Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I would rather say...

If you're not using SSL right now, there's no rush to upgrade, but do it anyway while this is in the forefront because when you do use SSL one day on your server, you might forget that you had this old version of OpenSSL.



And there may be other things besides web servers using OpenSSL that you didn't think of or aren't aware of.

For example, I believe that using curl to fetch an https URL leaves you open to this vulnerability if you connect to a malicious server. The odds of the server being bad and the odds of curl containing anything of value are low, but it still counts for something.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: