{"id":64573,"date":"2014-04-11T23:28:46","date_gmt":"2014-04-11T21:28:46","guid":{"rendered":"http:\/\/onsoftware.en.softonic.com\/?p=64573"},"modified":"2025-07-02T00:45:34","modified_gmt":"2025-07-02T07:45:34","slug":"report-nsa-has-been-exploiting-heartbleed-bug-for-years","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/report-nsa-has-been-exploiting-heartbleed-bug-for-years\/","title":{"rendered":"Report: NSA has been exploiting Heartbleed bug for years"},"content":{"rendered":"<p>Bloomberg released a report today accusing the United States National Security Agency of exploiting the <a title=\"&quot;Heartbleed&quot; security bug leaves majority of the web vulnerable\" href=\"http:\/\/news.en.softonic.com\/heartbleed-openssl-security-bug\" target=\"_self\" rel=\"noopener noreferrer\">Heartbleed bug<\/a> for years. If true, the NSA&#8217;s bulk <a title=\"PRISM Leaked NSA slides explains real-time monitoring\" href=\"http:\/\/news.en.softonic.com\/prism-leaked-nsa-slides-explains-real-time-monitoring\" target=\"_self\" rel=\"noopener noreferrer\">data collection program<\/a> could have been enabled by the Heartbleed bug.<\/p>\n<p>Two anonymous people &#8220;familiar with the matter&#8221; told Bloomberg that the NSA has been exploiting Heartbleed for years. The bug is found in the OpenSSL cryptography protocol that keeps connections to websites secure. Heartbleed allows hackers to listen in on the connection to find the <strong>private keys<\/strong> exchanged between users and websites.<\/p>\n<p>Heartbleed is turning out to be one of the biggest internet security holes ever discovered. Initial reports say that 66% of all websites are affect by Heartbleed, but those numbers <a title=\"Are the dangers of the Heartbleed vulnerability exaggerated?\" href=\"http:\/\/news.en.softonic.com\/heartbeat-bug-exaggeration\" target=\"_self\" rel=\"noopener noreferrer\">may be exaggerated<\/a>.<\/p>\n<p>&#8220;It flies in the face of the agency&#8217;s comments that defense comes first,&#8221; said director of the cyber statecraft initiative at the Atlantic Council Jason Healey. By keeping the Heartbleed bug vulnerable, the NSA could exploit it to collect more user data but <strong>at the expense of its citizens<\/strong>. Hackers and the NSA alike could have been using Heartbleed to steal user information since 2012 when the bug was first released.<\/p>\n<p>The NSA denies knowing about the Heartbleed bug until news broke about it this Monday. &#8220;Statement: NSA was not aware of the recently identified Heartbleed vulnerability until it was made public,&#8221; writes the NSA from its official Twitter account.<\/p>\n<p>The NSA&#8217;s <a title=\"New NSA chief explains agency policy on \u201czero-day\u201d exploits to Senate\" href=\"http:\/\/arstechnica.com\/tech-policy\/2014\/03\/new-nsa-chief-explains-agency-policy-on-zero-day-exploits-to-senate\/\" target=\"_blank\" rel=\"noopener noreferrer\">official policy<\/a> is to &#8220;disclose vulnerabilities in products and systems used by the US and its allies.&#8221; If Bloomberg&#8217;s report is true, it will fly in the face of the organization&#8217;s previous statements.<\/p>\n<p><em>Source: <a title=\"Bloomberg\" href=\"http:\/\/www.bloomberg.com\/news\/2014-04-11\/nsa-said-to-have-used-heartbleed-bug-exposing-consumers.html\" target=\"_blank\" rel=\"noopener noreferrer\">Bloomberg<\/a><\/em><\/p>\n<p><em>Via: <a title=\"Ars Technica\" href=\"http:\/\/arstechnica.com\/security\/2014\/04\/nsa-used-heartbleed-nearly-from-the-start-report-claims\/\" target=\"_self\" rel=\"noopener noreferrer\">Ars Technica<\/a><\/em><\/p>\n<h4>MORE ON THE HEARTBLEED VULNERABILITY<\/p>\n<ul>\n<li><a href=\"http:\/\/news.en.softonic.com\/heartbeat-bug-exaggeration\" target=\"_self\" rel=\"noopener noreferrer\">Are the dangers of the Heartbleed vulnerability exaggerated?<\/a><\/li>\n<li><a href=\"http:\/\/features.en.softonic.com\/heartbleed-five-steps-to-protect-your-account\" target=\"_self\" rel=\"noopener noreferrer\">Heartbleed: five steps to protect your accounts<\/a><\/li>\n<li><a href=\"http:\/\/news.en.softonic.com\/the-softonic-minute-heartbleed-twitter-facebook-and-windows-xp\" target=\"_self\" rel=\"noopener noreferrer\">The Softonic Minute: Heartbleed, Twitter, Facebook and Windows XP<\/a><\/li>\n<li><a href=\"http:\/\/news.en.softonic.com\/apple-not-affected-by-heartbleed-bug\" target=\"_self\" rel=\"noopener noreferrer\">Apple claims it was not affected by Heartbleed security bug<\/a><\/li>\n<li><a href=\"http:\/\/news.en.softonic.com\/soundcloud-heartbleed-bug-fix\" target=\"_self\" rel=\"noopener noreferrer\">Soundcloud signs out users in wake of Heartbleed bug<\/a><\/li>\n<li>&#8220;<a href=\"http:\/\/news.en.softonic.com\/heartbleed-openssl-security-bug\" target=\"_self\" rel=\"noopener noreferrer\">Heartbleed&#8221; security bug leaves majority of the web vulnerable<\/a><\/li>\n<\/ul>\n<\/h4>\n","protected":false},"excerpt":{"rendered":"<p>Bloomberg released a report today accusing the United States National Security Agency of exploiting the Heartbleed bug for years. If true, the NSA&#8217;s bulk data collection program could have been enabled by the Heartbleed bug. Two anonymous people &#8220;familiar with the matter&#8221; told Bloomberg that the NSA has been exploiting Heartbleed for years. The bug &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/report-nsa-has-been-exploiting-heartbleed-bug-for-years\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Report: NSA has been exploiting Heartbleed bug for years&#8221;<\/span><\/a><\/p>\n","protected":false},"author":2033,"featured_media":64576,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[2441],"tags":[],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-64573","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-how-to"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/64573","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/2033"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=64573"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/64573\/revisions"}],"predecessor-version":[{"id":330952,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/64573\/revisions\/330952"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/64576"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=64573"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=64573"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=64573"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=64573"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=64573"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=64573"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}