NSA Said to Exploit Heartbleed Bug for Intelligence for Years
bloomberg.com
bloomberg.com
> The Heartbleed flaw, introduced in early 2012 in a minor adjustment to the OpenSSL protocol, highlights one of the failings of open source software development.
And its discovery and resolution highlights one of the advantages of open-source software development.
I wouldn't say that its discovery (two years later) says anything good about open source development.
In the end software is written by people and people make mistakes. I'm pretty sure there are a lot of software be it open or closed source that had absolutely terrible security bugs. Judging open source as a whole by looking at a single project sounds a little bit like overgeneralization. Also, they are obviously in need of help though, I hear a lot of complaints from people about the OpenSSL code.
Deleted comment
How does this follow? You can just as easily hire "random people" to make mistakes as you can accept mistakes from people you don't pay. The problem is poorly reviewed code either way. Not the license.
Deleted comment
If you know `crashme` you already know one fuzzer, which "intended to test the robustness of Unix and Unix-like operating systems by executing random machine instructions." See https://en.wikipedia.org/wiki/Fuzz_testing
As a good app-sec'er you seem to need to be deeply steeped in fuzzer lore. Matasano: "We'll have you write a fuzzer. Everyone here writes fuzzers." http://www.matasano.com/careers/
(I'm obviously not replying to tptacek, just highlighting a bit. ... And basking in the good glow, yes.)
It's much easier to come up with workable exploits in decent time with symbolic input and the stp or z3 solver than with simple fuzzing.
"As a result, the open source model builds higher-quality, more secure, more easily integrated software. And it does it at a vastly accelerated pace, often at a lower cost." - http://www.redhat.com/about/whoisredhat/opensource.html for example.
As an ideology, comparing this OpenSSL happening to the stated goals of strong proponents open source, it is a complete failure of that ideology.
That it was then fixable is an advantage, but that's a separate thing. It doesn't offset the way a really common error in a change to a really common and important library sat unnoticed for two years ... until a private company paid security researcher found it.
You could argue that the bug was found and fixed and the software is now more secure :: the system works, this is how it works.
But this is not how open source proponents present it as working.
NB. This doesn't mean closed source is better. People don't push closed source as an ideology in the same way at all. But do compare open source to the claims made by open source advocates, as well as comparing it to the ease of fixing and finding bugs in closed source software.
Open Source advocates -- such as Eric S. Raymond -- believe that it is superior on technical grounds, the "many eyes make all bugs shallow" theory. They tend to disregard ideology and instead believe OS is the rational decision of those who want technically better software. In my opinion this is not always true, as Heartbleed shows (but then again who knows how many undisclosed vulnerabilities are there in existing proprietary software! At least now we know about Heartbleed!)
Free Software advocates -- such as Richard Stallman and the FSF -- believe it's a matter of ideology. This has little to do with technical quality. They say "sure, if the software is better that's a plus, but freedom is a matter of principle to us".
I'm not a zealot but I tend to side with the Free Software camp, and I don't see how the OpenSSL fiasco undermines their ideology.
PS: I also take issue with the "paid security researcher" remark. Absolutely nothing in either Free or Open Source excludes paid personnel or private companies from the equation. Hobbyist programmers are not the only ones accepted. I don't understand why you see this as extraordinary.
I never meant to imply paid researchers should not work on it. What I meant is:
The whole world can see every line of code in Linux. This is one of the reasons Linux is more secure than other operating systems and why open-source software overall is a safer than closed software. The transparency of the code ensures it’s secure. - Linux Foundation executive director Jim Zemlin
http://venturebeat.com/2013/11/26/linux-chief-open-source-is...
What happened in the case of Heartbleed? The security flaw was found by paying someone to work on the security.
I meant to mock this: The transparency of the code ensures it’s secure., mocking it by noting that nobody cared to look for or fix that bug because OpenSSL was important, because it was widely used, because it was interesting, because it was open source, because it was a puzzle, just for something to do one rainy day. Only when someone was paid to do it did it get done. Therefore the "open source is more secure" claim is a nonsense.
It's more secure because someone was paid to work on it. The claim that "open source did it" is snake oil.
I agree that thinking "open source magically makes software better and more secure" is absurd. I also agree that Jim Zemlin's statements (in general, in that article) are more of a PR thing than accurate statements.
