Started By
Message
locked post

NSA discovered/exploited Heartbleed for two years

Posted on 4/11/14 at 3:58 pm
Posted by joshnorris14
Florida
Member since Jan 2009
45233 posts
Posted on 4/11/14 at 3:58 pm
LINK /

quote:

“The agency found the Heartbeat glitch shortly after its introduction, according to one of the people familiar with the matter, and it became a basic part of the agency’s toolkit for stealing account passwords and other common tasks,” Riley wrote.

“Putting the Heartbleed bug in its arsenal, the NSA was able to obtain passwords and other basic data that are the building blocks of the sophisticated hacking operations at the core of its mission, but at a cost,” he added. “Millions of ordinary users were left vulnerable to attack from other nations’ intelligence arms and criminal hackers.”



What wonderful protectors we have.
Posted by Traffic Circle
Down the Rabbit Hole
Member since Nov 2013
4261 posts
Posted on 4/11/14 at 3:59 pm to
Are they protecting us or themselves? Kind of like a robot turning on its maker.
Posted by idlewatcher
County Jail
Member since Jan 2012
79252 posts
Posted on 4/11/14 at 4:01 pm to
quote:

joshnorris14


Welcome back. Hadn't seen you in forever
Posted by asurob1
On the edge of the galaxy
Member since May 2009
26971 posts
Posted on 4/11/14 at 4:02 pm to
You trade freedom for security. Did you expect anything less?

Posted by Joshjrn
Baton Rouge
Member since Dec 2008
27088 posts
Posted on 4/11/14 at 4:02 pm to
You must be hiding something, sir.
Posted by ironsides
Nashville, TN
Member since May 2006
8153 posts
Posted on 4/11/14 at 4:17 pm to
quote:

You trade freedom for security. Did you expect anything less?


I didn't expect the NSA to be able to get my password for Amazon or my bank account.

Oh yeah, I forgot: They aren't targeting me.

The government wouldn't dare target an individual that favors less government spending right? Just like the IRS applies their logic equally?
Posted by silverdawg
Member since Mar 2014
608 posts
Posted on 4/11/14 at 4:55 pm to
Obamacare uses open ssl protocal .
Posted by LSUwag
Florida man
Member since Jan 2007
17319 posts
Posted on 4/11/14 at 5:27 pm to
These guys just suck at being Americans.
Posted by constant cough
Lafayette
Member since Jun 2007
44788 posts
Posted on 4/11/14 at 5:28 pm to
The 'glitch' was probably something the NSA created.
Posted by AUin02
Member since Jan 2012
4281 posts
Posted on 4/11/14 at 5:42 pm to
quote:

The 'glitch' was probably something the NSA created.


Ehhh, don't give them too much credit. They've been finding and exploiting loopholes and glitches like this for years.
Posted by drizztiger
Deal With it!
Member since Mar 2007
37203 posts
Posted on 4/11/14 at 8:51 pm to
The public key private key model has been around for a long time now. This is a software issue.

ETA: Change your passwords now.
This post was edited on 4/11/14 at 9:11 pm
Posted by HailToTheChiz
Back in Auburn
Member since Aug 2010
48991 posts
Posted on 4/11/14 at 9:54 pm to
What's funny is that changing passwords won't matter. This is a server/software side problem not a user. You change the password without the site patching then the hacker has new password.

Reality is no one is safe on Internet. If hackers want your info they can get it. It's luck if the draw.

We should be able to sue nsa for any problems we may have, but we all know that's not going to happen.
Posted by LSURussian
Member since Feb 2005
126962 posts
Posted on 4/11/14 at 10:00 pm to
quote:

“The agency found the Heartbeat glitch
quote:

NSA discovered/exploited Heartbleed for two years
Which is it? Or, are there two viruses?
Posted by joshnorris14
Florida
Member since Jan 2009
45233 posts
Posted on 4/11/14 at 10:03 pm to
quote:

Which is it? Or, are there two viruses




Posted by drizztiger
Deal With it!
Member since Mar 2007
37203 posts
Posted on 4/11/14 at 10:04 pm to
quote:

What's funny is that changing passwords won't matter.
Yes, it will. Any data collected will no longer be relevant.
quote:

This is a server/software side problem not a user.
Agreed.
quote:

You change the password without the site patching then the hacker has new password.
True, but not exactly. 1. Sites need to patch. 2. All the major sites will or have done so. 3. This is a packet capture attack that doesn't target one individual. IE, no one is getting all of your passwords.

quote:

Reality is no one is safe on Internet. If hackers want your info they can get it. It's luck if the draw.
True, in a way perhaps. But plain text data isn't secure data. The issue with this vulnerability in OpenSSL (which in general, neither MS or Apple uses) is that the public key/private key secure connections have been compromised.

quote:

We should be able to sue nsa for any problems we may have, but we all know that's not going to happen.
Not sure about suing the NSA, but I'm not surprised they've known about it for 2 years and decided to not tell anyone.
Posted by Cs
Member since Aug 2008
10472 posts
Posted on 4/11/14 at 10:09 pm to
quote:

Which is it? Or, are there two viruses?



Heartbleed isn't a virus.
Posted by LSURussian
Member since Feb 2005
126962 posts
Posted on 4/11/14 at 10:13 pm to
So you don't know either? Or, are you just embarrassed your OP has such an obvious mistake in it?
Posted by LSURussian
Member since Feb 2005
126962 posts
Posted on 4/11/14 at 10:14 pm to
Two bugs? Is that better?
Posted by joshnorris14
Florida
Member since Jan 2009
45233 posts
Posted on 4/11/14 at 10:15 pm to
quote:

So you don't know either? Or, are you just embarrassed your OP has such an obvious mistake in it?





The only one who made an obvious mistake is you.
Posted by LSURussian
Member since Feb 2005
126962 posts
Posted on 4/11/14 at 10:16 pm to
Heartbeat or Heartbleed, joshie. Which is it?
first pageprev pagePage 1 of 2Next pagelast page

Back to top
logoFollow TigerDroppings for LSU Football News
Follow us on Twitter, Facebook and Instagram to get the latest updates on LSU Football and Recruiting.

FacebookTwitterInstagram