Revocation still doesn't work(imperialviolet.org) |
Revocation still doesn't work(imperialviolet.org) |
This and lack of PFS are much bigger catastrophes than the OpenSSL debacle in itself.
(PFS: supported by TLS but disabled by almost everyone so all your old traffic is decryptable with heartbled cert).