They tend to disregard ideology and instead believe OS is the rational decision of those who want technically better software.
If ESR is writing software in the way he thinks results in better software ... how come I know who he is? Because he's not doing that, he's doing more than that.
I don't know if he prefers working in the mornings or evenings. I don't know how he backs up his work. I don't know whether he prefers a laptop screen or an external display or who he trusts to contribute to it - presumably he made rational decisions there for the benefit of his software, and didn't feel the need to tell the world all about it.
Yet when it comes to open source, he does more than "choose the best option for his software and use it", he also: spreads the word, advocates for it, tries to convince others. Wikipedia says "Raymond was for a number of years frequently quoted as an unofficial spokesman for the open source movement."
By contrast, there is no comparable "closed source movement" which organizes conferences and runs websites and talks to journalists and advocates in favour of closed-source development because it makes software better. There's no popular closed-source unofficial spokesperson I can point to whom you recognise.
I argue that people pushing "open source produces better code" are making that an ideology of its own, separate from anything to do with Stallman and 'free as in speech'.
And it's that ideology of 'Open Source leads to technically better software' which Heartbleed is showing up as weak and oversold. You agree that it's "not always true". My point is that Open Source proponents make it seem like should be "always true", like there's a very strong case for it. And I say that Heartbleed shows there isn't.
'Everyone' knows about bounds checking in C. Everyone knows about not trusting input from a remote machine without verifying it. Everyone knows about being extra tip-toe careful around cryptography software because it's high importance and brittle. What did OpenSSL do about it? Nothing.
Almost as if Open Source made no difference at all, and what matters about developing trustworthy software is people, welcoming communities, a thousand cultural decisions setting and holding patterns of procedures to systematically catch common errors in C, common errors in network code, common errors in security, common errors in memory managment, add regression tests, encourage documentation, add compliance tests, etc. etc.
Open source does not automatically lead to better software.
And many people strongly imply that it does, automagically, lead to better software.
(The fact that OpenSSL still became popular and widely used despite being a mess is if anything a win for 'free as in speech' - anyone can do any due diligence they want on the OpenSSL code, make their decision to use it for any project, fork and patch and modify it as they go. On that front it's a massive win for that ideology).
Now that you've clarified you weren't talking about RMS's "free as in speech" ideology, I retract my nitpick.
I wouldn't say open source doesn't matter in regard to quality and security, though, but I agree with you on the importance of the other factors you mention. I do wonder what would have happened with a similar bug/exploit in a piece of commercial software. Who knows? Maybe it's already there and we simply don't know about it, and there are fewer people looking at it.
But yes, I also wonder about the balance of bugs in similar open/closed source software.
It doesn't excuse a misunderstanding of his subject matter, but an accusation of bias is likely an over-analysis.
You might have seen the story about how it gets $2000 in donations a year, which is supposed to be enough to marshal the expertise to prevent this kind of thing.
In case you haven't made the time yet -- ACLU's interview of Snowden at SXSW was excellent and dives into the implications of this: https://www.youtube.com/watch?v=UIhS9aB-qgU
On another (ironic) note this PSA from the US government is about 2 years late: http://www.bbc.com/news/technology-26985818
Though I must say I find it funny all the different names/what exactly it is I've seen.
No, they emphatically do not, at least until you explain that to them. And even then, it was "well, I don't really do anything important online anyway..."
"Why would anybody do that?" For the lulz ("random acts of malice"), sadly.
I hope it's now clear to everyone what NSA's vision about "cybersecurity" is. They think having vulnerabilities like this in the Internet's infrastructure is a good thing, because then they get to attack their "targets", to "protect us". It has nothing to do with actual security. Weakness is strength. Vulnerability is security.
Yes, and quite easily.
If that's your only testing criteria for whether a government agency is useful then NSA will pass with flying colors.
Anyway lets skip the banal "intelligence agencies failures are public and the successes are private" and get to actual examples:
DES SBoxes
SELinux
NSA Academic Centers of Excellence
VENONA
I assume what you really mean is whether their dragnet surveillance in particular is ever beneficial to US citizens, and that certainly seems to be a "no".
Their job is to keep us safe.
Letting us all run around with humungous holes in our security for years was a risk to our national security. How do you think the Chinese were able to clone our weapons systems so well? Shit like this.
NSA is a spy agency, expecting them not to use vulnerabilities they find is like sending them into a gunfight with a pocketful of rocks. Ask the Palestinians how that works out in the long run.
I think much of the NSA's surveillance is unconstitutional and should be rolled back by at least 2 orders of magnitude. That doesn't have to entail turning the world over to Russian and Chinese hackers.
That's exactly what they do when they allow bugs like this to continue to exist, rather than working to fix holes, not exploit them.
Boogey man FUD, I'm not worried about any hackers from [Insert_forgein_country_elites_want_you_to_hate]. The USgov, NSA and corrupt law enforcement are the only terrorists I'm worried about.
Why? Nations have track records of not killing/spying on each others?
It's reasonably to be suspicious of government.
Why do we let awful people like this be in charge of our well being? Is power too entrenched that no matter what happens, we can't do anything about it?
Spying on the country and spying on behalf of the country are not really the same thing.
Who gets to decide whether the risk is acceptable? To whom do we turn to when it's found that their risk assessment was flawed, and we require compensation for their recklessness and negligence?
The only way to get a different result is to re-allocate resources away from NSA and build an agency from the ground up that is geared toward securing systems.
(emphasis mine)
It's pretty weak IMHO but I don't really doubt it.
I would be surprised if every single commit to OpenSSL doesn't get dozens to hundreds of man-hours of attention from people very good at breaking secure systems.
With that in mind, you can also be sure that the NSA isn't the only government agency that is putting tons of money into exploiting OpenSSL and other critical software. I'd be surprised if it took them more than 1-3 months to find this exploit after it was introduced. If they found it in that time, you would expect that other government agencies found it nearly as quickly and have been exploiting it as well.
When you have million and billion dollar budgets used to find and exploit bugs in software, you can be certain that the average person is losing out big time.
The sources could be lying for many reasons. As a prank, to discredit Bloomberg when they report on other NSA stories, because they're embarrassed the NSA didn't know earlier, etc. But Bloomberg knows this and presumably required some evidence to satisfy themselves before reporting. So the deciding factor is really Bloomberg's reliability.
As soon as I thought about Heartbleed and the NSA (well before this story), I figured there was about a 99% chance that the NSA had found it and had been actively exploiting it for a decent portion of the time it was in the wild.
Stacked against that, Bloomberg's reliability doesn't really matter at all. If the sources are good, great! If the story is crap, it's still probably right by accident.
Deleted comment
I'd love to have harder evidence of what the NSA has been up to. I get that. But here are some things we know: the NSA believes its mission is to collect 100% of the world's data, with the possible exception of data that definitely belongs to US citizens. The NSA has boasted internally of cracking SSL implementations as part of its work. The NSA employs more people who are qualified for and tasked with finding this kind of exploit than anyone else. The NSA's leadership is willing to lie under oath to Congress -- let alone to anyone else -- about its activities. The NSA's secrets are about as heavily defended as secrets can be -- actually providing the kind of evidence requested here is widely considered treason against the United States. And now an investigative reporter with a serious reputation says that he has two sources who can confirm that the NSA knew about heartbleed shortly after it was created.
So let's assume you might behave differently in some way -- in any way -- if the NSA knew about and exploited heartbleed. You have imperfect information and you have to make a call. What else could you "need" before you decide to behave as though this article is accurate?
I think we "need" to assume that the NSA took advantage of heartbleed starting shortly after it was introduced. We'd just "like" to have a little more confirmation about what the hell they've been up to.
It should be clear by now that the NSA does not restrict themselves from anything... and should be disbanded.
NSA knows approximately 1 zillion vulnerabilities we don't know about and won't know about. They range from RCE's in Windows and Apache to flaws in cryptographic hash functions.
It's NSA's charter to stockpile these things, and, yeah, to use them against foreign adversaries.
It's bad though, because this one was so easily exploitable. It's the kind of thing a reasonable organization finds out about and wants fixed ASAP.
I don't see how leaving American companies vulnerable fulfills the NSA's charter.
I agree that this bug is different, but that might have been a subtle case to make inside the organization.
If I were any US-based company CEO whose customers got hacked by Heartbleed exploits, I'd drag their corpses to the court if necessary.
Sidenote: People have asked "Why are you doing JS-based cryptography on passwords if you have HTTPS?" - here we have the ideal answer. Encrypting the passwords using public-key crypto in addition to HTTPS and doing the decryption in RoR/PHP/nodejs would at least have spared the users from the need to change their passwords.
