18 ms·
Were Intelligence Agencies Using Heartbleed in November 2013?
- gregwtmtno 12y agoWhat worries me, is that the Snowden leaks didn't seem to have a strong emphasis on SSL encryption suggesting to me that they could circumvent it. For reference take a look at this article from September. http://www.reuters.com/article/2013/09/05/net-us-usa-security-snowden-encryption-idUSBRE98413720130905 http://www.reuters.com/article/2013/09/05/net-us-usa-securit...
- Zigurd 12y agoSnowden's files predate the existence of this vulnerability.
- scott_karana 12y agoNo, Snowden's files predate the public knowledge of the vulnerability. As far as I know, we presently have no way of determining whether or not the NSA had knowledge of the bug. From the CVE[1], we see that OpenSSL versions from the very start in 2012[2] were vulnerable. 1 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-0160 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-01... 2 http://www.openssl.org/source/ http://www.openssl.org/source/ (Jan 3 14:41:35 2012 openssl-1.0.1-beta1.tar.gz)
- Zigurd 12y agoSnowden's files predate the existence of the vulnerability. Many of his files were years old when he exfiltrated them. This vulnerability was created by a specific check-in that has been identified. That does not, of course, mean the NSA didn't use it, or even create it. Both are possible.
- scott_karana 12y agoOh, I see what you mean. Fair point. (It's a wide time range of files he's released so far though, right?)
- saraid216 12y agoYou'd think that, if any of his files actually covered such a possibility, he would have released that file by now.
- pyronite 12y ago> Snowden's files predate the existence of this vulnerability. The vulnerability is over two years old. I second scott_karana in thinking that you're wrong.
- ttctciyf 12y agoYep, in particular the Guardian article which the linked Reuters one is based on [1], says: >"For the past decade, NSA has lead [sic] an aggressive, multi-pronged effort to break widely used internet encryption technologies," stated a 2010 GCHQ document. "Vast amounts of encrypted internet data which have up till now been discarded are now exploitable." > An internal agency memo noted that among British analysts shown a presentation on the NSA's progress: "Those not already briefed were gobsmacked!" Which certainly sounds like SSL traffic was broadly compromised as far back as 2010. That doesn't conclusively prove heartbleed isn't of use to these agencies though; for example one possible scenario is that the British analysts were "gobsmacked" by some other undisclosed vulnerability similar in scope to this one, which has since been fixed (and, if you're inclined that way, you could theorize that heartbleed was introduced to replace it..) [1] http://www.theguardian.com/world/2013/sep/05/nsa-gchq-encryption-codes-security http://www.theguardian.com/world/2013/sep/05/nsa-gchq-encryp...
- rdl 12y agoSnowden's files predate large-scale use of SSL (except maybe by banking sites, which are essentially already pwned by the government).
- secfirstmd 12y agoI must admit to being suspicious about this. I would consider myself very very careful about password and other security issues because of various human rights projects I work on, yet on 16th March at very unusual but clever time for attempting such a thing against me (at the time I would have tried this, if I was targeting me and collected relevant pre-attack information) someone from the UK used my exact and recently changed password to login to my email service - traced back to a very unusual location for attempting such a thing. Luckily the service I use for low-level mail security noticed this strange login and blocked it. It has puzzled me quite a bit as nothing like this has (knowingly occurred to me before) and I take a lot of precautions (which for obviously reasons I'm not going to go into) against keyloggers, malware, MITM, etc etc. With such target hardening I was very suspicious of how it occurred. Ofcourse maybe I was sleep talking my passwords again :)
- yarou 12y agoA similar thing happened to me. Someone was repeatedly trying to access a gmail account of mine, which is strange because that account had not been active for over 5 years. They supplied the correct credentials every time, and the IP originated from some small village in China. I had also recently changed my password, so I don't think it was merely a coincidence. It is possible that I have been keylogged for 10 years without knowing it, but the timing is uncanny. Edit: Keylogged for the past 10 years without knowing it, across 5 different machines, with different architectures and operating systems. :-)
- secfirstmd 12y agoInteresting... If you don't mind me asking the question I always ask people when helping with their security (both cyber and physical) and eliminating an element of potential paranoia: Would your work/life make you a worthwhile legitimate target? (don't mean to sound rude but I guess it differentiates between random attacks and targeted ones)
- dobbsbob 12y agoHow do you even know what a legit target is anymore after Snowden dropping docs they spied on charities and Jr sys admins.
- teoruiz 12y agoVery shameless plug: we just launched a t-shirt campaign with teespring.com. All proceeds will be donated to the OpenSSL Software Foundation: * Campaign: http://teespring.com/hbts http://teespring.com/hbts * HN thread: https://news.ycombinator.com/item?id=7567461 https://news.ycombinator.com/item?id=7567461
- unhush 12y agoIs it possible for you to allocate those funds to (specifically) funding a security audit and code refactor of OpenSSL? Cryptography researcher Matthew Green has stated interest in starting a campaign: https://twitter.com/matthew_d_green/status/453862237502185472 https://twitter.com/matthew_d_green/status/45386223750218547...
