I tried to comment on the blog with something about a time stamp is all you need for the general case (and maybe some urls giving more information about the situation).
Patched: 0 and Vuln: 1 isn't really useful information for the user; if sensitive data is involved the site should take itself offline, not warn users. A time stamp indicating when a mess was resolved is all a user who cares needs to decide to create a new password.
Comments
I tried to comment on the blog with something about a time stamp is all you need for the general case (and maybe some urls giving more information about the situation).
Patched: 0 and Vuln: 1 isn't really useful information for the user; if sensitive data is involved the site should take itself offline, not warn users. A time stamp indicating when a mess was resolved is all a user who cares needs to decide to create a new password.
I could live with simplifying the proposal to just list CVE numbers and timestamps.