# Poll: Did NSA Know About and Use Heartbleed Bug?

**URL:** <https://boards.straightdope.com/t/poll-did-nsa-know-about-and-use-heartbleed-bug/685908>\
**Category:** In My Humble Opinion\
**Created:** [April 12, 2014, 1:38am UTC](https://boards.straightdope.com/t/poll-did-nsa-know-about-and-use-heartbleed-bug/685908 "2014-04-12T01:38:02Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![PastTense](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/pasttense/32/14550_2.png) [@PastTense](https://boards.straightdope.com/u/PastTense)\
**Post date:** [April 12, 2014, 1:38am UTC](https://boards.straightdope.com/t/poll-did-nsa-know-about-and-use-heartbleed-bug/685908/1 "2014-04-12T01:38:02Z")

</div>

“The U.S. National Security Agency knew for at least two years about a flaw in the way that many websites send sensitive information, now dubbed the Heartbleed bug, and regularly used it to gather critical intelligence, two people familiar with the matter said.”  
[http://www.bloomberg.com/news/2014-04-11/nsa-said-to-have-used-heartbleed-bug-exposing-consumers.html](http://www.bloomberg.com/news/2014-04-11/nsa-said-to-have-used-heartbleed-bug-exposing-consumers.html)

This story has been heavily reported in the tech press, although I don’t know if there any further verification than these two anonymous sources.

The government has strongly denied this report:  
“NSA was not aware of the recently identified vulnerability in OpenSSL, the so-called Heartbleed vulnerability, until it was made public in a private sector cybersecurity report. Reports that say otherwise are wrong.”

> **[IC ON THE RECORD • Statement on Bloomberg News story that NSA knew...](https://icontherecord.tumblr.com/post/82416436703/statement-on-bloomberg-news-story-that-nsa-knew)**
>
> Statement on Bloomberg News story that NSA knew about the “Heartbleed bug” flaw and regularly used it to gather critical intelligence
> 
> 
> April 11, 2014
> 
> 
> NSA was not aware of the recently identified vulnerability in OpenSSL, the so-called Heartbleed...

So which version is correct? I think the tech community no longer sees the government as having much credibility in this area (the Snowden revelations being a big factor) and I wonder how Dopers feel.

---

<div class="post-metadata">

**Author:** ![TriPolar](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/tripolar/32/3008_2.png) [@TriPolar](https://boards.straightdope.com/u/TriPolar)\
**Post date:** [April 12, 2014, 2:09am UTC](https://boards.straightdope.com/t/poll-did-nsa-know-about-and-use-heartbleed-bug/685908/2 "2014-04-12T02:09:28Z")

</div>

I don’t think the NSA is that good at hacking so I said no. Not that someone couldn’t have told them how to do it though, but it’s pretty much a coin toss right now.

---

<div class="post-metadata">

**Author:** ![beowulff](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/beowulff/32/542_2.png) [@beowulff](https://boards.straightdope.com/u/beowulff)\
**Post date:** [April 12, 2014, 2:21am UTC](https://boards.straightdope.com/t/poll-did-nsa-know-about-and-use-heartbleed-bug/685908/3 "2014-04-12T02:21:27Z")

</div>

Who cares?

---

<div class="post-metadata">

**Author:** ![TriPolar](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/tripolar/32/3008_2.png) [@TriPolar](https://boards.straightdope.com/u/TriPolar)\
**Post date:** [April 12, 2014, 2:29am UTC](https://boards.straightdope.com/t/poll-did-nsa-know-about-and-use-heartbleed-bug/685908/4 "2014-04-12T02:29:59Z")

</div>

> [@beowulff](#):
>
> Who cares?

Did the NSA tell you to post that?

---

<div class="post-metadata">

**Author:** ![buddha\_david](https://avatars.discourse-cdn.com/v4/letter/b/ee7513/32.png) [@buddha\_david](https://boards.straightdope.com/u/buddha_david)\
**Post date:** [April 12, 2014, 2:31am UTC](https://boards.straightdope.com/t/poll-did-nsa-know-about-and-use-heartbleed-bug/685908/5 "2014-04-12T02:31:30Z")

</div>

> [@PastTense](#):
>
> "The U.S. National Security Agency knew for at least two years about a flaw in the way that many websites send sensitive information, now dubbed the Heartbleed bug, and regularly used it to gather critical intelligence, **two people familiar with the matter said."**

Can’t help but wonder if those two people will soon find themselves unemployed…

And I did vote “Yes”; in fact, when this story broke, I smacked myself on the forehead and said, “So THAT’S how they’ve been doing it!”

