Hacker News new | ask | show | jobs
by lkd 4455 days ago
Or they straight out lied.

Wouldn't be the first time.

2 comments

Or they didn't.

See, now we have complete set of possible answers! So, what does it means when NSA officially announces something? I'd say, it means nothing.

If they did know, they would not admit it.

Maybe they didn't know. But we certainly do not have the right to know if they did know or not. This means something.

Or they just didn't know. Seriously, if you divide the world into the NDA and the non-NSA, then why would the former be much better than the latter at finding vulnerabilities in open source software?
Budget, mission, and legal privileges.

For the money they get, and the supposed "Cyber Command" mission, they should have a team of great auditors, and advanced tools, that's much larger and more competent than the volunteer OpenSSL team itself. This group should go over all similar code multiple times with a magnifying glass.

Otherwise, what's the point of the NSA & Cyber Command, on its own stated terms?