Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is a cross-vendor, cross-platform vulnerability that requires one to assume that almost any password used over https, any SSL session, or almost any SSL certificate used in the last year, hell, anything in server memory in the last year is compromised. I'm quite confident there are many systems that relied solely on SSL to gate immediate, root access, and some of those are still right now, as we speak, exploitable.

If that's not "burned down the internet" nothing possibly qualifies.



Same thing would apply to a vulnerability in Apache2 or nginx.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: