Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
81–90 of 120 posts
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#82I find it a stretch to believe that some part of the NSA didn't know about, and/or have a hand in introducing, Heartbleed. There has to be an NSA team dedicated to both causing and exploiting issues with very popular open source software. If there isn't, the NSA isn't living up to its reputation. The reality is that we'll never get the truth out of them, and it doesn't matter anyway because nothing they say can be be…
This is clearly now true for many of us.
I wonder how true it's becoming for the people to whom the NSA provide their information? When Clapper happily uses phrases like "the least possible untruthful answer" when explaining to congress why he said "No" when the answer was "Yes", I can't help but wonder if the FBI/CIA/Pentagon/President/B-613 are starting to question/disbelieve every word that comes out of the NSA?
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#83Just keep in mind that the NSA routinely lies... even in direct testimony under oath to Congress. http://www.slate.com/articles/news_and_politics/war_stories/...
An interesting take on the matter is at http://joelbrenner.com/clapper-and-wyden-scenes-from-a-sandb...
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#84Earlier quoted context omitted.
Unfortunately that "we" is the government officials themselves.
Clapper couldn't divulge the existence of a classified program in an open session hearing. If they really wanted answers vs. trying to grill the NSA in a public forum they could have asked the question in a closed session with only participants who've met the proper clearance level for said program disclosures. Unfortunately on HN anything NSA related is going to devolve into conspiracy theory groupthink these days v…
Edited to add: Or at least, the decision to break the law. Which law may have been decided later.
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#85Sincere question: is the NSA on record for having responsibly disclosed any previous security holes? Is there some track record of them having actively help close security holes in software?
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#86Just keep in mind that the NSA routinely lies... even in direct testimony under oath to Congress. http://www.slate.com/articles/news_and_politics/war_stories/...
Either way Clapper would be breaking the law. In this case was placed between the choice of breaking his SF-182 NDA (which actually does have criminal implications... just ask Snowden) or lying to Congress in response to a question that the Congressman asking knew the answer to, but didn't want to take the risk of putting into the record himself. An interesting take on the matter is at http://joelbrenner.com/clapper-…
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#87First, tumblr? Really? Second: "When Federal agencies discover a new vulnerability in commercial and open source software – a so-called “Zero day” vulnerability because the developers of the vulnerable software have had zero days to fix it – it is in the national interest to responsibly disclose the vulnerability rather than to hold it for an investigative or intelligence purpose." This is demonstrably false. That's…
"First, tumblr? Really?" That was my first reaction too. I'm probably late to the party on this, but when I saw the tumblr domain I thought it was some kind of satire at first.
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#88"If the Federal government, including the intelligence community, had discovered this vulnerability prior to last week, it would have been disclosed to the community responsible for OpenSSL." I see numerous disclosures from technology companies, security researchers in industry and academia... but for the life of me, I can't recount an instance in which a disclosure came from intelligence-community researchers. Is th…
I don't know of better examples though.
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#89Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#90Earlier quoted context omitted.
Use the bug for what purpose? The NSA constantly lies, and also just spies on non-terrorist organizations because terrorism: http://techcrunch.com/2014/04/08/snowden-council-of-europe-t... . They are so beyond deserving the benefit of any doubt.
For spying. No one, least of all Snowden, is calling for an end to the NSA's spying days.