Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

dixiegrrrrl

(60,010 posts)
Fri Apr 11, 2014, 06:57 PM Apr 2014

NSA knew for at least 2 years about Heartbleed bug, regularly used it to gather intelligence

The U.S. National Security Agency knew for at least two years about a flaw in the way that many websites send sensitive information, now dubbed the Heartbleed bug, and regularly used it to gather critical intelligence, two people familiar with the matter said.

“It flies in the face of the agency’s comments that defense comes first,” said Jason Healey, director of the cyber statecraft initiative at the Atlantic Council and a former Air Force cyber officer. “They are going to be completely shredded by the computer security community for this.”
http://www.bloomberg.com/news/2014-04-11/nsa-said-to-have-used-heartbleed-bug-exposing-consumers.html

anyone surprised??
7 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
NSA knew for at least 2 years about Heartbleed bug, regularly used it to gather intelligence (Original Post) dixiegrrrrl Apr 2014 OP
Not surprised in the least. Here's the LBN thread about this "breaking news": Electric Monk Apr 2014 #1
two anonymous sources? OKNancy Apr 2014 #2
Remember BlindTiresias Apr 2014 #3
Got any proof? idendoit Apr 2014 #4
Exactly... PosterChild Apr 2014 #5
The NSA has supplied encryption routines used by MineralMan Apr 2014 #6
Nawww! After all, they're there to "protect" us from such things. Tierra_y_Libertad Apr 2014 #7

BlindTiresias

(1,563 posts)
3. Remember
Fri Apr 11, 2014, 07:38 PM
Apr 2014

How the NSA lied about the scope of the surveillance when the Snowden information was just coming out? I would be extremely skeptical of any official statements from the NSA.

PosterChild

(1,307 posts)
5. Exactly...
Sat Apr 12, 2014, 03:00 PM
Apr 2014

... in fact, since the code is open source and publicly available, it should be easy enough to locate exactly who it was who introduced the bug and talk to them about it. Did they even try?

MineralMan

(146,317 posts)
6. The NSA has supplied encryption routines used by
Sat Apr 12, 2014, 03:04 PM
Apr 2014

many open source applications. The NSA is probably the leading supplier of encryption modules in the world. They're in almost everything.

Do they put back doors in those modules? I imagine they do, and always have thought so.

I'm not surprised, and neither should be anyone else.

Want more info? Click below:

http://www.nsa.gov/ia/programs/suiteb_cryptography/

 

Tierra_y_Libertad

(50,414 posts)
7. Nawww! After all, they're there to "protect" us from such things.
Sat Apr 12, 2014, 03:04 PM
Apr 2014
The shepherd always tries to persuade the sheep that their interests and his own are the same. Marie Beyle (Stendahl)
Latest Discussions»General Discussion»NSA knew for at least 2 y...