On Fri, Apr 11, 2014 at 03:52:57PM -0400, Nico Kadel-Garcia wrote: > On Fri, Apr 11, 2014 at 6:08 AM, Hannes Erven <han...@erven.at> wrote: > > This is not entirely correct: any web server process with openssl-based SSL > > enabled was vulnerable. So even if the repository itself wasn't > > served on HTTPS, but some other vhost was, you're still affected. > > Do you have a pointer to that?
http://xkcd.com/1354/