Skip to content

Comment on We need a “/heartbleed.txt” standard, and we need it ASAP

Comments

So sites ought to list their unpatched vulnerabilities? Erm?

jikOP

Well, yes, frankly, they should. ;-)

Frankly, it doesn't matter whether they do or not, because if a vulnerability is known and there are exploits for it in the wild, then hackers are simply going to try to exploit it, not check /heartbleed.txt.

Aside from all that, sites who don't have the courage to list their unpatched vulnerabilities can simply only list the ones that are already patched.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.