9 ms·
I still like how these timelines are all about the big tech companies and not about governments, services and banks etc. These are arguably where some of the bi
by mindstab 12y ago
I still like how these timelines are all about the big tech companies and not about governments, services and banks etc. These are arguably where some of the biggest risk targets are actually at (see today's post about Canada government's Revenue Services (tax agency) loosing people's info to heartbleed).
We probably need a stronger web security system people can be on. Also some of the blame falls to the big companies, banks, telcos etc themselves, I mean who wants to report security flaws to Telcos in a world where they then turn around and instead of giving you a $15k bounty, send you to jail like Weeve. And ok that's not the best comparison because he went well beyond discovering and did exploit as well. But none the less, some of the big corporate world need to clue in and get more friendly with tech rather than hostile, because right now they don't have a very good reputation and so then tech leaves them out in the cold. Did anyone think about notifying telcos and banks much? or just other big tech companies.
- ig1 12y agoIn a post-Snowden world the assumption is now that any vulnerability shared with a government is fair game for the government to use offensively. It wouldn't surprise me if plenty of people who would have previously reported a vulnerability to the government or local CERT are no longer willing to do so.
- anfedorov 12y agoIn a pre and post-Snowden world, I would imagine if a government discovers a bug like Heartbleed and has no evidence of anyone else knowing about it, they will classify it and use it offensively. They will then collect evidence and construct a model of who else knows of the vulnerability and weigh the costs (to their offensive capabilities) and benefits (to everyone's defensive capabilities) of disclosing it publicly. Once there is reason to believe that the benefits outweigh the costs, they will disclose it in a way that doesn't expose their knowing about it beforehand.
- andyjdavis 12y agoBasically, governments are rational actors. Not really surprising but many people seem to assume the government will be either irrationally benevolent or irrationally evil.
- lutusp 12y ago> Basically, governments are rational actors. Citation needed. :) There are two schemes that assure irrational governmental behavior -- dictatorship, and democracy. For different reasons, of course. > Not really surprising but many people seem to assume the government will be either irrationally benevolent or irrationally evil. There's plenty of historical support for those views -- you know, evidence?
- andyjdavis 12y agoWhat might appear to be irrational behavior to you is just due to people making decisions based on different information, differing priorities and a different decision making process informed by different life experience. If someone's decisions appear irrational to you, you just don't possess enough data about the information they have access to, their priorities and the world model in their head.
- ordinary 12y agoWhy is the assumption "governments are rational" more reasonable than "governments are irrational"? Both seem equally possible to me, given the fact that we don't have the information to tell, either way. In any case, that's a false dichotomy. Governments are not uniform entities, and there's no point talking about them as if they are. Governments, like people, do some rational and some irrational things.
- afarrell 12y agoBecause it takes quite a lot of work and training for individual humans to act rational. Therefore, without other information, it is a better default assumption that any given human or system-of-humans is non-rational.
- sadfnjksdf 12y agoAs soon as anyone knows, they are going to use that info however they see fit. Probably getting their own house in order before spreading the news, to not put themselves at risk. However, even though spouting a conspiracy theory is a faux pas here, I can't help but wonder if the "he who smelt it, dealt it" rule applies here. Lets say your country were to setup a network interconnecting major research institutions, etc. After its use takes off and it is obvious that everyone is going to be communicating over this new medium in a short amount of time, you see the value in keeping tabs on people. You decide that it is in your best interest to put backdoors into encryption algorithms in enterprise communication software. So you see there are these guys that have become the place that everyone is starting to go to find what they are looking for. This is a good place to be. You eventually get your hands on this also. It's a waste of time and energy to constantly be decrypting everyone's messages, so what the hell- let's put a backdoor in that also. Everything is going well. Wait... ok, we should have thought of that. Another country now knows about this vulnerability and it hasn't been publicized, which means they will start using it to spy on contractors that work for us. We'd better leak this information so everyone fixes their hole. Let's tell Google. We're already on good terms with them.
- pvg 12y agoThe full timeline doesn't make big tech companies look particularly great. Heartbleed was a bug that came in with a questionable implementation of a questionable feature. It sailed through standards bodies and OpenSSL itself. A sensible explanation is that these are underfunded, understaffed efforts. But next, the feature went live on the servers of more or less everyone, including Google and Yahoo and Amazon. People who employ and, presumably, well-compensate many experts in security and SSL implementations. Still, the code marched on, unnoticed, undisabled, deployed. How did that happen?
- jamesaguilar 12y agoBig tech companies, small ones, and OSS folks, all write bugs. How does it "not look particularly great" to do something that literally every person writing software does. Wait, not even to do it. To miss the error in an obscure change in a backwater part of OpenSSL that no one uses. It does not strike me as likely that these companies review every change to every possible piece of sensitive software. The volume of work would be far too large.
- jfoster 12y agoI think the broader point being made is that practically anyone could come along and write code that then gets widely deployed. They just have to pick the right project, build up a bit of trust, and then submit a subtle but intentional bug. It's scary how easy it might be. It's not very clear how to defend against this.
- jfoster 12y agoAnother angle to that is that telcos and banks are localized services (none have high % market share across the globe) that people use less frequently than email. Whilst they carry potentially higher rewards for blackhats, in an aggregate effect on society, a single bank not being secure is probably less noteworthy than a globally used service like Gmail or Facebook not being secure. Also, banks only deal with money, whereas in certain locations and situations, lives potentially depend on Gmail, Facebook and Twitter being secure. (oppressive governments and such)
- orky56 12y agoA report suggested that the NSA already knew about the Heartbleed bug 2 years ago and took advantage (http://www.bloomberg.com/news/2014-04-11/nsa-said-to-have-used-heartbleed-bug-exposing-consumers.html http://www.bloomberg.com/news/2014-04-11/nsa-said-to-have-us...) This suggests that first the NSA discovered it, then Neel Mehta, and finally Codenomicon. As other commenters have rightly suggested, the government, or at least an agency there of, uses information asymmetry as a weapon of intelligence on its users (aka citizens). In the case of private corporations, they have a more contractual duty to their users to ensure that these bugs are patched so that those with malevolent intentions can't harm their users. In my opinion, a bug that has been discovered but not shared is just as bad as a weaponized biological agent. Each rely on secrecy to exploit a group that is unaware.
- dpeck 12y agoLikely quite a few people between the (two confirmed and one rumored) discoverers as well.
- thefreeman 12y agoThat article contains exactly 0 facts. It is complete FUD. The only evidence they have that the NSA knew about it is an unquoted statement that "two people familiar with the matter said". I am not saying it's impossible the NSA knew. But people throwing around that article as evidence is absolutely laughable.
- higherpurpose 12y agoMost banks weren't vulnerable to Heartbleed.