Jump to content

"The NSA has exploited Heartbleed bug for years"

TopWargamer

http://www.theverge.com/2014/4/11/5605444/the-nsa-has-exploited-heartbleed-bug-for-years-bloomberg-reports

http://www.bloomberg.com/news/2014-04-11/nsa-said-to-have-used-heartbleed-bug-exposing-consumers.html

 

Bloomberg is reporting that the Heartbleed bug, which shocked the web security community this week, has been known and actively exploited by the National Security Agency for at least two years. According to two anonymous sources familiar with the matter, the bug was kept secret in the interest of national security, while the agency used it to obtain passwords and other data. Since the bug was first committed in 2012, the report suggests the NSA discovered the bug and maintained access for nearly the entire lifespan of Heartbleed.

 

Kept secret in the name of  "national security." Ya, sure, whatever. No wonder the NSA has been able to collect all of our information so easily, they used Heartbleed against us, although they did use other methods of doing so (another example is PRISM). Well, now since Heartbleed is well known to the public, hopefully everybody can take precautions to shut it down, and hopefully shut down an avenue that the NSA used to collect information on all of us. Let's see where this leads, and hopefully it doesn't end well for the NSA, but we shall see.

COMIC SANS

Link to comment
Share on other sites

Link to post
Share on other sites

"National security" my ass... ah well at least we found it and are working on fixing it.

Link to comment
Share on other sites

Link to post
Share on other sites

How do I say this..... I've lost more respect from the 0 respect I had for the NSA.

    CPU: 3930k  @ stock                                  RAM: 32GB RipjawsZ @ 2133Mhz       Cooling: Custom Loop
MOBO: AsRock x79 Extreme9                      SSD: 240GB Vertex 3 (OS)                     Case: HAF XB                     LG 34um95 + Ergotron MX Arm Mount - Dual Review
  GPUs: Gigabyte GTX 670 SLI                     HDD: 1TB WD Black                                PSU: Corsair AX 860                               Beyerdynamic - Custom One Pro Review

Link to comment
Share on other sites

Link to post
Share on other sites

That bug probably wasn't a bug. Maybe intended, until we eventually found it..

 

That. Security flaw exploited by shady government arm shocker! 

It says a lot that people aren't even shocked by this sort of news anymore. 

Link to comment
Share on other sites

Link to post
Share on other sites

I'm not surprised at all by this.

 Motherboard: MSI Z97S Krait Edition █ CPU: Intel i7-4790K █ GPU: Nvidia Geforce GTX 780Ti █ RAM: 8GB AVEXIR DDR3 1600  █ Storage: 120GB Kingston HyperX SSD + 1TB Seagate Barracuda HDD 


█ Monitor: 21.5" 1080p 60Hz  PSU: 700w █ Case: Fractal Define R4 █       ...LTT Dark Theme master race.


Project MiniConsole


Link to comment
Share on other sites

Link to post
Share on other sites

There's absolutely no proof. Everyone can take their tin foil hats off.

 

Really, man. After all the things they have done this is where you draw the line?

 

"Yeah they sure can record an entire country's phone calls, tap into any network that hasn't been encrypted and try to decrypt every network that is encrypted but nooo they wouldn't do this."

 

Calling people tin foil hatters after this point is just the sign of massive denial. America is a dystopian country 1984 style and you just don't want to accept it.

The stone cannot know why the chisel cleaves it; the iron cannot know why the fire scorches it. When thy life is cleft and scorched, when death and despair leap at thee, beat not thy breast and curse thy evil fate, but thank the Builder for the trials that shape thee.
Link to comment
Share on other sites

Link to post
Share on other sites

is this an update to the previous thread on heartbleed?