- grugq 12y agoyeah, I actually started that campaign. You'll notice it is the tweet he is replying too ;)
- danbruc 12y agoI don't get the number 1396891800 - what does it mean?
- fjarlq 12y agoNumber of seconds between Jan 1 1970 and the discovery of Heartbleed, I suppose. The time_t time stamp.
- danbruc 12y agoThat makes me feel less dumb - I thought I was missing something obvious. Thx!
- SimHacker 12y agoObviously it's Mrs. Charlotte Faye Wylie Med's National Provider Identifier Number -- what did you think it was? Did you already forget??!
- rdudek 12y agoThis wouldn't surprise me one bit. Governments employing hackers to exploit whatever they can get their hands on is not something new. Also, makes one think what other exploits are out that are being used, yet, we're not aware of it?
- TaylorAlexander 12y agoMy theory is that basically all of our traffic is compromised, we just don't know it yet. It seems clear that the NSA has been actively working to find and exploit every vulnerability they can, and they have the power of a well-funded concerted effort, secret physical access, and gag orders all on their side. I bet they can do a whole lot more than what we know.
- unhush 12y agoI helped write this post. Note that we're very interested in anyone who has been keeping raw packet logs from before the Heartbleed vuln. was public. If you find 18 03 (01 | 02 | 03) 00 03 01 in them, please let me know or post pcap files. Contact info: https://www.eff.org/about/staff/yan-zhu https://www.eff.org/about/staff/yan-zhu
- gojomo 12y agoAre heartbeats typically visible in the raw traffic, or (after some point) do they wind up inside the secured stream? (If the latter, this could be an unfortunate case where Perfect Forward Security, when enabled, also helps obscure exploits from later forensic discovery...)
- anaphor 12y agoIt appears that you might be right, from the RFC: "However, a HeartbeatRequest message SHOULD NOT be sent during handshakes. If a handshake is initiated while a HeartbeatRequest is still in flight, the sending peer MUST stop the DTLS retransmission timer for it. The receiving peer SHOULD discard the message silently, if it arrives during the handshake. In case of DTLS, HeartbeatRequest messages from older epochs SHOULD be discarded." But that doesn't make sense to me because the PoC code didn't complete the handshake did it? Edit: according to Google the reason is that OpenSSL does not honour the "SHOULD" part of the spec :/
- kyrra 12y agoVRT (people who maintain a ruleset for Snort) published free rules for detecting Heartbleed attempts. If you read their blog post about it[0] (and the comments), the first 5 bytes of all the Heartbeat messages are unencrypted and you are able to detect the lookup within those first 5 bytes. [0] http://vrt-blog.snort.org/2014/04/heartbleed-memory-disclosure-upgrade.html http://vrt-blog.snort.org/2014/04/heartbleed-memory-disclosu...
- unhush 12y agoIn the case of the sample described in the post, there was a TLS handshake that was immediately terminated, followed by a client hello and the heartbeats. The client hello and heartbeats were sent in the clear. I conjecture that the TLS handshake was used to fingerprint the server, since not all 3 versions of the payload will succeed on all TLS versions.
- singold 12y agoAs I cant access this page from Chrome (doesn't let me because "it's not secure") here is the archive.org link https://web.archive.org/web/20140410171401/https://www.eff.org/deeplinks/2014/04/wild-heart-were-intelligence-agencies-using-heartbleed-november-2013 https://web.archive.org/web/20140410171401/https://www.eff.o... Could it be that because of heartbleed now i can't access eff.org?
- unhush 12y agoAre you joking? If not please report what error you're getting in Chrome.
- singold 12y agoNo joking, where can I report that?
- unhush 12y agoEmailing me works. yan at eff dot org.
- unhush 12y agoFor anyone following along at home, we looked into this and it seems to be caused by the fact that you're using an older operating system that doesn't ship with the StartCom CA cert that eff.org uses. So probably not an attack. :)
- nodata 12y agoEFF uses StartCom?!
- ScottBurson 12y agoThis would be so easy for the NSA etc. to do that I think we have to consider it as inevitably having occurred. All they would have had to do is take a close look at any new changes committed to OpenSSL and other critical infrastructure software. Surely they have people doing that -- they would be remiss not to.
- hackinthebochs 12y agoEven easier, I would bet a lot of money that they have at least some rudimentary static analysis tools to detect potential targets, and this sort of memory error is pretty low hanging fruit for such a tool. To me it seems almost certain that they knew about it and they certainly exploited it if they knew. The bigger question to me is how many of these bugs have they rooted out that have not been made public yet?
- hcarvalhoalves 12y agoEven easier: Some dude finds a 0day and sells it to some agency.
- stcredzero 12y agoWhy don't we have groups doing that sort of analysis on our behalf? Programmers are at a fundamental disadvantage when it comes to testing and verifying their own code. You can't trust a shop to verify itself when it comes to infrastructure this critical.