---

<div class="post-metadata">

**Author:** ![rbroome](https://avatars.discourse-cdn.com/v4/letter/r/838e76/32.png) [@rbroome](https://boards.straightdope.com/u/rbroome)\
**Post date:** [April 12, 2014, 2:59am UTC](https://boards.straightdope.com/t/poll-did-nsa-know-about-and-use-heartbleed-bug/685908/6 "2014-04-12T02:59:17Z")

</div>

> [@PastTense](#):
>
> “The U.S. National Security Agency knew for at least two years about a flaw in the way that many websites send sensitive information, now dubbed the Heartbleed bug, and regularly used it to gather critical intelligence, two people familiar with the matter said.”  
> [NSA Said to Have Used Heartbleed Bug, Exposing Consumers - Bloomberg](http://www.bloomberg.com/news/2014-04-11/nsa-said-to-have-used-heartbleed-bug-exposing-consumers.html)
> 
> This story has been heavily reported in the tech press, although I don’t know if there any further verification than these two anonymous sources.
> 
> The government has strongly denied this report:  
> “NSA was not aware of the recently identified vulnerability in OpenSSL, the so-called Heartbleed vulnerability, until it was made public in a private sector cybersecurity report. Reports that say otherwise are wrong.”  
> [http://icontherecord.tumblr.com/post/82416436703/statement-on-bloomberg-news-story-that-nsa-knew](http://icontherecord.tumblr.com/post/82416436703/statement-on-bloomberg-news-story-that-nsa-knew)
> 
> So which version is correct? I think the tech community no longer sees the government as having much credibility in this area (the Snowden revelations being a big factor) and I wonder how Dopers feel.

I can’t decide. When I first heard Bloomsberg’s report I believed it. The problem now is one can’t decide who to believe. Unless the information turns up in Snowden’s reports, I don’t know who to believe. If it is true, it would be classified at a very high level. I may be gullible, but folks with those clearances don’t leak information to the press without an OK. If one of them is even slightly suspected, their clearance gets suspended and their career is over. The risks far outweigh the benefits. When such information is leaked I believe it is done deliberately. The NSA is in a difficult position. In this case they know people will assume they knew. And they may. What they don’t know is the full extent of the Snowden leaks. If they did have the flaw, the truth might come out any moment. Now they can both admit (via this leak) and deny via the press release. The contradiction causes confusion and gives defenders something to point to. If they knew and the information does come out, the leak gives them some cover. If no proof comes out, they can point to the press release. At this point, it is all about damage control.

If my theory is true, I doubt a bunch of Gov’t bureaucrats came up with this plan. I wonder what the PR agency had to go through when they got hired to advise the NSA. Talk about a difficult customer!

---

<div class="post-metadata">

**Author:** ![buddha\_david](https://avatars.discourse-cdn.com/v4/letter/b/ee7513/32.png) [@buddha\_david](https://boards.straightdope.com/u/buddha_david)\
**Post date:** [April 12, 2014, 3:11am UTC](https://boards.straightdope.com/t/poll-did-nsa-know-about-and-use-heartbleed-bug/685908/7 "2014-04-12T03:11:14Z")

</div>

After actually reading the article (heh) it turns out the “two people familiar with the matter” are [Ghostery](http://en.wikipedia.org/wiki/Ghostery) Senior Dir. of Research Andy Kahl & Bloomberg’s Michael Riley – i.e., two journalists presenting their opinions as fact. :smack:

That said, I do agree with their _opinion_ – that is, the NSA probably knew about and utilized this bug for a very long time. After all, it’s an exploit that allows secret access to a computer system and leaves no trace, which is especially handy for a government agency whose mandate is to access computer systems and leave no trace. On the other hand, I don’t think we’ll ever know the entire truth…

---

<div class="post-metadata">

**Author:** ![Senegoid](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/senegoid/32/6606_2.png) [@Senegoid](https://boards.straightdope.com/u/Senegoid)\
**Post date:** [April 12, 2014, 5:42am UTC](https://boards.straightdope.com/t/poll-did-nsa-know-about-and-use-heartbleed-bug/685908/8 "2014-04-12T05:42:56Z")

</div>

Something I’m finding really :dubious: about this whole Heartbleed thing is that it’s supposedly been hidden in there for several years, and all of a sudden almost simultaneously, _two_ people on near-opposite sides of the planet discover it independently.

---

<div class="post-metadata">

**Author:** ![tellyworth](https://avatars.discourse-cdn.com/v4/letter/t/977dab/32.png) [@tellyworth](https://boards.straightdope.com/u/tellyworth)\
**Post date:** [April 12, 2014, 5:55am UTC](https://boards.straightdope.com/t/poll-did-nsa-know-about-and-use-heartbleed-bug/685908/9 "2014-04-12T05:55:07Z")

</div>

> [@buddha\_david](#):
>
> After all, it’s an exploit that allows secret access to a computer system and leaves no trace

That’s not necessarily true. If it was widely exploited before the partial disclosure in April, chances are someone will turn up evidence of it. The University of Michigan has [checked their logs](https://zmap.io/heartbleed/) back to November 2013, and the first sign of scans turned up in April, from Chinese IPs.

