5 ms·
Evidence? And if so, pretty much what we expected and exactly why this behaviour is terrible
by mindstab 12y ago
Evidence? And if so, pretty much what we expected and exactly why this behaviour is terrible
- joshstrange 12y ago>> The U.S. National Security Agency knew for at least two years about a flaw in the way that many websites send sensitive information, now dubbed the Heartbleed bug, and regularly used it to gather critical intelligence, two people familiar with the matter said. (emphasis mine) It's pretty weak IMHO but I don't really doubt it.
- deleted 12y ago[deleted]
- joshstrange 12y agoLol, exactly. If this was on The Intercept [0] I'd feel differently but "two people familiar with the matter" doesn't inspire much confidence. [0] https://firstlook.org/theintercept/ https://firstlook.org/theintercept/
- sp332 12y agoProbability that story is true | Bloomberg reporting it == Probability that the sources are right * Probability that Bloomberg isn't lying about having sources ~= 80%. The sources could be lying for many reasons. As a prank, to discredit Bloomberg when they report on other NSA stories, because they're embarrassed the NSA didn't know earlier, etc. But Bloomberg knows this and presumably required some evidence to satisfy themselves before reporting. So the deciding factor is really Bloomberg's reliability.
- reedlaw 12y agoWhy do you think Bloomberg was any more thorough in its Heartbleed investigation than Newsweek was in outing Dorian Nakamoto as the author of Bitcoin?
- gwern 12y agoNewsweek was purchased by some shady people and hasn't been famous for investigation for... ever?; Bloomberg is one of the leading financial periodicals which is a major part of the Bloomberg empire and hooked into all sorts of circles. Would you be so skeptical if it was being reported on nytimes.com?
- mikeash 12y agoDon't forget the priors. As soon as I thought about Heartbleed and the NSA (well before this story), I figured there was about a 99% chance that the NSA had found it and had been actively exploiting it for a decent portion of the time it was in the wild. Stacked against that, Bloomberg's reliability doesn't really matter at all. If the sources are good, great! If the story is crap, it's still probably right by accident.
- yen223 12y agoI've heard of the NSA, and I've read that xkcd comic on how Heartbleed works. Can I be quoted as a person "familiar with the matter"?
- arrrg 12y agoThe bug only existed in the wild for two years and less than a month. I’m not sure what the “at least two years” means in that context. The NSA can’t have known this bug for a lot longer and “at least two years” implies to me “at least 24 months and possibly many more”, not “at least 24 months, at most 25”.
- hackinthebochs 12y agoThe trick is to put yourself in the context of a potential leaker. Is this person technical? Would they have the skill to distinguish between heartbleed and another equally powerful exploit? What "at least two years" means to me is not that they knew specifically about heartbleed shortly after it was introduced, but that there may be another equally damaging bug the NSA exploits that a non-programmer could easily confuse. After all, I'm sure they don't have this exploit labelled "heartbleed" in their database.
- malandrew 12y agoFurthermore, if a piece of software is responsible for protecting a huge percentage of the internet and is known to be a mess, you can be absolutely certain that there is not just one or two researchers, but possibly several teams responsible for probing that code base each and every day looking for exploits. I would be surprised if every single commit to OpenSSL doesn't get dozens to hundreds of man-hours of attention from people very good at breaking secure systems. With that in mind, you can also be sure that the NSA isn't the only government agency that is putting tons of money into exploiting OpenSSL and other critical software. I'd be surprised if it took them more than 1-3 months to find this exploit after it was introduced. If they found it in that time, you would expect that other government agencies found it nearly as quickly and have been exploiting it as well. When you have million and billion dollar budgets used to find and exploit bugs in software, you can be certain that the average person is losing out big time.