Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Red Hat Enterprise Linux Server release 5.6 is still supported and ships with OpenSSL 0.9.8e which is not vulnerable. I am sure there are other examples as well. If I had a StartSSL certificate and the browsers started to remove support of them or warn that my site has a StartSSL certificate signed before a certain date and cant be trusted I would be really pissed.

I have always felt there was conflict between system administrators wanting proven and stable versus developers wanting bleeding edge. I have given up the fight when it comes to web development and use Ubuntu 12.04LTS which still is not bleeding edge enough for most of my dev's. For infrastructure components outside of web development though I dont think its a safe assumption that people are on a vulnerable version.

This is a prime example of why I would never give anything away free. Unrelated to SSL certificates; I rather throw out my old equipment than give it away since the people I give it too will never be happy and don't understand its free for a reason and demand support. The fact that you cant afford something better does not give you rights to it.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: