> SSLv2 is, in itself, harmless since no random user using their browser will ever use it.
Erh... No.
That was actually the main result of the DROWN paper and eventually the reason why everyone was disabling backwards compatibility with SSLv2: https://drownattack.com/
The mere fact that you are supporting SSLv2 means that an attacker can abuse this to do key operations with your private key.