Live data from Hacker News

NSA Said to Exploit Heartbleed Bug for Intelligence for Years

bloomberg.com

21–30 of 192 posts

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#21
I don't know if Heartbleed could reach this point, but I think probably the only possibility for getting average citizens up in arms about this kind of thing is for them to start seeing major personal detrimental effects (like oops, all my email has been stolen and deleted and my bank account's empty), and then learn that the NSA could have easily prevented it if they weren't having so much fun being super-hackers instead.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#22
post #13

Do we have anything that leads us to believe the NSA was aware of heartbleed at all before we found out, other than speculation because of their resources?

We have "two people familiar with the matter" which is to say sources that Bloomberg thought were credible enough to lead a story with.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#23
This is how NSA "protects America" and its infrastructure from "cybercrime" - by allowing a bug like this to exist for years without telling anyone about it.

I hope it's now clear to everyone what NSA's vision about "cybersecurity" is. They think having vulnerabilities like this in the Internet's infrastructure is a good thing, because then they get to attack their "targets", to "protect us". It has nothing to do with actual security. Weakness is strength. Vulnerability is security.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#24
post #3

This looks like another case where the actions of the NSA are the opposite of what's in the best interest of US Citizens.

Was it though? The NSA's job is to spy on behalf of the country. While keeping the bug a secret put people at risk, there is an argument to be made that it was a useful tool. Law enforcement regularly makes the decision to allow low level criminals to continue to commit crimes in order to catch their leaders even though doing so puts people at risk. There are always tradeoffs.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#25
post #20

No fucking way. This is disastrous PR stuff, second only to the Snowden revelations. It should be clear by now that the NSA does not restrict themselves from anything... and should be disbanded.

I don't know how "disastrous" this really is. NSA knows approximately 1 zillion vulnerabilities we don't know about and won't know about. They range from RCE's in Windows and Apache to flaws in cryptographic hash functions. It's NSA's charter to stockpile these things, and, yeah, to use them against foreign adversaries. It's bad though, because this one was so easily exploitable. It's the kind of thing a reasonable o…

Eventually, the bad guys will find all of these bugs. And do massive amounts of damage (in this case, potentially billions of people who should change their password, and hundreds of thousands of administrators having to swap certificates).

And all the time, the NSA had the capability and knowledge to prevent this damage. What a great service they did to their country, indeed.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#26
post #10
post #4

My first thought: if this is the case, then why did they try so hard (and get "trolled" in the progress) to get the SSL keys from Lavabit?

Because NSA didn't try to get Lavabit's keys at all; DOJ did. Two very different organizations. Not as incestuously linked as people think they are. Also, worth mentioning: it's not particularly easy to get private keys out of servers with the bug.

That makes sense, I guess. I'm not American so I don't know much about the inner workings of these institutions.

Is it unlikely for FBI to ask NSA's help?

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#28
post #20

No fucking way. This is disastrous PR stuff, second only to the Snowden revelations. It should be clear by now that the NSA does not restrict themselves from anything... and should be disbanded.

I don't know how "disastrous" this really is. NSA knows approximately 1 zillion vulnerabilities we don't know about and won't know about. They range from RCE's in Windows and Apache to flaws in cryptographic hash functions. It's NSA's charter to stockpile these things, and, yeah, to use them against foreign adversaries. It's bad though, because this one was so easily exploitable. It's the kind of thing a reasonable o…

> It's NSA's charter to stockpile these things, and, yeah, to use them against foreign adversaries.

I don't see how leaving American companies vulnerable fulfills the NSA's charter.

Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years

#30
post #26
post #10

Earlier quoted context omitted.

Because NSA didn't try to get Lavabit's keys at all; DOJ did. Two very different organizations. Not as incestuously linked as people think they are. Also, worth mentioning: it's not particularly easy to get private keys out of servers with the bug.

That makes sense, I guess. I'm not American so I don't know much about the inner workings of these institutions. Is it unlikely for FBI to ask NSA's help?

One of the only things that should make you feel optimistic is that there are a bunch of intelligence/law-enforcement agencies and they all hate each other and hate the idea of working together or sharing information with each other.
Post reply on HN