The NSA's primary function is performing signals intelligence. To perform that function, they've spent the past ~60 years building up cryptanalytic capability (pretty much unmatched by any other single organization either governmental or private).
Because of this, they have a secondary function, which is to serve as subject-matter-experts for other government agencies. They provide advice, mainly in the form of influencing NIST standards (overtly by providing recommendations, and as we've come to learn, covertly by fucking with standards). This is a side-effect of their primary function however.
Asimov's first law of the NSA is to intercept and process signals intelligence. Any other function is secondary, and certainly will not take precedence over their first function.
What the Snowden revelations have shown, is that there's a conflict of interest between their primary function and being tasked with providing advice. I think it's a reasonable argument to be had that they probably should get out of the business of providing guidance to other agencies, as now all that advice is tainted.
The security of "US-based companies" is so far down the list of priorities that I hesitate to suggest it exists at all. Reporting vulnerabilities to vendors is at best orthogonal to their primary function, and at worst, counter to it. If you want to argue that someone in the government should be responsible for helping companies fix security issues, that's also a good argument. But it certainly shouldn't be the NSA (and definitely not now that we know they have no compulsion about misleading everyone).
I'm going to ignore your side-note about JS browser-based crypto. Unlike the people on here who diligently try to explain the fundamental issues with doing JS-crypto, I'm now of the opinion that you can't reason with these people.
That changes the risks/rewards of early-patching quite a bit. They can be confident it's their own trump card for quite a while, and learn about (or strategically mislead) any teams that arrive later to the same knowledge. When it's really "burnt", and in use by the NSA's enemies, then they can help US companies patch... and possibly even assure them exactly how much damage (if any) occurred.
(In the extreme, with say a big friend-of-NSA telecom or defense contractor, that could even be: "Hi, American BigCo. In the 48 hours between the beginning of enemy exploitation and your patching, we saw about 13,000 suspicious heartbeats directed at your servers. If you don't have raw traffic logs to do your own audit of exactly what server memory was lost, we can share our copy with you. It's a pleasure doing business with you.")
In fact, perhaps the reason for the synchronized reveal from US and non-US discoverers just now is that the first non-NSA probing (by either malicious actors or researchers) was just recently detected, starting the race to patch.
"Here's the license plate number and home address of the guy who just ran over your grandma. Sorry for your loss."
And if the time window of exploitation is kept small, the exact same magnitude of data loss could have happened in a rapid-disclosure and patch scenario. (Two years ago, were practices for rapid response better or worse than now? Would the time window of public-knowledge-but-incomplete-protection have been any smaller - or maybe larger?)
So why not let it break later (and maybe never), rather than earlier? It's like any kind of "technical debt" analysis... oftentimes it makes sense to defer fixes, because by the time the issue becomes critical, it may have already been rendered moot, by larger changes.
This whole things just sucks.
And all the time, the NSA had the capability and knowledge to prevent this damage. What a great service they did to their country, indeed.
That's not really true. The NSA has incredible resources that other bad guys do not.
I think a critical step on this logic chain is "once we find all the bugs, we will be safe." Given that step, you would obviously want the NSA to tell the vendors about every single bug they find.
But it's really not the case that we will ever "find all the bugs." Even if the vast resources required were needed to be spent to find all the bugs in version 3.1415, there would be new bugs in 3.1416.
I can kinda-sorta buy the full-disclosure argument that "if an independent researcher can find X then so can the bad guys." That argument doesn't apply to the NSA. They have a much better reason to believe "we found this exploit, and it will take a long time for someone else to find it out."
I would not be surprised at all if Israel and China didn't also know about Heartbleed.
What people are shocked about is that they didn't understand what the law permitted, or how quickly mixing the law of induction with datacenters full of computers can led to global-level surveillance.
With all that said, I would mind if it's true NSA knew of this bug and left it alone. It's a powerful weapon for SIGINT to be sure, but it's too easy to find by other state spy agencies doing code review; NSA would have had to assume other nations knew about it at well and were putting US government and private-sector comms at risk.
An attorney general collects the business records of thousands of people they know are innocent of wrongdoing in the course of routine investigations into fraud by large businesses.
