Damus
kasperd · 67w
I am curious about the disclosure timeline. I can see that SSL.com have disabled the buggy validation method, so exploitation should not be possible now. But was this bugzilla issue visible to the public before the CA had been notified about the issue?