It's obviously going to be a lot easier to convince maintainers of web sites with wildly varying stacks to drop a plain-text file into the root directory of their site, then it is going to be to convince them to implement a universal password change API.
If Mozilla, Microsoft, and Google added support for /heartbleed.txt to their browsers then a whole lot of people would check it. Even if not, if password managers are modified to check it, and this leads to even a minor increase in the penetration of the user of password managers by users of the internet, that would be a good thing.
Comments
It's obviously going to be a lot easier to convince maintainers of web sites with wildly varying stacks to drop a plain-text file into the root directory of their site, then it is going to be to convince them to implement a universal password change API.
If Mozilla, Microsoft, and Google added support for /heartbleed.txt to their browsers then a whole lot of people would check it. Even if not, if password managers are modified to check it, and this leads to even a minor increase in the penetration of the user of password managers by users of the internet, that would be a good thing.