Both of those are still considered "due process" because in both cases they are following a set process. Due process doesn't mean the government won't look at you if you're innocent, which seems to be a big misconception. It essentially means that the government should handle cases with similar particulars in similar ways.
So in the case of the NSA, if that collection happened under the same type of legal authority, after going through the same FISC review (if needed), was held to the same standards of reasonable and articulable suspicion (or whatever standards were required to be met for §215) then the collection that would happen from there would have been given due process.
As for your link, while its accusations are damning enough, they don't appear to support your first point or your last one. It's hard to argue DoJ is "ignoring" the law when the EFF themselves make quite clear that "The language of Section 215 allows for secret court orders to collect 'tangible things' that could be relevant to a government investigation – a far lower threshold and more expansive reach than a warrant based on probable cause. The list of possible 'tangible things' the government can obtain is seemingly limitless, and could include everything from driver’s license records to Internet browsing patterns."
So don't take my word for it, take EFF's.
As much as Snowden has shown us the amount of effort NSA puts into this kind of stuff, I think we need more evidence than this article is giving.
Deleted comment
http://blog.cloudflare.com/answering-the-critical-question-c...
I wish newspaper articles had a bit of metadata that indicated whether the sources are verifiable. Then we wouldn't have to waste any time reading them when they aren't.
The NSA needs to be dissolved. It is a costly liability whose actions work against the nations interests as a whole.
> Statement: NSA was not aware of the recently identified Heartbleed vulnerability until it was made public.
The NSA has a good history recently of lying through their teeth, and the bit at the end "Unless there is a clear national security or law enforcement need..." is a pretty damned large asterisk.
because if not this is just straight up link bait.
It's wiggle-room a mile wide, but I'm not sure if there's a better alternative given the current climate.
If they are given carte blanche to use the exploit indefinitely, they will keep it forever and let the world discover and exploit it as well. If they have a finite time period like 1-3 months, they will prioritize exploiting those systems that are actually valuable for national security. While they are doing so, they should keep an auditable log of all the systems they use the exploit against so that oversight may be performed in hindsight. Furthermore, they should absolutely be barred from using any exploit against a target with a US-based IP, or possibly even any IP address in allied nations.
It is far less likely that the agency will have the opportunity to abuse exploits if they are forced to prioritize targets due to a fixed deadline on disclosure.
During the deadline period, they should also be working on a plan that minimizes the amount of damages once disclosure is forced. i.e. there should be a list of people and companies that get the information first and everyone on the list should be people in charge of protecting computer systems (i.e. no one involved in offensive activities is on the list). Companies like Google, Facebook, Akamai, Apple and the package maintainers for all the major *nix distros should be on that shortlist of those that get priority notification.
Presumably if the anonymous sources here were discovered, they'd be in big criminal trouble, right? I am curious how far the government goes to try and discover them.
And I think there is no way these anonymous sources would have contacted the journalists without Snowden going first, to establish the context and interest. Snowden's actions continue to benefit us all, cascading.
You may think it's awful that the NSA knew for 2 years, and didn't push fixes... but their funders and overseers, in Congress and the DoD, would be more likely angry if, given the NSA's massive budget and mission, the NSA didn't know about this bug right away via code audit/analysis. Knowing vulnerabilities first is the whole job of the "Cyber Command".
And, the best defense isn't necessarily a panicked fire-drill of preemptive patching ASAP, if you're sure you're the only ones who know. It could make tactical and economic sense to simply prepare contingency plans, and wait for the first evidence of a 2nd-discoverer.
If they truly didn't know about this, you'd expect that a lot of the US government infrastructure has also been vulnerable this entire time.
I've seen the Alexa top 1000 list showing who was vulnerable. I wonder if there is a similar list for the top 1000 computer systems and networks over which the NSA has security oversight.
1. Gain signals intelligence on specified foreign targets. 2. Protect U.S. signals from having the same done to the U.S. by other states.
The second responsibility is why there are things like SELinux, NSA "Suite B" cryptography, etc. It has also led to security bugfixes to open source code (such as X.org) used by NSA or within government.
The reason that both duties are held in NSA is because the best way to defend against the best SIGINT hackers in the world is to have the expertise of the best SIGINT hackers in the world. It's why NFL teams have their offense practice against their own defense and vice versa.
