Why would you be worried, they'll post as you? There's probably three dozen accounts I have that I'd worry about before I'd worry about TIF. And I'll be waiting another month or so before I start doing anything about it. XKCD does a good job explaining what heartbleed is, and why you should care about it. http://xkcd.com/1354/ The data accessed is only in the heap - your accounts specifically are only at risk if you were logging in while someone was abusing the bug. More troubling (and why it might not matter if you change your account information right now) is that someone abusing heartbleed could have access to the server's private key. Basically, if they were able to get the private key, any and all communications to the server could be monitored and decrypted. It's until services effected with heartbleed patch OpenSSL and generate new keypairs that they'll be "safe." So your best bet is to change account passwords now, a month from now, and again in the future. Also fundamentals for account safety are a must - a longer password is better, and do not reuse passwords (especially now).