, to discredit Bloomberg when they report on other NSA stories, because they're embarrassed the NSA didn't know earlier, etc. But Bloomberg knows this and presumably required some evidence to satis…

Why do you think Bloomberg was any more thorough in its Heartbleed investigation than Newsweek was in outing Dorian Nakamoto as the author of Bitcoin?

Newsweek was purchased by some shady people and hasn't been famous for investigation for... ever?; Bloomberg is one of the leading financial periodicals which is a major part of the Bloomberg empire and hooked into all sorts of circles. Would you be so skeptical if it was being reported on nytimes.com?

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#144

Now would be the time to start looking up the backgrounds of the people who implemented heartbeat support. For instance, the same guy responsible for the Heartbeat spec was the author of the OpenSSL implementation. While we do not want to make this into a witch hunt, now that the NSA is involved in Heartbleed, we should definitely rule out malice by checking for direct ties between contributors of known flawed/malici…

100% agree. Here's a related question: How many people do you think the NSA employs to work on open source software and blend into the community, establish credibility, etc. Is the answer zero people? Given what we know about the NSA now, zero seems unlikely.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#145

Bloomberg really puts its bias on display: > The Heartbleed flaw, introduced in early 2012 in a minor adjustment to the OpenSSL protocol, highlights one of the failings of open source software development. And its discovery and resolution highlights one of the advantages of open-source software development.

One of the claimed advantages of open source is to produce higher quality, more secure software.

"As a result, the open source model builds higher-quality, more secure, more easily integrated software. And it does it at a vastly accelerated pace, often at a lower cost." - http://www.redhat.com/about/whoisredhat/opensource.html for example.

As an ideology, comparing this OpenSSL happening to the stated goals of strong proponents open source, it is a complete failure of that ideology.

That it was then fixable is an advantage, but that's a separate thing. It doesn't offset the way a really common error in a change to a really common and important library sat unnoticed for two years ... until a private company paid security researcher found it.

You could argue that the bug was found and fixed and the software is now more secure :: the system works, this is how it works.

But this is not how open source proponents present it as working.

NB. This doesn't mean closed source is better. People don't push closed source as an ideology in the same way at all. But do compare open source to the claims made by open source advocates, as well as comparing it to the ease of fixing and finding bugs in closed source software.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#146
post #38
post #20

Earlier quoted context omitted.

I don't know how "disastrous" this really is. NSA knows approximately 1 zillion vulnerabilities we don't know about and won't know about. They range from RCE's in Windows and Apache to flaws in cryptographic hash functions. It's NSA's charter to stockpile these things, and, yeah, to use them against foreign adversaries. It's bad though, because this one was so easily exploitable. It's the kind of thing a reasonable o…

Exactly, I don't mind them having the capability for this kind of thing. What bothers me is the lack of due process and rule of law!

There's plenty of both. NSA is wrapped with layers upon layers of process and oversight both, which is something re-confirmed in the wake of Snowden's revelations.

What people are shocked about is that they didn't understand what the law permitted, or how quickly mixing the law of induction with datacenters full of computers can led to global-level surveillance.

With all that said, I would mind if it's true NSA knew of this bug and left it alone. It's a powerful weapon for SIGINT to be sure, but it's too easy to find by other state spy agencies doing code review; NSA would have had to assume other nations knew about it at well and were putting US government and private-sector comms at risk.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#150
post #32

Earlier quoted context omitted.

American companies are vulnerable to literally hundreds of vulnerabilities NSA knows about; that's something that was widely known (public, in fact) almost a decade before Snowden. I agree that this bug is different, but that might have been a subtle case to make inside the organization.

The worst problem with the NSA knowing about Heartbleed is the total lack of accountability. If I were any US-based company CEO whose customers got hacked by Heartbleed exploits, I'd drag their corpses to the court if necessary. Sidenote: People have asked "Why are you doing JS-based cryptography on passwords if you have HTTPS?" - here we have the ideal answer. Encrypting the passwords using public-key crypto in addi…

There seems to be a lot of confusion about what the job of the NSA is, with this most recent Heartbleed incident being the most recent example.

The NSA's primary function is performing signals intelligence. To perform that function, they've spent the past ~60 years building up cryptanalytic capability (pretty much unmatched by any other single organization either governmental or private).

Because of this, they have a secondary function, which is to serve as subject-matter-experts for other government agencies. They provide advice, mainly in the form of influencing NIST standards (overtly by providing recommendations, and as we've come to learn, covertly by fucking with standards). This is a side-effect of their primary function however.

Asimov's first law of the NSA is to intercept and process signals intelligence. Any other function is secondary, and certainly will not take precedence over their first function.

What the Snowden revelations have shown, is that there's a conflict of interest between their primary function and being tasked with providing advice. I think it's a reasonable argument to be had that they probably should get out of the business of providing guidance to other agencies, as now all that advice is tainted.

The security of "US-based companies" is so far down the list of priorities that I hesitate to suggest it exists at all. Reporting vulnerabilities to vendors is at best orthogonal to their primary function, and at worst, counter to it. If you want to argue that someone in the government should be responsible for helping companies fix security issues, that's also a good argument. But it certainly shouldn't be the NSA (and definitely not now that we know they have no compulsion about misleading everyone).

I'm going to ignore your side-note about JS browser-based crypto. Unlike the people on here who diligently try to explain the fundamental issues with doing JS-crypto, I'm now of the opinion that you can't reason with these people.

Post reply on HN