Slashdot Mirror


Obama Says He May Or May Not Let the NSA Exploit the Next Heartbleed

An anonymous reader writes "The White House has joined the public debate about Heartbleed. The administration denied any prior knowledge of Heartbleed, and said the NSA should reveal such flaws once discovered. Unfortunately, this statement was hedged. The NSA should reveal these flaws unless 'a clear national security or law enforcement need' exists. Since that can be construed to apply to virtually any situation, we're left with the same dilemma as before: do we take them at their word or not? The use of such an exploit is certainly not without precedent: 'The NSA made use of four "zero day" vulnerabilities in its attack on Iran's nuclear enrichment sites. That operation, code-named "Olympic Games," managed to damage roughly 1,000 Iranian centrifuges, and by some accounts helped drive the country to the negotiating table.' A senior White House official is quoted saying, 'I can't imagine the president — any president — entirely giving up a technology that might enable him some day to take a covert action that could avoid a shooting war.'" Side note: CloudFlare has named several winners in its challenge to prove it was possible to steal private keys using the Heartbleed exploit.

7 of 134 comments (clear)

  1. Well, yeah by LordLucless · · Score: 5, Insightful

    Spy agency's job is to spy. It'd be remiss of them not to use such a security hole.

    The question is, would he allow the NSA to exploit a similar vulnerability against Americans. And I think we already know the answer to that one too.

    --
    Just because you're paranoid doesn't mean there isn't an invisible demon about to eat your face
    1. Re:Well, yeah by Charliemopps · · Score: 5, Insightful

      No, the NSAs (as well as all government agencies) job is to defend the constitution and protect the citizens of the United States of America. The NSA has abandon the former goal in favor of the latter. They are not mutually exclusive. This country was founded on the principle that we as a people value freedom and liberty over life itself. The NSA, and apparently the president have forgotten this.

  2. Sounds like by rmdingler · · Score: 5, Insightful
    He is pretty much admitting the next vulnerability will be exploited until no further military or law enforcement benefit exists.

    There are almost certainly ongoing exploits of vulnerable systems.

    People will very often tell you their intentions if you listen closely enough.

    --
    Happiness in intelligent people is the rarest thing I know.

    Ernest Hemingway

  3. There's no information here. by slapjerkt · · Score: 5, Insightful

    The information content of a sentence whose structure is, "I may x or I may not x" is 0.

    --
    [Signature omitted due to copyright restrictions.]
  4. If you trust the word of the NSA by kruach+aum · · Score: 5, Insightful

    you're a moron. Don't trust liars who have been proven to lie and then continue lying. In fact you probably shouldn't trust liars in general.

  5. Obama could issue an Executive Order by PeeAitchPee · · Score: 5, Insightful

    The NSA is part of the Executive Branch. Obama could immediately, at the very least, put a temporary halt on all of these types of activities and conduct a review gauging the potential impact on ordinary US citizens as collateral damage. He has done no such thing -- not with mass surveillance, not with HeartBleed, not with any of the other nasty shit disclosed in the Snowden leaks. Don't DARE give him a pass on anything NSA-related -- he doesn't need Congress in this case and can personally shut it all down at any time.

  6. Re:Not it actually isn't... by Enigma2175 · · Score: 5, Insightful

    The job of any government agency to defend the constitution. It's the job of the judicial branch. Furthermore, you actually expect a spy agency to protect the constitution? That's not even close to their job.

    The naivete some have on this issue is rather surprising given the demographics of the site.

    Employees at the NSA take an oath to defend the constitution. From the NSA's website:

    NSA/CSS employees are Americans first, last, and always. We treasure the U.S. Constitution and the rights it secures for all the people. Each employee takes a solemn oath to support and defend the Constitution of the United States against all enemies, foreign and domestic.

    It's not naivete, it's just expecting them to do what they SWORE TO DO.

    --

    Enigma