That doesn’t eliminate the possibility that the NSA used the exploit on specific targets of course. But it does confirm that any earlier attacks could have left a trace somewhere and might yet be revealed.

There’s no way to know for sure, and there might never be. I think the NSA is fairly likely to be telling the truth here, but I’m not at all certain of that.

---

<div class="post-metadata">

**Author:** ![Rick\_Kitchen](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/rick_kitchen/32/522_2.png) [@Rick\_Kitchen](https://boards.straightdope.com/u/Rick_Kitchen)\
**Post date:** [April 12, 2014, 6:08am UTC](https://boards.straightdope.com/t/poll-did-nsa-know-about-and-use-heartbleed-bug/685908/10 "2014-04-12T06:08:00Z")

</div>

you’re asking us for opinions that we have no basis to make a reasoned answer on? it would be like flipping a coin.

---

<div class="post-metadata">

**Author:** ![buddha\_david](https://avatars.discourse-cdn.com/v4/letter/b/ee7513/32.png) [@buddha\_david](https://boards.straightdope.com/u/buddha_david)\
**Post date:** [April 12, 2014, 9:32am UTC](https://boards.straightdope.com/t/poll-did-nsa-know-about-and-use-heartbleed-bug/685908/11 "2014-04-12T09:32:08Z")

</div>

> [@tellyworth](#):
>
> That doesn’t eliminate the possibility that the NSA used the exploit on specific targets of course. But it does confirm that any earlier attacks could have left a trace somewhere and might yet be revealed.

It’s safe to assume that the NSA uses numerous tricks to cover their tracks, even when they break into a system via the front door. We ARE talking about the largest and most well-funded intelligence organization on earth, not some enclave of drunken Russian hackers, after all. So any evidence they do leave behind would only trace as far back as “McDermott’s Waffle House” or something.

---

<div class="post-metadata">

**Author:** ![Jonathan\_Chance](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/jonathan_chance/32/701_2.png) [@Jonathan\_Chance](https://boards.straightdope.com/u/Jonathan_Chance)\
**Post date:** [April 12, 2014, 2:00pm UTC](https://boards.straightdope.com/t/poll-did-nsa-know-about-and-use-heartbleed-bug/685908/12 "2014-04-12T14:00:26Z")

</div>

Toss in the fact that their credibility is for shit and I’m not sure I’d believe them if they told me they weren’t space aliens.

---

<div class="post-metadata">

**Author:** ![ratatoskK](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ratatoskk/32/2987_2.png) [@ratatoskK](https://boards.straightdope.com/u/ratatoskK)\
**Post date:** [April 12, 2014, 2:12pm UTC](https://boards.straightdope.com/t/poll-did-nsa-know-about-and-use-heartbleed-bug/685908/13 "2014-04-12T14:12:26Z")

</div>

Since this was a yes-or-no question, I answered Yes, but actually I think it’s entirely possible the NSA conceived and/or used Heartbleed, but I don’t know whether they actually do/did.

---

<div class="post-metadata">

**Author:** ![Gagundathar](https://avatars.discourse-cdn.com/v4/letter/g/a183cd/32.png) [@Gagundathar](https://boards.straightdope.com/u/Gagundathar)\
**Post date:** [April 12, 2014, 3:10pm UTC](https://boards.straightdope.com/t/poll-did-nsa-know-about-and-use-heartbleed-bug/685908/14 "2014-04-12T15:10:45Z")

</div>

I voted yes because if they didn’t know they sure as heck should have. The NSA employs some of the brightest crackers on the planet. This was an open source flaw. It would astound me if the NSA didn’t know about it. They don’t even have to ‘sneak in’ and get the source. It is there to be read. If they don’t run emulators on their servers of all of the common combinations of SSL, then they aren’t who I think they are.

Seriously, this is pretty much a no-brainer to me, but I am (as almost always) willing to be corrected.

---

<div class="post-metadata">

**Author:** ![beowulff](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/beowulff/32/542_2.png) [@beowulff](https://boards.straightdope.com/u/beowulff)\
**Post date:** [April 12, 2014, 4:41pm UTC](https://boards.straightdope.com/t/poll-did-nsa-know-about-and-use-heartbleed-bug/685908/15 "2014-04-12T16:41:57Z")

</div>

> [@TriPolar](#):
>
> Did the NSA tell you to post that?

Wait!  
That’s not what I posted!  
Someone must have changed my post after the fact.

---

<div class="post-metadata">

**Author:** ![Measure\_for\_Measure](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/measure_for_measure/32/557_2.png) [@Measure\_for\_Measure](https://boards.straightdope.com/u/Measure_for_Measure)\
**Post date:** [April 12, 2014, 8:29pm UTC](https://boards.straightdope.com/t/poll-did-nsa-know-about-and-use-heartbleed-bug/685908/16 "2014-04-12T20:29:52Z")

</div>

> [@beowulff](#):
>
> Who cares?

> [@TriPolar](#):
>
> Did the NSA tell you to post that?

Did the NSA tell _you_ to post _that_?

> [@beowulff](#):
>
> Wait!  
> That’s not what I posted!  
> Someone must have changed my post after the fact.

That was me.  
The OP: Yes, the NSA probably knew about it. Not 100% though and not even 95%. It should be investigated.

---

<div class="post-metadata">

**Author:** ![Measure\_for\_Measure](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/measure_for_measure/32/557_2.png) [@Measure\_for\_Measure](https://boards.straightdope.com/u/Measure_for_Measure)\
**Post date:** [April 12, 2014, 11:16pm UTC](https://boards.straightdope.com/t/poll-did-nsa-know-about-and-use-heartbleed-bug/685908/17 "2014-04-12T23:16:20Z")

</div>

AFAIK, OpenSSL was an all-volunteer effort: it had no employees.

> [@PastTense](#):
>
> The government has strongly denied this report:  
> “NSA was not aware of the recently identified vulnerability in OpenSSL, the so-called Heartbleed vulnerability, until it was made public in a private sector cybersecurity report. Reports that say otherwise are wrong.”  
> [http://icontherecord.tumblr.com/post/82416436703/statement-on-bloomberg-news-story-that-nsa-knew](http://icontherecord.tumblr.com/post/82416436703/statement-on-bloomberg-news-story-that-nsa-knew)

If this is the case, heads should roll. The NSA should be combing OpenSSL, looking for exploitable bugs. This bug wasn’t especially profound. There needs to be an investigation of this example of sheer incompetence. [Other intelligence agencies](https://www.eff.org/deeplinks/2014/04/wild-heart-were-intelligence-agencies-using-heartbleed-november-2013) apparently knew about this bug: why didn’t the NSA? This concerns me.

(The link in question documents a pattern of cyber-activity last fall that fits an intelligence gathering profile more than a cybercrime profile. And yet we know the NSA didn’t have access to this bug: their official statement proves that, up to a point.)

---

<div class="post-metadata">

**Author:** ![Octarine](https://avatars.discourse-cdn.com/v4/letter/o/22d042/32.png) [@Octarine](https://boards.straightdope.com/u/Octarine)\
**Post date:** [April 12, 2014, 11:59pm UTC](https://boards.straightdope.com/t/poll-did-nsa-know-about-and-use-heartbleed-bug/685908/18 "2014-04-12T23:59:41Z")

</div>

Given that right now anything we think is basically as credible as going “eenie meenie miny moe” between the two options, I went with “Yes,” because the NSA said “No,” and I’m not exactly confident in their truth telling abilities right now.

---

<div class="post-metadata">

**Author:** ![Rysto](https://avatars.discourse-cdn.com/v4/letter/r/ecccb3/32.png) [@Rysto](https://boards.straightdope.com/u/Rysto)\
**Post date:** [April 13, 2014, 12:02am UTC](https://boards.straightdope.com/t/poll-did-nsa-know-about-and-use-heartbleed-bug/685908/19 "2014-04-13T00:02:53Z")

</div>

I have no idea whether they actually knew or not. I definitely believe that had they known they would have been exploiting the hell out of it though.

---

<div class="post-metadata">

**Author:** ![tellyworth](https://avatars.discourse-cdn.com/v4/letter/t/977dab/32.png) [@tellyworth](https://boards.straightdope.com/u/tellyworth)\
**Post date:** [April 13, 2014, 12:10am UTC](https://boards.straightdope.com/t/poll-did-nsa-know-about-and-use-heartbleed-bug/685908/20 "2014-04-13T00:10:09Z")

</div>

> [@buddha\_david](#):
>
> It’s safe to assume that the NSA uses numerous tricks to cover their tracks, even when they break into a system via the front door. We ARE talking about the largest and most well-funded intelligence organization on earth, not some enclave of drunken Russian hackers, after all. So any evidence they do leave behind would only trace as far back as “McDermott’s Waffle House” or something.

It doesn’t have to trace back to the NSA. Any evidence of Heartbleed being exploited earlier than April, from any source, suggests the NSA is probably lying.

Measure for Measure’s EFF link has one very likely positive hit in November. That tips my answer to Yes.

[Next page](https://boards.straightdope.com/t/poll-did-nsa-know-about-and-use-heartbleed-bug/685908.md?page=2)
