Live data from Hacker News

NSA Said to Exploit Heartbleed Bug for Intelligence for Years

bloomberg.com

181–190 of 192 posts

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#181
post #178

Earlier quoted context omitted.

Are there any cases where the actions of the NSA are in any way beneficial to US citizens? Can they show that they have ever done anything positive at all? Have they saved a single life? Stopped a single threat? Or are they too busy jerking it to sexting pics and playing WoW (seriously? Come on, guys) to actually do anything useful with the BILLIONS of dollars of money that they get to play with?

It is posts like this that make me think twice about reading the comments on NSA stories. For starters how many intelligence agencies publicize their successes? Do you think other four eyes purchase full page ads detailing the highlights of successful intelligence operations? Anyway lets skip the banal "intelligence agencies failures are public and the successes are private" and get to actual examples: DES SBoxes SEL…

Exactly my point. An organization like the NSA can say "Oh, yeah. We've had great success. We can't tell you what it was, of course. Just take our word for it. What's that you're typing there? Don't want to tell us? It doesn't matter, because we already know."

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#182
post #178

Earlier quoted context omitted.

It is posts like this that make me think twice about reading the comments on NSA stories. For starters how many intelligence agencies publicize their successes? Do you think other four eyes purchase full page ads detailing the highlights of successful intelligence operations? Anyway lets skip the banal "intelligence agencies failures are public and the successes are private" and get to actual examples: DES SBoxes SEL…

Exactly my point. An organization like the NSA can say "Oh, yeah. We've had great success. We can't tell you what it was, of course. Just take our word for it. What's that you're typing there? Don't want to tell us? It doesn't matter, because we already know."

And yet off the top of my head I was able to provide you with four programs/ways NSA has benefited the lives of US citizens. Why did you ask for examples if you were going to completely ignore them?

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#183
post #182

Earlier quoted context omitted.

Exactly my point. An organization like the NSA can say "Oh, yeah. We've had great success. We can't tell you what it was, of course. Just take our word for it. What's that you're typing there? Don't want to tell us? It doesn't matter, because we already know."

And yet off the top of my head I was able to provide you with four programs/ways NSA has benefited the lives of US citizens. Why did you ask for examples if you were going to completely ignore them?

I don't trust a cryptography tool that the NSA says is secure when they openly and proudly spy on US citizens. Centers of Academic Excellence? They are probably also involved in the School of the Americas. Just calling something a school doesn't make it a good thing.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#184
A reasonable policy upon discovering this type of bug is to allow the agency a fix period of time to exploit the bug and then require that they provide support in fixing the bugs for as many major US companies and institutions as possible as quickly as possible.

If they are given carte blanche to use the exploit indefinitely, they will keep it forever and let the world discover and exploit it as well. If they have a finite time period like 1-3 months, they will prioritize exploiting those systems that are actually valuable for national security. While they are doing so, they should keep an auditable log of all the systems they use the exploit against so that oversight may be performed in hindsight. Furthermore, they should absolutely be barred from using any exploit against a target with a US-based IP, or possibly even any IP address in allied nations.

It is far less likely that the agency will have the opportunity to abuse exploits if they are forced to prioritize targets due to a fixed deadline on disclosure.

During the deadline period, they should also be working on a plan that minimizes the amount of damages once disclosure is forced. i.e. there should be a list of people and companies that get the information first and everyone on the list should be people in charge of protecting computer systems (i.e. no one involved in offensive activities is on the list). Companies like Google, Facebook, Akamai, Apple and the package maintainers for all the major *nix distros should be on that shortlist of those that get priority notification.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#185
post #90

Earlier quoted context omitted.

The bug only existed in the wild for two years and less than a month. I’m not sure what the “at least two years” means in that context. The NSA can’t have known this bug for a lot longer and “at least two years” implies to me “at least 24 months and possibly many more”, not “at least 24 months, at most 25”.

The trick is to put yourself in the context of a potential leaker. Is this person technical? Would they have the skill to distinguish between heartbleed and another equally powerful exploit? What "at least two years" means to me is not that they knew specifically about heartbleed shortly after it was introduced, but that there may be another equally damaging bug the NSA exploits that a non-programmer could easily con…

Furthermore, if a piece of software is responsible for protecting a huge percentage of the internet and is known to be a mess, you can be absolutely certain that there is not just one or two researchers, but possibly several teams responsible for probing that code base each and every day looking for exploits.

I would be surprised if every single commit to OpenSSL doesn't get dozens to hundreds of man-hours of attention from people very good at breaking secure systems.

With that in mind, you can also be sure that the NSA isn't the only government agency that is putting tons of money into exploiting OpenSSL and other critical software. I'd be surprised if it took them more than 1-3 months to find this exploit after it was introduced. If they found it in that time, you would expect that other government agencies found it nearly as quickly and have been exploiting it as well.

