Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The problem is that just "getting a fix out there" isn't enough. People have to deploy that fix for it to mean anything. And the way you get people to deploy a fix is to make them aware that they need to.

Given how widely deployed OpenSSL is, and how many of those systems are run by part-time or amateur sysadmins who aren't going to be monitoring CVE lists constantly, getting the word out that (1) there's a huge problem and (2) here's how you fix it is of paramount importance.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: