There have been concerns that the NSA may have been aware of the Heartbleed SSL exploit for years before it was publicized. If this is true, then it would mean that the NSA knowingly allowed many American consumers and business to conduct transactions in an unsafe manner and stayed quiet about it. Putting aside the other controversy around NSA activities, If the S in the NSA stands for security instead of surveillance then when the NSA discovers an exploit with this potential to damage the American economy it is their responsibility to first help secure American's from financial harm. The use of exploits for surveillance should come second. The NSA should not be responsible for testing software but knowing inaction during a threat to american livelihoods should not be tolerated.



