Live data from Hacker News

NSA Said to Exploit Heartbleed Bug for Intelligence for Years

bloomberg.com

161–170 of 192 posts

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#161
I've never understood theories about NSA capability. Everyone complains that Government officials are barely competent, if at all, yet when it comes to NSA, those same people think NSA staff is at least ten times as brilliant as the general population.

Everything I've seen NSA do is largely based on the same techniques Google uses, except 10 years later, much more expensively, and with much uglier PowerPoint presentations. The only thing NSA has that private organizations don't is the compelled cooperation of telecom companies.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#162
post #42
post #26

Earlier quoted context omitted.

That makes sense, I guess. I'm not American so I don't know much about the inner workings of these institutions. Is it unlikely for FBI to ask NSA's help?

It is probably illegal for FBI to ask for NSA's help in gaining evidence for a US criminal case, although pointing that out is sure to start a raucous subthread about "parallel construction".

If it's "probably illegal", surely you can cite the law?

Notably, the FISA cell phone record orders passed information to the NSA through the FBI, so no hint of a "chinese wall" there. Secret bulk collection for 'national security', everyone bathing in the same pool of data.

I do suspect it's policy not to casually request, or become overly dependent on, such NSA-to-domestic sharing. And – as we've seen in the "parallel construction" revelations you allude to – it's definitely policy to try to obscure any such sharing when it happens.

But to reassure people that it's "probably illegal" is flimsy hand-waving when you can't name the law, and there's public evidence that it happens to the contrary.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#163
post #69

This is flamebait. Sad it's getting so many upvotes.

I agree, in the first 3 paragraphs I shook my head 3 times

"two people familiar with the matter said." "threatens to renew the rancorous debate over the role of the government’s top computer experts." "Heartbleed appears to be one of the biggest glitches in the Internet’s history" "as many as two-thirds of the world’s websites" "it’s possible that cybercriminals missed the potential in the same way security professionals did, suggested Tal Klein, vice president of marketing at Adallom"

"this article is shite, suggested ikt, junior vice president of Compuglobalhypermeganet"

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#165
I've been seeing a lot of comments recently along the lines that we "need" more evidence before we assume that the NSA took advantage of heartbleed. I don't get that at all.

I'd love to have harder evidence of what the NSA has been up to. I get that. But here are some things we know: the NSA believes its mission is to collect 100% of the world's data, with the possible exception of data that definitely belongs to US citizens. The NSA has boasted internally of cracking SSL implementations as part of its work. The NSA employs more people who are qualified for and tasked with finding this kind of exploit than anyone else. The NSA's leadership is willing to lie under oath to Congress -- let alone to anyone else -- about its activities. The NSA's secrets are about as heavily defended as secrets can be -- actually providing the kind of evidence requested here is widely considered treason against the United States. And now an investigative reporter with a serious reputation says that he has two sources who can confirm that the NSA knew about heartbleed shortly after it was created.

So let's assume you might behave differently in some way -- in any way -- if the NSA knew about and exploited heartbleed. You have imperfect information and you have to make a call. What else could you "need" before you decide to behave as though this article is accurate?

I think we "need" to assume that the NSA took advantage of heartbleed starting shortly after it was introduced. We'd just "like" to have a little more confirmation about what the hell they've been up to.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#166
post #163
post #69

This is flamebait. Sad it's getting so many upvotes.

I agree, in the first 3 paragraphs I shook my head 3 times "two people familiar with the matter said." "threatens to renew the rancorous debate over the role of the government’s top computer experts." "Heartbleed appears to be one of the biggest glitches in the Internet’s history" "as many as two-thirds of the world’s websites" "it’s possible that cybercriminals missed the potential in the same way security professio…

The point about it being VERY serious, I can accept. The rest... yep, pure bull. Also "btw Open Source sucks, proprietary good".

The article is rubbish.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#167
> The U.S. National Security Agency knew for at least two years about a flaw in the way that many websites send sensitive information, now dubbed the Heartbleed bug [...]

