Skip to content

Comment on We need a “/heartbleed.txt” standard, and we need it ASAP

Comments

Biggest ever hole? Really? Am I the only one that remembers Yahoo placing passwords in the URL of unencrypted pages? I remember having to erase the URL line when people were around for fear of leaking my password.

jikOP

I hardly think that a security hole, no matter how large, at a single web site, is on the same magnitude as one security hole that probably impacts the majority of web sites on the internet and could have been taken advantage of completely invisibly for years.

This is a silly, unnecessary standard that will probably not be implemented by anyone.

Saying we need it and we need it now is simply ridiculous.

Interestingly enough, MtGox did this as well in the very early (pre-alpha) days of its role as a Bitcoin exchange.

Its developers were summarily bashed for this practice when seeking feedback (and rightly so).

...WHAT?! Did they use <form method="get"> for their login forms?

Relax. They have now switched to "post", and everything is just fine.

Is that really bigger? Heartbleed meant that I, sitting comfortably in my home, could hit up yahoo.com and grab your credentials without being anywhere near your computer, or any of the data your computer sends or receives.

Password in the URL with unencrypted HTTP is colossally dumb, but at least I have to either access your computer or at least snoop on its connection to take advantage of it.

My point is that there have probably been hundreds of these types of events going back to the ancient times of the internet. The sky is not falling guys, just a good downpour.

My point is that heartbleed is unique in its combination of severity and scope. Something like 25% of all the web servers on the internet could have their most private data extracted for a period of two years. The sky isn't falling, but I can't think of anything else that comes close. Vulnerabilities that affect individual sites, while still really bad, still don't approach this.

Isn't Yahoo one (of the many) sites affected by heartbleed?

Yes, and they were particularly slow in patching it too. Took them over a day.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.