Earlier quoted context omitted.
Where do we draw the line? When millions die and billions of dollars in irrecoverable damage is done? Who gets to decide whether the risk is acceptable? To whom do we turn to when it's found that their risk assessment was flawed, and we require compensation for their recklessness and negligence?
One could make the argument that given the depth of the NSA's capabilities they were in an unique position to know who, if anyone, also knew of the bug.
NSA Said to Exploit Heartbleed Bug for Intelligence for Years
91–100 of 192 posts
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#92Earlier quoted context omitted.
Was it though? The NSA's job is to spy on behalf of the country. While keeping the bug a secret put people at risk, there is an argument to be made that it was a useful tool. Law enforcement regularly makes the decision to allow low level criminals to continue to commit crimes in order to catch their leaders even though doing so puts people at risk. There are always tradeoffs.
Their job is not to spy on behalf of the country. Their job is to keep us safe. Letting us all run around with humungous holes in our security for years was a risk to our national security. How do you think the Chinese were able to clone our weapons systems so well? Shit like this.
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#93Earlier quoted context omitted.
>> The U.S. National Security Agency knew for at least two years about a flaw in the way that many websites send sensitive information, now dubbed the Heartbleed bug, and regularly used it to gather critical intelligence, two people familiar with the matter said. (emphasis mine) It's pretty weak IMHO but I don't really doubt it.
Probability that story is true | Bloomberg reporting it == Probability that the sources are right * Probability that Bloomberg isn't lying about having sources ~= 80%. The sources could be lying for many reasons. As a prank, to discredit Bloomberg when they report on other NSA stories, because they're embarrassed the NSA didn't know earlier, etc. But Bloomberg knows this and presumably required some evidence to satis…
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#94Bloomberg really puts its bias on display: > The Heartbleed flaw, introduced in early 2012 in a minor adjustment to the OpenSSL protocol, highlights one of the failings of open source software development. And its discovery and resolution highlights one of the advantages of open-source software development.
> And its discovery and resolution highlights one of the advantages of open-source software development. I wouldn't say that its discovery (two years later) says anything good about open source development.
In the end software is written by people and people make mistakes. I'm pretty sure there are a lot of software be it open or closed source that had absolutely terrible security bugs. Judging open source as a whole by looking at a single project sounds a little bit like overgeneralization. Also, they are obviously in need of help though, I hear a lot of complaints from people about the OpenSSL code.
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#95Your friends tell you about your flaws and shortcomings. The people who keep quiet or even exploit your flaws? They are not your friends. So, what's to keep some organization that runs a package repo from publishing OpenSSL packages that claim to be like OpenSSL 1.0.1g but actually display the heartbleed bug? I also ask myself, would the NSA seek to implement such a thing? They would, though that is an entirely diffe…
(Or just use Debian in the Gentoo flavour from the beginning)
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#96Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#97Earlier quoted context omitted.
One could make the argument that given the depth of the NSA's capabilities they were in an unique position to know who, if anyone, also knew of the bug.
So we should just blindly trust an agency that has repeatedly been shown to have abused that very trust for self-serving and hypocritical ends?
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#98I'm wondering if any State Attorney Generals are tech savvy, don't like the current administration, and want some publicity[1] enough to start an investigation? I would imagine a subpoena asking for the financial records of the OpenSSL contributors would be a first step (to find Gov payments). I can see a very scary witch hunt. 1) that part might be a little rhetorical, every AG likes good publicity.
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#99The NSA needs to be dissolved. It is a costly liability whose actions work against the nations interests as a whole.
Re: NSA Said to Exploit Heartbleed Bug for Intelligence for Years
#100This looks like another case where the actions of the NSA are the opposite of what's in the best interest of US Citizens.