In this case the flaw is so completely egregious (and relatively easy to spot for other states' spy agencies reviewing commit diffs) that the duty of NSA would quite clearly to have been to get OpenSSL fixed, if only because so much government IT could be affected by this.
The bug was introduced pre-Snowden as well, so it's not like NSA didn't have other cyber weapons to use to achieve the effects they need. So if it's true that NSA knew about the bug and let it remain open to protect "methods and sources" then they definitely chose wrong and someone needs to explain how they came to that choice...
So, what's to keep some organization that runs a package repo from publishing OpenSSL packages that claim to be like OpenSSL 1.0.1g but actually display the heartbleed bug? I also ask myself, would the NSA seek to implement such a thing? They would, though that is an entirely different question from if they have.
(Or just use Debian in the Gentoo flavour from the beginning)
1) that part might be a little rhetorical, every AG likes good publicity.
That being said, it would be a pretty standard tactic for an AG to look at who paid the people who did the work. It is a pattern in a lot of different types of investigations and familiar to an AG. Will they find anything? Doubtful. Will that really matter? Doubtful.
I should at this point say that I am thinking of a scenario that would occur to an AG (the pattern happens a lot). I am not advocating such behavior. It would have a huge chilling effect on public source code of any type and probably generate some seriously evil legislation (certifications or liability insurance). These concerns have never been part of most politicians concerns.
I am at the same time comfortable filing this under "things that will never happen".
I never said anything about damages.
Deleted comment
> “I knew hackers who could break it nearly 15 years ago,” Lewis said of the SSL protocol.
Anyone know wtf he's talking about?
http://en.wikipedia.org/wiki/Transport_Layer_Security#Attack...
Plus, since the whole thing is based on CAs, if you can get an intermediate cert (and does anything think the NSA can't?) and you have the means to MITM someone, that's as good as breaking it, too.
15 years ago, we were using keys with much lower entropy, as well, which may have simply been outpaced by computing power.
http://www.nbcnews.com/tech/security/nsa-denies-it-used-hear...
Sorry? Paid programmers writing closed code with probably less review and auditing have been shown to create less bugs? What are they trying to say?
Everything I've seen NSA do is largely based on the same techniques Google uses, except 10 years later, much more expensively, and with much uglier PowerPoint presentations. The only thing NSA has that private organizations don't is the compelled cooperation of telecom companies.
While we do not want to make this into a witch hunt, now that the NSA is involved in Heartbleed, we should definitely rule out malice by checking for direct ties between contributors of known flawed/malicious code related to the implementation of Heartbeat.
The only reasonable course of action is to apply oversight of the NSA. If people in open-source are moles, the only reasonable way to discover this is via oversight of the agency. If there are moles, there are records within the agency showing this to be the case. Getting ahold of those records is how you prove this and you get those records by getting congress to do their job and provide oversight.
Interesting that they say "at least" two years. The bug is two years old, so they could have also chosen to say "at most" two years or "up to" two years. Least biased would be to just say "since the bug was introduced, two years ago".
I wonder if Bruce "probability is close to one that every target has had its private keys extracted by multiple intelligence agencies" Schneier is one of them.
Also, worth mentioning: it's not particularly easy to get private keys out of servers with the bug.
Is it unlikely for FBI to ask NSA's help?
Notably, the FISA cell phone record orders passed information to the NSA through the FBI, so no hint of a "chinese wall" there. Secret bulk collection for 'national security', everyone bathing in the same pool of data.
I do suspect it's policy not to casually request, or become overly dependent on, such NSA-to-domestic sharing. And – as we've seen in the "parallel construction" revelations you allude to – it's definitely policy to try to obscure any such sharing when it happens.
But to reassure people that it's "probably illegal" is flimsy hand-waving when you can't name the law, and there's public evidence that it happens to the contrary.
Deleted comment
"two people familiar with the matter said." <- so you made it up
"threatens to renew the rancorous debate over the role of the government’s top computer experts." <- you made this up as well
"Heartbleed appears to be one of the biggest glitches in the Internet’s history" <- Not even close.
"as many as two-thirds of the world’s websites" <- less than 17% of SSL based webservers, certainly not two-thirds of the entire freakin internet.
"it’s possible that cybercriminals missed the potential in the same way security professionals did, suggested Tal Klein, vice president of marketing at Adallom"
"this article is shite, suggested ikt, junior vice president of Compuglobalhypermeganet"
The article is rubbish.