The US National Security Agency knew about the critical Heartbleed security flaw in the Internet, and not only did it not disclose it but it was also exploiting it to collect information.
Heartbleed concerns the encryption software that about two-thirds of websites use to transmit data to and from their users. The vulnerability, which has existed in the OpenSSL software since 2012, is one of the largest security breaches in the history of the Internet, and some companies and experts are even recommending that ordinary users change their passwords everywhere.
Major companies such as Yahoo, Cisco and Juniper Networks rushed to upgrade their systems after the discovery of Heartbleed last week, and the US government warned of a potential wave of cyberattacks.
Bloomberg sources state that the NSA systematically exploited Heartbleed for surveillance, a tactic that contradicts a key goal of the agency, the protection of computers in the US.
The publication comments that whistleblower Edward Snowden's revelations about the NSA's practices have given a clearer picture of the agency's two roles, often contradictory: on the one hand, protecting government networks and certain critical infrastructure, and on the other, launching attacks on other computers, even those of other governments, to collect information.
For this reason, the NSA reportedly has a long list of security vulnerabilities in various software products, which it does not always disclose.
However, the committee that was tasked with reviewing the NSA's practices after the Snowden revelations recommended, among other things, that the agency should hurry to fix security gaps instead of using them for surveillance.
Source: planet-greece.blogspot.com
