that's about as succinct an explanation as I've seen. is it bad that even though all these major sites are patching and now giving the green light for password change, I'm still feeling too lazy to do it right now?
this whole thing just bugs me with how unknown the true impact is. if the bug has been exploited, how will we be able to tell? the idea is that it's so low level that the process of stealing the info isn't even logged. so if my credit card gets compromised (which seems to happen every 18 months or so), was that because of Heartbleed or just regular good old skimming or database hack?
|