Interesting that they say "at least" two years. The bug is two years old, so they could have also chosen to say "at most" two years or "up to" two years. Least biased would be to just say "since the bug was introduced, two years ago".

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#168
post #154
post #146

Earlier quoted context omitted.

There's plenty of both. NSA is wrapped with layers upon layers of process and oversight both, which is something re-confirmed in the wake of Snowden's revelations. What people are shocked about is that they didn't understand what the law permitted, or how quickly mixing the law of induction with datacenters full of computers can led to global-level surveillance. With all that said, I would mind if it's true NSA knew…

The DoJ decided to ignore the law. https://www.eff.org/foia/section-215-usa-patriot-act The NSA secretly collects the private data of people they know are innocent, which is the opposite of due process.

The FBI collects the private data of thousands of people they are innocent every time they use a mass-intercept warrant on a particular cell phone tower.

An attorney general collects the business records of thousands of people they know are innocent of wrongdoing in the course of routine investigations into fraud by large businesses.

Both of those are still considered "due process" because in both cases they are following a set process. Due process doesn't mean the government won't look at you if you're innocent, which seems to be a big misconception. It essentially means that the government should handle cases with similar particulars in similar ways.

So in the case of the NSA, if that collection happened under the same type of legal authority, after going through the same FISC review (if needed), was held to the same standards of reasonable and articulable suspicion (or whatever standards were required to be met for §215) then the collection that would happen from there would have been given due process.

As for your link, while its accusations are damning enough, they don't appear to support your first point or your last one. It's hard to argue DoJ is "ignoring" the law when the EFF themselves make quite clear that "The language of Section 215 allows for secret court orders to collect 'tangible things' that could be relevant to a government investigation – a far lower threshold and more expansive reach than a warrant based on probable cause. The list of possible 'tangible things' the government can obtain is seemingly limitless, and could include everything from driver’s license records to Internet browsing patterns."

So don't take my word for it, take EFF's.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#169
post #124

Earlier quoted context omitted.

Consider: what if the NSA's sensors are so extensive that they know the exact moment anyone other than them tries to exploit certain bugs? That changes the risks/rewards of early-patching quite a bit. They can be confident it's their own trump card for quite a while, and learn about (or strategically mislead) any teams that arrive later to the same knowledge. When it's really "burnt", and in use by the NSA's enemies,…

I don't see how that protects the people whose data was stolen. "Here's the license plate number and home address of the guy who just ran over your grandma. Sorry for your loss."

It limits the corporate risks: they know exactly which passwords to change, accounts to lock, and other data loss to ameliorate.

And if the time window of exploitation is kept small, the exact same magnitude of data loss could have happened in a rapid-disclosure and patch scenario. (Two years ago, were practices for rapid response better or worse than now? Would the time window of public-knowledge-but-incomplete-protection have been any smaller - or maybe larger?)

So why not let it break later (and maybe never), rather than earlier? It's like any kind of "technical debt" analysis... oftentimes it makes sense to defer fixes, because by the time the issue becomes critical, it may have already been rendered moot, by larger changes.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#170

Earlier quoted context omitted.

Are there any cases where the actions of the NSA are in any way beneficial to US citizens? Can they show that they have ever done anything positive at all? Have they saved a single life? Stopped a single threat? Or are they too busy jerking it to sexting pics and playing WoW (seriously? Come on, guys) to actually do anything useful with the BILLIONS of dollars of money that they get to play with?

The NSA has done a lot of beneficial things, such as helping design more secure crypto primitives (e.g. strengthening DES against differential cryptanalysis, fixing SHA-0 to produce SHA-1) and helping build secure software (e.g. SE Linux). I assume what you really mean is whether their dragnet surveillance in particular is ever beneficial to US citizens, and that certainly seems to be a "no".

Why should we assume that SELinux is secure? I would suspect that if there was NSA involvement then it is necessarily less secure because they would want to be able to access it at will.
Post reply on HN