I tried to comment on the blog with something about a time stamp is all you need for the general case (and maybe some urls giving more information about the situation).
Patched: 0 and Vuln: 1 isn't really useful information for the user; if sensitive data is involved the site should take itself offline, not warn users. A time stamp indicating when a mess was resolved is all a user who cares needs to decide to create a new password.
Comments
In theory, one could expand this standard to allow for arbitrary mass-hack information.
Yeah, I added an update to the bottom of the posting mentioning the possibility of generalizing it.
I tried to comment on the blog with something about a time stamp is all you need for the general case (and maybe some urls giving more information about the situation).
Patched: 0 and Vuln: 1 isn't really useful information for the user; if sensitive data is involved the site should take itself offline, not warn users. A time stamp indicating when a mess was resolved is all a user who cares needs to decide to create a new password.
I could live with simplifying the proposal to just list CVE numbers and timestamps.