3 ms·
I wish that affected sites would simply reset my password themselves, internally, and then inform me when I visit the site that I need to use the 'Forgot Passwo
by senorprogrammer 12y ago
I wish that affected sites would simply reset my password themselves, internally, and then inform me when I visit the site that I need to use the 'Forgot Password' function to reset my password.
As it stands, they get to say they're patched while I remain vulnerable, and now it's my fault if my account is compromised if I don't get around to resetting my password (or they're a site I visited once, years ago, and forgot all about).
Simply updating OpenSSL without fixing passwords just shifts the onus to the users.
- bdcravens 12y agoThat's a tough call, especially for small companies. There are very real support expenses (not every app or it's users have SaaS-like support requirements) that don't make this an easy call.