Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

So, the NSA are, to a person, lying sacks of shit. After their director's performance in front on congress -- the "least untruthful answer possible" -- don't trust a damn word.

So when they say they share, with whom? And what priority? Ooh, you found a documentation bug; is that the one you chose to share? The more severe a bug is, the more useful to them.

There's a million ways to parse this bullshit that come down to mean they're doing what they did all along but better at lying in public.



I want to be more specific about the concept of sharing.

There are two uses of "sharing" in the response. One was sharing of vulnerabilities. It was never clear who it was shared with. It could be with the DoD, with GCHQ, with private contractors under contract with the NSA, etc. and still be counted as "sharing."

The other is an example of sharing one patch, for the Bash vulnerability, with the private sector.

I think we are supposed to connect those two pieces of data, but there's no reason to do so.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: