Letting a bug/vuln this broad go unpatched for years for the NSA's own benefit is beyond negligent concerning our nation's security.
Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
91–100 of 120 posts
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#92Earlier quoted context omitted.
Either way Clapper would be breaking the law. In this case was placed between the choice of breaking his SF-182 NDA (which actually does have criminal implications... just ask Snowden) or lying to Congress in response to a question that the Congressman asking knew the answer to, but didn't want to take the risk of putting into the record himself. An interesting take on the matter is at http://joelbrenner.com/clapper-…
The questions were pre-approved. He could have objected to it beforehand, in private.
But whether Clapper objected or not, Sen. Feinstein apparently got an inkling the question would be asked, as she made clear at the start of the session that there would be a closed hearing immediately afterward for questions that couldn't be discussed in an open forum.
And since Wyden and Udall both knew the actual answer, if they were so convinced the answer should be made public then either could have simply put it in the Senate record thanks to their Constitutional privilege and taken the risk that would come with that. Instead the risk was shifted entirely onto the public servant who didn't have Constitutional immunity from prosecution.
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#93Earlier quoted context omitted.
NSA was not aware of the recently identified vulnerability in OpenSSL, the so-called Heartbleed vulnerability, until it was made public in a private sector cybersecurity report Or perhaps the "private sector cybersecurity report" was a IRC chat two years ago for l33t haxors.
They went on to: "Reports that NSA or any other part of the government were aware of the so-called Heartbleed vulnerability before April 2014 are wrong." so there's no weasel-wording going on here.
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#94Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#95Earlier quoted context omitted.
The questions were pre-approved. He could have objected to it beforehand, in private.
That's immaterial though. The questioner knew the answer was classified, so it's not as if that was a surprise, because the questioner was a member of the Select Committee on Intelligence. In other words, he wasn't asking for his own edification, he was asking in order to force Clapper to either lie or break his oath by divulging the secret. Even saying "I can't answer that" would be an admission for the same exact r…
"And since Wyden and Udall both knew the actual answer, if they were so convinced the answer should be made public then either could have simply put it in the Senate record thanks to their Constitutional privilege and taken the risk that would come with that."
Agreed, and I would think more highly of them if they had. I'm not sure what the game was. That still does not change the fact that Clapper is guilty, though.
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#96Earlier quoted context omitted.
NSA was not aware of the recently identified vulnerability in OpenSSL, the so-called Heartbleed vulnerability, until it was made public in a private sector cybersecurity report Or perhaps the "private sector cybersecurity report" was a IRC chat two years ago for l33t haxors.
They went on to: "Reports that NSA or any other part of the government were aware of the so-called Heartbleed vulnerability before April 2014 are wrong." so there's no weasel-wording going on here.
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#97Earlier quoted context omitted.
Or they straight out lied. Wouldn't be the first time.
Or they didn't. See, now we have complete set of possible answers! So, what does it means when NSA officially announces something? I'd say, it means nothing.
Maybe they didn't know. But we certainly do not have the right to know if they did know or not. This means something.
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#98Earlier quoted context omitted.
Unfortunately that "we" is the government officials themselves.
Clapper couldn't divulge the existence of a classified program in an open session hearing. If they really wanted answers vs. trying to grill the NSA in a public forum they could have asked the question in a closed session with only participants who've met the proper clearance level for said program disclosures. Unfortunately on HN anything NSA related is going to devolve into conspiracy theory groupthink these days v…
Re: Statement on Bloomberg News story that NSA knew about the “Heartbleed bug”
#99Earlier quoted context omitted.
http://www.odni.gov/index.php/carousel-items/916-the-intelli...
You just can't make this sh*t up: the "No Fear Act".
Does legislation that can't be summarized in a clumsy acronym ever get passed? I can just imagine cabinet meetings: "Sure, world peace is a nice idea, but we can't think of terrible enough acronym for it, so we've decided against it."