Worst case scenario they are looking into streams of suspicious behavior, like Russian IPs attempting to validate the SINs somewhere else, like at a bank.
"It is irrelevant whether your system can even support some of the cipher suites in the list, because the Heartbeat request that triggers the vulnerability is sent before any encryption takes place."
http://www.hut3.net/blog/cns---networks-security/2014/04/14/...
I was specifically wondering if a) the heartbeat messages which leak data (keys or whatever) are encrypted or not, and b) if they are, and PFS was used, is it even possible for someone to audit a full packet capture for heartbeat attacks.
So I called them up, waited on hold for 5 minutes. I spoke with a CRA rep who said "Yup, we screwed up. Fixed". And it was fixed. Total time to fix an $11K screw up? 15 minutes. Try that with any other organization.
Every single interaction with them and every single person I know that has to deal with them has been nothing but mindblowingly professional. Even on the phone, they are exceptionally good at getting to the point IMMEDIATELY but without the normal "this isn't the right department" BS that every other Canadian government agency has.
It's hard to even think of a number two. The Supreme Court maybe? Elections Canada? Ellis Don?
Anyway, I call, and it was the closest thing to magic I've ever seen. I give reception my SIN, and ask for the woman that signed the letter I received. I'm on hold for only 10 or 20 seconds, the woman answers, and greets me with my name. I didn't say more than a couple of sentences explaining the issue, and she says she'll check her computer, taps a button and poof she knows everything. Literally a few more seconds, and everything is sorted, and a cheque is being mailed.
I was almost speechless, I was expecting a 30 minute call between departments, explaining numbers, CRA scratching their heads since this was taking place across multiple provinces, and then me having to physically mail in a variety of personal information. Instead, it was a 1 or 2 minute call with an incredibly friendly woman, and she was so organized, it's like she spent the day preparing for me to call in advance. And, to reiterate, this was the woman that signed the original letter I received, not someone from support or customer service.
Now, the CRA website is a nightmare, but talking to them on the phone was the most impressive service I've ever encountered.
Even at a previous job back in the late 90's we were doing full pcap of our gov't department's T1 to the internet.
Products from companies like Netscout and VSS make this pretty straightforward.
I imagine a government agency, particularly dealing with revenue, might be a primary user of such a tool, though.
For instance, one guy looked up the information attached to his SIN. Something like an hour later RCMP showed up, and escorted the fellow out of the building.
And you don't really expect them to blindly patch things right away do you?
Maybe the Canadian government should walk down to the CSEC offices and ask them hey can you guys stop conspiring with the rest of the 5 Eyes Alliance to sabotage IETF standards