It's certainly a bad bug, and it ought to have been caught. But it feels like this would be much harder to exploit than many other bugs which have had far less hoopla.
As I understand, this SSL bug makes it rather trivial to perform MITM attacks against apps which use the default system SSL libs.
That's certainly a problem, but most people are using trustworthy ISPs (at least in this sense). Comcast seems unlikely to try to steal your bank password, and Verizon is unlikely to try to harvest your HN cookies.
It seems like this primarily affects people connecting to untrustworthy access-points, such as Coffee Shops, or Airport Wifi - While that's certainly something that needs to be fixed, it seems far less crucial than remote-code-execution [1], or many other bugs we see regularly.
I'm sure I'm missing something here, can someone help me understand? Is it just the "Ick" factor of having something you thought was encrypted actually being fairly open?
I don't understand why this is getting more attention that other (seemingly) more dangerous exploits.
[1] - http://msisac.cisecurity.org/advisories/2013/2013-088.cfm