CM Storm Switch Tester MOD (In-Progress) - http://linustechtips.com/main/topic/409147-cm-storm-switch-tester-macro-mod/


       Ammo Can Speaker 02 (Completed) - http://linustechtips.com/main/topic/283826-ammo-can-speakers-02/       A/B Switch V 0.5 (Completed) - http://linustechtips.com/main/topic/362417-ab-switch-v0


     Build 01 - The Life of a Prodigy -  http://linustechtips.com/main/topic/13103-build-01-the-life-of-a-prodigy/             Build 02 - Silent Server 3000 - http://linustechtips.com/main/topic/116670-build-02-silent-server-3000/

Link to comment
Share on other sites

Link to post
Share on other sites

We have ourselves to blame. When we are born, at least for those in the US and not born under someone's house like a stray cat, you were marked the moment you were born. We get our social security number ect ect. That stuff we can't help, what we /can/ help is what info we publicly share. You can't blame the NSA for all the dumb you (you in a broad term) posted on the Internet. People who actively Facebook are the prime examples of this kind of behavior. You're trusting your info so carelessly. You can't hide info from the government since it's already in the system, but you can prevent what is being leaked. Try not to use such rubbish passwords, either. A simple to remember pass phrase is a lot more effective than some BS upper and lower case combo with a symbol thrown in. Those passwords are easy to crack.

 

Take the George Zimmerman case. Remember all the people who were glued to that case because they had nothing better to do than to be race baiters. Now contrast that to the number of people who claim to hate the NSA yet careless post their crap online publicly. Think of all the people that know Facebook sells you out and still continue to trust Zuck with their information for some unknown illogical reason. Keep all this in mind that a dumb race baiting case got several times more outrage from citizens vs the US government bending you over and getting away with it. Where is the outrage for that? This is why Americans aren't taken seriously. It's all let's complain about something, but continue fueling the fire.

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Really, man. After all the things they have done this is where you draw the line?

"Yeah they sure can record an entire country's phone calls, tap into any network that hasn't been encrypted and try to decrypt every network that is encrypted but nooo they wouldn't do this."

Calling people tin foil hatters after this point is just the sign of massive denial. America is a dystopian country 1984 style and you just don't want to accept it.

You didn't read what I said, there is NO PROOF. As soon as there is a vulnerability in anything everyone rushes to blame the NSA like headless chickens. Maybe wait to see what snowden says yeah?

Have you actually read 1984? The only country like it is North Korea. You Americans live in a democracy, use it.

Link to comment
Share on other sites

Link to post
Share on other sites

You didn't read what I said, there is NO PROOF. As soon as there is a vulnerability in anything everyone rushes to blame the NSA like headless chickens. Maybe wait to see what snowden says yeah?

Have you actually read 1984? The only country like it is North Korea. You Americans live in a democracy, use it.

Actually it's a Republic with democratic tendency.. (America is really more of a Corpocracy at this point though.. ) Still though fair point, and really why would the NSA want that crap anyways? I mean it's not like it'd be all that useful to them for anything..

"Her tsundere ratio is 8:2. So don't think you could see her dere side so easily."


Planing to make you debut here on the forums? Read Me First!


unofficial LTT Anime Club Heaven Society

Link to comment
Share on other sites

Link to post
Share on other sites

You didn't read what I said, there is NO PROOF. As soon as there is a vulnerability in anything everyone rushes to blame the NSA like headless chickens. Maybe wait to see what snowden says yeah?

Have you actually read 1984? The only country like it is North Korea. You Americans live in a democracy, use it.

Psh, as if they didn't use it, and as if anyone had reason to be surprised when the NSA was found out. Governments everywhere are listening, that will never change no matter what legislation gets passed to prevent it. Did they create it? Maybe not.

 

edit: I need to make this sound less extreme. I'm fully in support of restricting and preventing the NSA, but I don't think that they'll actually stop listening. The most we can hope for is not getting arrested because we walked by a possible spot that may sell explosives that my cousin's wife's sister's nephew's niece bought. But you still can't say that they didn't use it for something.

My previous 4P Folding & current Personal Rig

I once was a poor man, but then I found a crown.

Link to comment
Share on other sites

Link to post
Share on other sites

You didn't read what I said, there is NO PROOF. As soon as there is a vulnerability in anything everyone rushes to blame the NSA like headless chickens. Maybe wait to see what snowden says yeah?

Have you actually read 1984? The only country like it is North Korea. You Americans live in a democracy, use it.

 

You don't need proof. If serial killer has killed 29 people before no one cares to prove the 30th murder.

