10.04.2014 - 06:56 [ Techdirt ]

Shameful Security: StartCom Charges People To Revoke SSL Certs Vulnerable To Heartbleed

Yesterday, we wrote about just how terrible the Heartbleed bug in OpenSSL is. It‘s been generating plenty of discussion, with folks like Bruce Schneier calling it „catastrophic“ and saying that „on the scale of 1 to 10, this is an 11.“ It‘s a pretty big deal. So you‘d think that everyone would be scrambling to help plug the vulnerability as painlessly as possible. And most companies have been doing that. But one — StartCom — apparently sees this as an opportunity to rake in cash and to screw over those most vulnerable.