- hackinthebochs 12y agoYeah--it should be a no-brainer. Running such critical code through as many static analysis tools you can get your hands on should be standard practice. I wonder why Coverity and the rest havent taken it upon themselves. I remember a story about Coverity running their tool on random open source projects and emailing them about issues they found. Maybe OpenSSL is too far in the hole to start that now.
- betterunix 12y ago
- higherpurpose 12y agoIt should be illegal for a government to make use of botnets this way.
- lawnchair_larry 12y agoIt is. They don't care.
- jessaustin 12y agoAll is legal for the sovereign. After all, the Law is his tool: why would he consent to its use against him?
- nhaehnle 12y agoI don't know if you're trolling or genuinely don't know how this works. If you don't, please read up on the constitution of whatever country you live in. The respect for those constitutions has eroded significantly since the beginning of the century, but they still exist and we must still insist on them. Don't give up the achievements of the past that easily.
- jessaustin 12y agoWhile we're handing out reading assignments, I'd encourage you to read something that wasn't assigned in junior-high civics class; perhaps Machiavelli? Political power has been exercised for millennia, and its nature is far closer to the caricature I offered than anything written in any newfangled constitution. The point is that a constitution is not an achievement, the "unlocking" of which would transform a society in any lasting way. It might be more accurate to say that a constitution or similar document is an aspiration, but since few such have been fulfilled it's foolish to be surprised when we fall short. The fault is not in our constitutions, but in ourselves, that we are underlings. We knew when we built this monstrous war and imprisonment machine that it would be turned against us, yet we built it anyway.
- 12y ago
- infinity0 12y agoGCHQ have been known to attack IRC networks: https://www.networkworld.com/community/blog/eff-cyber-attack-against-hacktivists-cfaa-you-impunity-nsa-and-gchq https://www.networkworld.com/community/blog/eff-cyber-attack...
- reillyse 12y agoPardon me for being cynical about this, but from what we've heard about NSA hacking and industry collaboration I would say it's highly likely that a large number of the Certificate Authorities themselves are compromised by the NSA or GCHQ and so it renders the question moot.4 Certificate Authorities control > 90% of the market 3 of them based in the US and 1 in the UK. With access to the CA's keys they can sign any number of certificates they want.
- lern_too_spel 12y agoPardon me for being realistic, but I would say exactly the opposite. If the CAs were compromised, that would be the biggest story by far in Snowden's documents, and it would have appeared in the newspapers by now.
- hendzen 12y agoThe Snowden documents (that have been released) were actually very light on technical information. The real details of how BULLRUN works are probably compartmentalized to a very small group of people and not accessible to a random sysadmin. So it is entirely possible that CAs have been compromised and Glenn Greenwald and the rest of those with the Snowden cache have no idea.
- hadoukenio 12y agoAs I commented yesterday on HN, if this ever came to light, it would be the Internet's version of a "Lehman Brothers" style collapse. Thinking about it more, it would actually be awesome. The cabal of CAs would fall and hopefully a bulletproof distributed system model would eventually replace this snakeoil industry.
- arh68 12y agoHow would this have been in the documents? Didn't the documents come first? This came later, I thought. EDIT: ...might've come later. exact timeline probably unknowable.
- dobbsbob 12y agoI would say they are compromised just by watching Moxie Marlinspike's presentation about the shitty state of CAs and how he was able to find signing certs just laying around in unprotected directories https://www.youtube.com/watch?v=Z7Wl2FW2TcA https://www.youtube.com/watch?v=Z7Wl2FW2TcA
- diminoten 12y agohttp://en.wikipedia.org/wiki/Betteridge's_law_of_headlines http://en.wikipedia.org/wiki/Betteridge's_law_of_headlines I don't think so, mostly because to get useful information out of memory after only one heartbeat would be quite lucky. If this were an actual attack, I think we'd see many more heartbeats in Koeman's logs.
- nl 12y agoAs I've mentioned elsewhere, heartbleed combined with bulk data collection means all your historic communications can be read unless your provider was using Perfect Forward Secrecy. I don't think this aspect is getting as much publicity as it should.
- arh68 12y ago> bulk data collection Including whatever the McDonald's free wi-fi might store? I'm not insinuating they were an actor, but is that how simple it could've been? Anything communicated over unsecure/not-secure-enough wi-fi could've been captured & apparently now decrypted using newly-acquired information? I'm halfway sure that's what it means. But that would just be crazy, right?
- nl 12y agoAnything communicated over unsecure/not-secure-enough wi-fi could've been captured & apparently now decrypted using newly-acquired information? Yes. An attacker would have to collect that information, AND have grabbed the private keys from a vulnerable site. But there is nothing technically stopping that from happening. (And of course I expect there may be a market for those keys now) But that would just be crazy, right? Yes. Crazy but possible.
- shard972 12y agoProbably not, If they did they would have raised these security flaws to the general public in the interest of security.