HomeinetBloomberg: NSA knew about and used the Heartbleed bug

Bloomberg: NSA knew about and used the Heartbleed bug

The NSA knew about the Heartbleed and regularly used it to gather information for at least two years, unnamed sources told Bloomberg.

NSA-Heartbleed

If the publication of the (valid) website is true, the NSA could collect information, such as passwords and private communications from hundreds of thousands of websites, given that Heartbleed is a bug in the popular open-source OpenSSL encryption software, which is used for data security on hundreds of thousands of websites, including Gmail and Facebook.

About two hours after Bloomberg's publication, the NSA and the White House denied the claims in statements they sent to Mashable.

“The NSA did not know the vulnerability of OpenSSL, the so‑called Heartbleed, until it was disclosed by some company on the internet,” said an NSA spokesperson to Mashable. “The publications that say otherwise are incorrect.”

The spokesperson of the National Security Council Caitlin Hayden also stated that neither the NSA nor any other federal agency knew about the Heartbleed bug.

“If the federal government, including the intelligence community, had discovered the vulnerability, they would have reported it to the OpenSSL community”, Hayden said in a statement.

Of course, we would not expect anything else from government statements, since if it were revealed that the NSA had left the door open to other intelligence agencies and the entire world, it would contradict what the agency claims to be its core mission. If you forgot the mission of the secret service, let us remind you that it is to protect and defend cybersecurity.
Bloomberg's revelation seems to have shocked a lot of people, although it should not have been a surprise. During the last few days, some had already wondered if the NSA was using Heartbleed to break SSL encryption, given that documents leaked by Edward Snowden revealed that the agency has been trying to break it for years.

“It wouldn't be at all a surprise to me if the NSA had discovered the vulnerability long before us” said to Wired, Matt Blaze, cryptographer and professor at the University of Pennsylvania. “It is certainly something the NSA would have found extremely useful in their arsenal.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS