Hacker News new | ask | show | jobs
by mygrant 4442 days ago
We had certs that were only used and present on machines that were not vulnerable, and therefore did not replace or revoke them. Please don't do this.
2 comments

Furthermore servers that weren't even using OpenSSL or the particular version(s) that were susceptible. What is the actual percentage of servers that needed to react to this?
I dunno... Probably worth it from a netsec point of view.