 

At least North Korea does not claim that it is the pinnacle of democracy, an exemplar for the world, but America does all that. They boast how it's the "free of a country they are" Hell, they have invaded countries to "bring democracy to them".

 

Even a cursory look at how America actually functions, anyone can realize democracy is mostly in name only.

 

 

Actually it's a Republic with democratic tendency.. (America is really more of a Corpocracy at this point though.. ) Still though fair point, and really why would the NSA want that crap anyways? I mean it's not like it'd be all that useful to them for anything..

 

 

They collect many other forms of data that really has no function for them. They are obsessed with hoarding.

The stone cannot know why the chisel cleaves it; the iron cannot know why the fire scorches it. When thy life is cleft and scorched, when death and despair leap at thee, beat not thy breast and curse thy evil fate, but thank the Builder for the trials that shape thee.
Link to comment
Share on other sites

Link to post
Share on other sites

If true, the most egregious thing is that the NSA let this bug go unreported and unfixed, potentially allowing (other) criminal organizations to exploit it.

 

Actually it's a Republic with democratic tendency.. (America is really more of a Corpocracy at this point though.. ) Still though fair point, and really why would the NSA want that crap anyways? I mean it's not like it'd be all that useful to them for anything..

 

I'd say it would be pretty useful to get any server using Open SSL to spill the current contents of memory, potentially including the encryption keys.

Link to comment
Share on other sites

Link to post
Share on other sites

If true, the most egregious thing is that the NSA let this bug go unreported and unfixed, potentially allowing (other) criminal organizations to exploit it.

 

 

I'd say it would be pretty useful to get any server using Open SSL to spill the current contents of memory, potentially including the encryption keys.

I meant as in the people who are worried about their information.. Even if they did and I don't support it or anything else, but I really don't think people are as important as they think they are and the government is spending their time doing anything with them.

"Her tsundere ratio is 8:2. So don't think you could see her dere side so easily."


Planing to make you debut here on the forums? Read Me First!


unofficial LTT Anime Club Heaven Society

Link to comment
Share on other sites

Link to post
Share on other sites

I meant as in the people who are worried about their information.. Even if they did and I don't support it or anything else, but I really don't think people are as important as they think they are and the government is spending their time doing anything with them.

 

Well you go ahead and keep on thinking that, then.

Link to comment
Share on other sites

Link to post
Share on other sites

Well you go ahead and keep on thinking that, then.

Well more damn power to them I guess. The only thing I'd have on any of these sites that they wouldn't already have is maybe a credit card number and I don't think uncle sam is going to charge my bank account. I really just don't have anything for anyone and most people don't. I have always been curious about what exactly people have that's such classified information.

"Her tsundere ratio is 8:2. So don't think you could see her dere side so easily."


Planing to make you debut here on the forums? Read Me First!


unofficial LTT Anime Club Heaven Society

Link to comment
Share on other sites

Link to post
Share on other sites

Im dying from suprise.

 

Listen, Privacy doesn't exist. The NSA will always, always have ways to get our information. Its just the nature of the beast.

 

If you want privacy, go completely off grid. Otherwise, you have to live with it.

The Mistress: Case: Corsair 760t   CPU:  Intel Core i7-4790K 4GHz(stock speed at the moment) - GPU: MSI 970 - MOBO: MSI Z97 Gaming 5 - RAM: Crucial Ballistic Sport 1600MHZ CL9 - PSU: Corsair AX760  - STORAGE: 128Gb Samsung EVO SSD/ 1TB WD Blue/Several older WD blacks.

                                                                                        

Link to comment
Share on other sites

Link to post
Share on other sites

i kinda doubt this

"years" make it seem like they have been doing it since forever

with logs u can see who was abusing it

If your grave doesn't say "rest in peace" on it You are automatically drafted into the skeleton war.

Link to comment
Share on other sites

Link to post
Share on other sites

TL;DR

 

Of cause they have. Im not surprised no do I care.  

Link to comment
Share on other sites

Link to post
Share on other sites

If true, the most egregious thing is that the NSA let this bug go unreported and unfixed, potentially allowing (other) criminal organizations to exploit it.

 

 

That's my thoughts exactly.

 

It's pretty clear they have been systematically undermining the Internet's security.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×