SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    NSA on Security Vulnerabilities Disclosure
Date    Thursday May 01 2014, @10:42PM
Author    martyb
Topic   
from the who's-henhouse-is-being-guarded? dept.
https://soylentnews.org/article.pl?sid=14/05/01/1611226

SpallsHurgenson writes:

The US National Security Agency (NSA) will not always disclose security vulnerabilities, such as Heartbleed, and said it assesses each case individually, according to a blog post on the White House website.

"Disclosing a vulnerability can mean that we forego an opportunity to collect crucial intelligence that could thwart a terrorist attack stop the theft of our nation's intellectual property, or even discover more dangerous vulnerabilities that are being used by hackers or other adversaries to exploit our networks," government cyber security co-ordinator Michael Daniel explained. "We have also established a disciplined, rigorous and high-level decision-making process for vulnerability disclosure. This inter-agency process helps ensure that all of the pros and cons are properly considered and weighed."

The article continues with a list of factors used to assess disclosure:

Assuming these are the only factors they use, how reasonable do you think they are? What, if anything, would you change and why?

Links

  1. "not always disclose" - http://www.v3.co.uk/v3-uk/news/2342039/us-admits-nsa-does-not-always-disclose-security-flaws-it-uncovers
  2. "blog post" - http://www.whitehouse.gov/blog/2014/04/28/heartbleed-understanding-when-we-disclose-cyber-vulnerabilities

© Copyright 2026 - SoylentNews, All Rights Reserved

printed from SoylentNews, NSA on Security Vulnerabilities Disclosure on 2026-08-14 10:38:02