Discussion about this post

User's avatar
Comrade Wingtardd's avatar

There is no way the NSA does not have a team of coders that know the OpenSSL code by heart. They've definitely known about it.

Comrade Wingtardd's avatar

"... attempt to exploit would stick out like a sore thumb"

How? None of those TLS heartbeat requests are logged anywhere, you would never know. You can definitely target someone - you only need know what websites they tend to visit. Granted, it's more useful to an identity thief / fraud type than the NSA, but in no way is it a "weak" exploit - it's rather devastating.

16 more comments...

No posts

Ready for more?