[170939] in North American Network Operators' Group
Re: [[Infowarrior] - NSA Said to Have Used Heartbleed Bug for Years]
daemon@ATHENA.MIT.EDU (Randy Bush)
Sun Apr 13 10:53:02 2014
Date: Sun, 13 Apr 2014 23:52:32 +0900
From: Randy Bush <randy@psg.com>
To: Michael Thomas <mike@mtcc.com>
In-Reply-To: <534AA308.5080509@mtcc.com>
Cc: North American Network Operators' Group <nanog@nanog.org>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
>> the point of open source is that the community is supposed to be doing
>> this. we failed.
> Versus all of the closed source bugs that nobody can know of or do
> anything about?
for those you can blame the vendor. this one is owned by the community.
it falls on us to try to lower the probability of a next one by actively
auditing source as our civic duty.
randy