Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

unhappycamper

(60,364 posts)
Thu Apr 17, 2014, 06:47 AM Apr 2014

Would You Trust The NSA's Advice On How To Deal With Heartbleed?

https://www.techdirt.com/articles/20140414/16111926910/would-you-trust-nsas-advice-how-to-deal-with-heartbleed.shtml

Would You Trust The NSA's Advice On How To Deal With Heartbleed?
from the didn't-think-so dept
(Mis)Uses of Technology
by Mike Masnick
Tue, Apr 15th 2014 5:16am

Somewhat late to the game (by about a week), after the Heartbleed vulnerability was publicly revealed, and a few days after it was reported and denied that the NSA was already well aware of Heartbleed and exploiting it, the NSA has put out a one page PDF about Heartbleed. This seems like something of a too little, too late effort by the NSA to live up to its semi-promise of a "bias" towards revealing vulnerabilities over exploiting them. However, that leads to the simple question that plenty of people should be asking: given everything you've learned about the NSA recently (or, well, for years), would you trust the NSA's advice on how to deal with Heartbleed? Not that I think the NSA would publicly suggest anything bad, but at this point, the NSA has a serious trust problem in convincing anyone engaged in computer security that they have their best interests in mind.

--

The NSA one page handout:
http://s3.documentcloud.org/documents/1112649/slicksheet-openssl-web.pdf

Latest Discussions»Issue Forums»National Security & Defense»Would You Trust The NSA's...