Topic: Heartbleed

7 chapters across the catalog

Tom Tatoe
Episode 715 31:49 - 37:07

715: Tom Tatoe

NCCIC Operations, Cyber Incident Reporting, and Vulnerability Mitigation

The National Cybersecurity and Communications Integration Center (NCCIC) is described as the central interface for cyber threat mitigation. Secretary Jeh Johnson claims the agency handled 97,000 incident reports and issued 12,000 alerts in 2014. The segment mocks the agency's "house calls" to private companies and its role in mitigating vulnerabilities like Heartbleed and Shellshock.

Arming A-holes
Episode 667 1:51:22 - 1:59:03

667: Arming A-holes

Admiral Mike Rogers, NSA and Heartbleed Bug

NSA Director Admiral Mike Rogers claimed during a Stanford talk that the agency discovered the "Heartbleed" vulnerability and shared the patch with the private sector within 24 hours. This contradicts the public narrative that Google researcher Neel Mehta discovered the bug. The hosts suggest the NSA allowed Google to take credit to maintain a "fundamentally strong internet" while hiding the agency's involvement.

Johnson's Johnson, Jump!
Episode 609 2:35:16 - 2:38:40

609: Johnson's Johnson, Jump!

Heartbleed Bug Branding and Canadian Arrest

The "Heartbleed" security bug was branded with a professional logo by the security firm Codenomicon, which the hosts claim was plagiarized from the artist Danger Mouse. They also question how Canadian police were able to arrest a 19-year-old for exploiting the bug if the vulnerability supposedly leaves no logs or traces.

Cli-Fi®
Episode 608 29:05 - 34:02

608: Cli-Fi®

Bloomberg NSA Heartbleed Report, Michael Reilly, Zero-Day Exploits

Bloomberg News reported that the NSA was aware of the Heartbleed bug for at least two years and exploited it for intelligence gathering. The NSA and the White House issued rare, flat denials, stating their policy is to disclose major vulnerabilities to the public. The hosts analyze the conflicting reports, questioning why the NSA would need such a bug given their existing surveillance capabilities.

Cli-Fi®
Episode 608 34:02 - 44:27

608: Cli-Fi®

Codenomicon, Google, Heartbleed Discovery Timeline

The discovery of the Heartbleed bug by security firm Codenomicon and Google researcher Neel Mehta is scrutinized for its suspicious timing and connections to government spooks. Howard A. Schmidt, a former White House cybersecurity coordinator, serves as the chairman of Codenomicon, while Mehta has ties to the Freedom of the Press Foundation. The hosts question the "coincidental" simultaneous discovery of a two-year-old bug by two separate entities.

Cli-Fi®
Episode 608 44:28 - 53:13

608: Cli-Fi®

Al Jazeera Heartbleed Coverage, Alicia Hutnick, Professional Spin

Attorney Alicia Hutnick appeared on Al Jazeera to discuss the Heartbleed bug, providing what the hosts characterize as professional spin and technically inaccurate information. Hutnick claimed the bug left no "breadcrumbs" and downplayed its impact on military infrastructure. The hosts argue that such media appearances are designed to run interference for the NSA and confuse the general public about data security.

Big Sandy
Episode 607 2:38:25 - 2:41:28

607: Big Sandy

Intelligence Budget Transparency Act, Black Budgets, and Heartbleed

Congressman Peter Welch is promoting the "Intelligence Budget Transparency Act" to force the disclosure of the total dollar amounts spent by the 17 US intelligence agencies. The hosts discuss the "Heartbleed" bug in OpenSSL, questioning why the open-source community failed to catch a vulnerability that existed for two years. They suggest the NSA likely exploited the bug for years while ignoring its potential for domestic harm.