10 ms·
At this point it's safer to say that an intelligence agency is responsible than that they aren't responsible. This is precisely what Schneier, Greenwald, et al.
by pvnick 13y ago
At this point it's safer to say that an intelligence agency is responsible than that they aren't responsible. This is precisely what Schneier, Greenwald, et al. mean when they say that the NSA tactics degrade the security of the overall internet architecture. It's incredibly dangerous.
- venomsnake 13y agoI personally incline toward - memory safety in C is hard. We have had enough of those bug pop on their own to need encouragement. Whether interested parties knew of it and use it as a key towards all you can eat intelligence buffet is another story.
- natdempk 13y agoMemory safety in C is hard, but this bug, a memcpy with a user-supplied, unchecked length? I mean this is stuff that I learned about in my first serious class that involved C, and it wasn't even security related. C is a language where you code defensively at almost all times, yet this was ignored in the SSL implementation, a project which is based around communicating with a user? This is the situation where you really can't trust things like lengths. Either its incompetence or shilling, both of which are harrowing.
- danielweber 13y agoEither its incompetence Incompetence on the part of the website companies that didn't pay the money to hire people to make sure that a piece of their critical infrastructure was up to the task? Yes, I agree. (I don't really believe that, BTW. Shit happens.)
- ahomescu1 13y agoThere is no proof in either direction. It's safer to just say nothing at all.
- jessaustin 13y ago"Safer" is an interesting adjective: its meaning depends on your threat model. Are you more worried about underestimating the already-tarnished honor of a secretive federal agency, or about being screwed over by that same agency? I personally care more about the latter.
- rtpg 13y agoHow can you make such a claim? Do you have any proof that they were involved with this specific bug? I get that the NSA is after us but when you consider that the bug is of the exact same class as a bug every C programmer has ever made in their career, it seems probable that it could have happened on accident. Where do you see the malicious intent?
- mietek 13y agoWhy do heartbeats need payloads?
- Shish2k 13y agoTo account for out-of-order packets, apparently (TLS-over-UDP is something I've never heard of, but I guess it exists?)
- 3pt14159 13y agoThe NSA has two mandates. First, it is to ensure that Americans are using secure communication channels. Second, it is to collect data. When these two things come into conflict they have the authority to make a decision. For centralized communication channels, for example, they will often help beef up security in exchange for the ability to wiretap. If this bug was not caught by the NSA, then they are incompetent, something that I've rarely seen levelled at them as of late, but it is possible. If this bug was perpetrated by the NSA, then they are evil because they are exposing Nato and other allied countries to foreign attacks and corporate espionage. Given the stakes, what they've said in the PRISM slides, and their history, I'd say evil is more likely than incompetent.
- rtpg 13y agoNobody caught this bug over two years (supposedly). Stranger things have happened. Also, while the NSA might have wanted to create this bug to exploit it, you still haven't shown that they created this bug. They might have known about it and exploited it, but saying they put the bug in the first place is a very strong claim.
- smtddr 13y agoNah, I am extremely pro-Snowden & extremely anti-NSA... but I'm also a person that enjoys programming in C. C is hard. I really think this was just a bug. What _is_ possible though is that the NSA knew about this bug since awhile back and kept it secret. But then if they knew about the bug, why was nasa.gov vulnerable? I would not expect any .gov domains to be vulnerable unless to create plausible deniability - but this kind of conspiracy logic has no end.
- AYBABTME 13y agoWhat's critical about nasa.gov? It's just a marketing facade. Not patching it means nothing. I'm not saying that NSA did/didn't do X. Just that the above about .gov domains is not a valid argument. Intelligence gathering trumps trivial service to citizens.