Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The NSA would monitor hacker message boards and the various black market websites for exploits like this.

If they find something which they don't see any chatter about on any of these sources, then it's reasonable to presume no one has found it. Moreover, actually exploiting heartbleed would leave a signature. You can fake SSL certificates, but eventually someone has to lose their money, or some innovation has to come out of the blue. MitM's involve traffic diversions unless they're conducted at a government level.

Espionage always leaves a trail - even if you don't know where someone gets their intel, you can always tell they must be getting it somehow.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: