Live data from Hacker News

Has the NSA Been Using the Heartbleed Bug?

wired.com

21–23 of 23 posts

Re: Has the NSA Been Using the Heartbleed Bug?

#21
post #17
post #11

Earlier quoted context omitted.

Uhm, as NSA and other agencies are responsible for "secure" internal comm, they have methods for that. Sometimes they get broken, probably, but thats their mission to find out, and sometimes let the enemy continue thinking their breakin is effective. Its the same methods as in 1940, that is, classic intel methods. Security does not just mean strong crypto algorithms. If you find your enemy has found a flaw in openssl…

These are fair points, but I think the GP comment above was referring as much to political economy type espionage. Say, for example, china wants to spy on a military contractor. Unless the NSA is sharing its secure pigeon network with every US defense contractor (and many of them, large and small) some pretty important US national security assets might be in play. So, perhaps not "state secrets" but things like techn…

Tactical weapons guidance systems, tesla and space-x, I believe those are in the category of "NSA will secure this with a bit more tools than given to the public as recommendations".

It could be methods like increasing security for those companies gmail accounts - on the Google internal network and all, closing all normal backdoors on Tesla employee computers, installing NSAs own intrusion detection system on them and such.

And to top it off, feed any Chinese and Russian hackers misinformation through honeypots and "accidents".

In Sweden for example during cold war it was quite popular to install extra instrumentation on jets and provide "just for the soviets" technical documentation - seed confusion and such.

Re: Has the NSA Been Using the Heartbleed Bug?

#22
post #12

I would think that the NSA would be opening themselves up to quite a firestorm if they were found to be exploiting this bug without saying a word about it. I very much doubt they were making use of this for the simple fact that, by not disclosing, they'd be allowing this gaping hole to potentially be used by "enemy" governments, which is the exact opposite of what they want.

If they knew about this, they used it, and they told or by other means deactivated heartbeat for sensitive systems of USA, and using honeypots to see if the Russians and Chinese have figured it out too. Then when their honeypots attract alot of bees, is time to tell Google to seal the hole, to protect all the medium sensitivity networks and info.

Good thought, though I would think that the reason behind a ton of government offices suddenly dropping SSL would've been leaked by one of the many hands involved.
Post reply on HN