back
2 comments
I wouldn't get too excited; it requires a MITM so abusing it at scale would be difficult.

Big targets should be wary, people's Hetzner servers and VMs are probably safe. They're not worth the effort to get a MITM on.

Interesting choice of example, two months ago an organization found their Hetzner server was MITMed https://news.ycombinator.com/item?id=37955264
The patch was just released two days ago.