3 ms·
Until there is final proof and production of sufficient evidence, this post is as valid as the claims that information was extracted. Whilst I completely agree
by herghost 13y ago
Until there is final proof and production of sufficient evidence, this post is as valid as the claims that information was extracted.
Whilst I completely agree that if taken as a reason not to update this is unhelpful, the OP isn't enumerating reasons to not update, he's providing early assessment and commentary.
As an industry we've once again not done ourselves any favours with the way this has been handled in the media - it started out as the apocalypse of SSL and all we hold dear, and whilst the update exercise was valid, it appears that the percentage of affected systems was actually quite low and the extent of the apocalypse might well have been overstated.
That's not to say there isn't a problem here, by any means - I've spent all day scanning servers and quietly weeping as I watched usernames and passwords dance around my screen - but getting to the analysis of what actually happened should have started before the headlines ran away with themselves.