TicketBleed (CVE-2016-9244) (F5 BIG-IP)
ticketbleed.com
ticketbleed.com
And sites smaller than that top 1M are even less likely to be using it.
I don't find that a very large impact personally. F5 knows who their customers are and can easily contact them.
We don't need a big media panic blitz and dedicated domain name for this.
Fact of the matter is SSL accelerators just aren't all that popular now, SSL got cheaper with session resumption and newer ciphers, CPUs got fast and accelerated instructions for AES and all but a few people just use CDNs when their needs go beyond that.
http://www.bus.umich.edu/KresgePublic/Journals/Gartner/resea...
I wonder how many of these are/were TLS version or extension intolerant.
I think people are focusing too much on the name/branding because they don't have an interest on the troubleshooting that led to this discovery, which I found very interesting as I can totally relate to that sort of work.
It's 2017, man. Every little last thing can be bled dry for some sweet, sweet Internet attention. It seems to be one of the most valuable currencies of a new generation of people.
> It is similar in spirit and implications to the well known Heartbleed vulnerability. It is different in that it exposes 31 bytes at a time instead of 64k, requiring more rounds to carry out an attack, and in that it affects the proprietary F5 TLS stack, not OpenSSL.