I just heard about this heartbleed bug yesterday. I've changed a couple of my passwords, but just how big a deal is this?
It's a very big deal, for a variety of reasons. Any time you can get a machine to involuntarily spit contents of memory back to you, you've found the keys to the kingdom. Well... almost
Making it even bigger of a deal is the fact that it's open source and as such, used all over the place. Some of the bigger providers use it.
Safe bet is to change your passwords for any site that uses OpenSSL. But don't bother changing until the site has been fixed. You can check by going here:
https://lastpass.com/heartbleed/
Punch in the URL and check the status. You'll want to change common passwords for sites that aren't infected if you used it on a site that is infected.
If you changed your password before the site was patched you effectively did nothing to safeguard against it.
I have to wonder if the folks publishing every detail of how our privacy can be breached in excruciating technical detail are helping or hurting us. It's basically putting up a billboard alerting anyone interested in malicious activity advertising 'how to' accomplish it.
That's one way of looking at it.
The other is that majority of people/companies only pretend to be interested in security. They make grand statements, goals, etc; but when it comes to practice almost everything else trumps security, most common is ease of use. If making it more secure makes it 'harder' to use - then less secure and easier to use is almost always chosen.
The only way to combat that is to make the vulnerability public and force the company to fix the hole. This has been true with large and small companies, rich/poor, popular/mostly unknown.
So, without speaking to the latest issue with openSSL specifically, it's definitely an interesting debate to have.
In fact, right now there is a huge debate in the security community about whether the NSA should be forced to release all the exploits they've found. One side says that will hurt our national security, waste valuable NSA research, money, and time, and possibly give our enemies an edge. The other side is that if the NSA found out about it, so can China, or Russia, or anyone else, and unless the NSA tells manufacturers they found it then the vulnerability will exist for everyone. It's an interesting conversation, with lots of different situations and differing opinions.