The "sslv3" USE flag has the following description, Support for the old/insecure SSLv3 protocol but it's enabled by default (+sslv3 in IUSE). It looks kind of bad to have an "insecure" flag enabled by default =) The hardened team are considering adding USE="-sslv2 -sslv3" to the hardened profile, but before they do, I'd like to ask if there's a good reason to leave it enabled in gnutls. If sslv3 can be turned off in gnutls and openssl by default, then we won't have to make the hardened profile diverge any further (and the other profiles will receive the desired benefits).
I thought of this many times, and decided to wait for a change in the entire tree. Sounds reasonable to do this now.