Live data from Hacker News

We need a “/heartbleed.txt” standard, and we need it ASAP

blog.kamens.us

11–20 of 51 posts

Re: We need a “/heartbleed.txt” standard, and we need it ASAP

#11
post #7

Biggest ever hole? Really? Am I the only one that remembers Yahoo placing passwords in the URL of unencrypted pages? I remember having to erase the URL line when people were around for fear of leaking my password.

I hardly think that a security hole, no matter how large, at a single web site, is on the same magnitude as one security hole that probably impacts the majority of web sites on the internet and could have been taken advantage of completely invisibly for years.

This is a silly, unnecessary standard that will probably not be implemented by anyone.

Saying we need it and we need it now is simply ridiculous.

Re: We need a “/heartbleed.txt” standard, and we need it ASAP

#12

Biggest ever hole? Really? Am I the only one that remembers Yahoo placing passwords in the URL of unencrypted pages? I remember having to erase the URL line when people were around for fear of leaking my password.

...WHAT?! Did they use for their login forms?

Relax. They have now switched to "post", and everything is just fine.

Re: We need a “/heartbleed.txt” standard, and we need it ASAP

#14
post #9

Well, it didn't take HN/Reddit long to hug that site to death... Google's cache link doesn't seem to be working. Anyone else got a cache? Edit: Ah, no, this seems to work now: http://webcache.googleusercontent.com/search?q=cache:blog.ka...

Sorry. My blog doesn't usually get this much traffic. ;-) Trying to increase the number of servers but httpd isn't cooperating.

I use CloudFlare (https://www.cloudflare.com/) on my blog - handles even the largest load HN has thrown at it.

Worth setting it up - just in case :-)

Re: We need a “/heartbleed.txt” standard, and we need it ASAP

#15
post #8

In theory, one could expand this standard to allow for arbitrary mass-hack information.

Yeah, I added an update to the bottom of the posting mentioning the possibility of generalizing it.

I tried to comment on the blog with something about a time stamp is all you need for the general case (and maybe some urls giving more information about the situation).

Patched: 0 and Vuln: 1 isn't really useful information for the user; if sensitive data is involved the site should take itself offline, not warn users. A time stamp indicating when a mess was resolved is all a user who cares needs to decide to create a new password.

Re: We need a “/heartbleed.txt” standard, and we need it ASAP

#18

Biggest ever hole? Really? Am I the only one that remembers Yahoo placing passwords in the URL of unencrypted pages? I remember having to erase the URL line when people were around for fear of leaking my password.

Is that really bigger? Heartbleed meant that I, sitting comfortably in my home, could hit up yahoo.com and grab your credentials without being anywhere near your computer, or any of the data your computer sends or receives.

Password in the URL with unencrypted HTTP is colossally dumb, but at least I have to either access your computer or at least snoop on its connection to take advantage of it.

Re: We need a “/heartbleed.txt” standard, and we need it ASAP

#20

Biggest ever hole? Really? Am I the only one that remembers Yahoo placing passwords in the URL of unencrypted pages? I remember having to erase the URL line when people were around for fear of leaking my password.

Interestingly enough, MtGox did this as well in the very early (pre-alpha) days of its role as a Bitcoin exchange.

Its developers were summarily bashed for this practice when seeking feedback (and rightly so).

Post reply on HN