Is that really bigger? Heartbleed meant that I, sitting comfortably in my home, could hit up yahoo.com and grab your credentials without being anywhere near your computer, or any of the data your computer sends or receives.
Password in the URL with unencrypted HTTP is colossally dumb, but at least I have to either access your computer or at least snoop on its connection to take advantage of it.
My point is that there have probably been hundreds of these types of events going back to the ancient times of the internet. The sky is not falling guys, just a good downpour.
My point is that heartbleed is unique in its combination of severity and scope. Something like 25% of all the web servers on the internet could have their most private data extracted for a period of two years. The sky isn't falling, but I can't think of anything else that comes close. Vulnerabilities that affect individual sites, while still really bad, still don't approach this.
Comments
Is that really bigger? Heartbleed meant that I, sitting comfortably in my home, could hit up yahoo.com and grab your credentials without being anywhere near your computer, or any of the data your computer sends or receives.
Password in the URL with unencrypted HTTP is colossally dumb, but at least I have to either access your computer or at least snoop on its connection to take advantage of it.
My point is that there have probably been hundreds of these types of events going back to the ancient times of the internet. The sky is not falling guys, just a good downpour.
My point is that heartbleed is unique in its combination of severity and scope. Something like 25% of all the web servers on the internet could have their most private data extracted for a period of two years. The sky isn't falling, but I can't think of anything else that comes close. Vulnerabilities that affect individual sites, while still really bad, still don't approach this.