When you have million and billion dollar budgets used to find and exploit bugs in software, you can be certain that the average person is losing out big time.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#186
post #128

> The agency found the Heartbleed glitch shortly after its introduction, according to one of the people familiar with the matter, Presumably if the anonymous sources here were discovered, they'd be in big criminal trouble, right? I am curious how far the government goes to try and discover them. And I think there is no way these anonymous sources would have contacted the journalists without Snowden going first, to es…

Not necessarily, this might actually be an approved ass-covering leak. You may think it's awful that the NSA knew for 2 years, and didn't push fixes... but their funders and overseers, in Congress and the DoD, would be more likely angry if, given the NSA's massive budget and mission, the NSA didn't know about this bug right away via code audit/analysis. Knowing vulnerabilities first is the whole job of the "Cyber Com…

A possible smoking gun in this case would be to check if most of the NSA's and the DOD systems over which it has oversight were not vulnerable this entire time while the private sector remained vulnerable.

If they truly didn't know about this, you'd expect that a lot of the US government infrastructure has also been vulnerable this entire time.

I've seen the Alexa top 1000 list showing who was vulnerable. I wonder if there is a similar list for the top 1000 computer systems and networks over which the NSA has security oversight.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#187

Now would be the time to start looking up the backgrounds of the people who implemented heartbeat support. For instance, the same guy responsible for the Heartbeat spec was the author of the OpenSSL implementation. While we do not want to make this into a witch hunt, now that the NSA is involved in Heartbleed, we should definitely rule out malice by checking for direct ties between contributors of known flawed/malici…

We absolutely do not want this. We rely on the goodwill of a lot of really smart people to produce the open source security software we rely. Even if the person who introduced this bug did in fact conspire with the NSA, we would do far more damage by going on a witch hunt. The majority of people working on this software are well-intentioned and if contributing to open source means that they risk being subject to a witch hunt for their contributions they will be far less likely to partake.

The only reasonable course of action is to apply oversight of the NSA. If people in open-source are moles, the only reasonable way to discover this is via oversight of the agency. If there are moles, there are records within the agency showing this to be the case. Getting ahold of those records is how you prove this and you get those records by getting congress to do their job and provide oversight.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#188
post #152

Earlier quoted context omitted.

This might seem like a nitpick, but I think you're confusing two distinct camps here: let's call them "Open Source" and "Free Software". Open Source advocates -- such as Eric S. Raymond -- believe that it is superior on technical grounds, the "many eyes make all bugs shallow" theory. They tend to disregard ideology and instead believe OS is the rational decision of those who want technically better software. In my op…

I do see the distinction between open source and free software, but I'm not sure it applies here. This bit of your comment particularly: They tend to disregard ideology and instead believe OS is the rational decision of those who want technically better software. If ESR is writing software in the way he thinks results in better software ... how come I know who he is? Because he's not doing that, he's doing more than…

I agree with you that open source does not automatically lead to better software.

Now that you've clarified you weren't talking about RMS's "free as in speech" ideology, I retract my nitpick.

I wouldn't say open source doesn't matter in regard to quality and security, though, but I agree with you on the importance of the other factors you mention. I do wonder what would have happened with a similar bug/exploit in a piece of commercial software. Who knows? Maybe it's already there and we simply don't know about it, and there are fewer people looking at it.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#189
post #152

Earlier quoted context omitted.

This might seem like a nitpick, but I think you're confusing two distinct camps here: let's call them "Open Source" and "Free Software". Open Source advocates -- such as Eric S. Raymond -- believe that it is superior on technical grounds, the "many eyes make all bugs shallow" theory. They tend to disregard ideology and instead believe OS is the rational decision of those who want technically better software. In my op…

PS: I also take issue with the "paid security researcher" remark. Absolutely nothing in either Free or Open Source excludes paid personnel or private companies from the equation. Hobbyist programmers are not the only ones accepted. I don't understand why you see this as extraordinary. I never meant to imply paid researchers should not work on it. What I meant is: The whole world can see every line of code in Linux. T…

In this case, you're right. I don't know that I would make a general rule out of it, though. Maybe in general open source helps, but in this case (for several reasons, including that OpenSSL seems to be a barely understandable mess, or "written by monkeys" as some put it) it didn't.

I agree that thinking "open source magically makes software better and more secure" is absurd. I also agree that Jim Zemlin's statements (in general, in that article) are more of a PR thing than accurate statements.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#190
post #188

Earlier quoted context omitted.

I do see the distinction between open source and free software, but I'm not sure it applies here. This bit of your comment particularly: They tend to disregard ideology and instead believe OS is the rational decision of those who want technically better software. If ESR is writing software in the way he thinks results in better software ... how come I know who he is? Because he's not doing that, he's doing more than…

I agree with you that open source does not automatically lead to better software. Now that you've clarified you weren't talking about RMS's "free as in speech" ideology, I retract my nitpick. I wouldn't say open source doesn't matter in regard to quality and security, though, but I agree with you on the importance of the other factors you mention. I do wonder what would have happened with a similar bug/exploit in a p…

Security researchers do find and report buffer overflows in closed source software, which then get fixed by the manufacturer. It happens.

But yes, I also wonder about the balance of bugs in similar open/closed source software.

Post reply on HN