OpenSSL NULL pointer de-reference (CVE-2020-1971)
lists.freebsd.org
lists.freebsd.org
> Note: The OpenSSL project has published publicly available patches for versions included in FreeBSD 12.x. This vulnerability is also known to affect OpenSSL versions included in FreeBSD 11.4. However, the OpenSSL project is only giving patches for that version to premium support contract holders. The FreeBSD project does not have access to these patches and recommends…
Remember, people making billions and millions of dollars at Google and Mozilla tell you that your personal/hobby website MUST have HTTPS. But when it comes to actually doing the updates to OpenSSL, apparently, we're all supposed to have premium support contracts, for something that's not even technically necessary for a personal website in the first place -- advocacy and artificial limitations notwithstanding.
---
In my mind, this is just another confirmation that running HTTPS in non-commercial settings is a bad idea. Of course, I know that I'm in the minority in today's world, but I'm never running HTTPS on my personal site.