I'm surprised that I haven't been contacted by any sites yet with advice to reset my password. Is it the case that not many sites were actually running 1.0.1? Or are they just patching, creating new certs, and calling it a day?
I may be wrong, but I think that your credentials with a site are only vulnerable if they had the heartbeats extension turned on.
As for re-issuing certs Namecheap is sucking in that department last night and today (it could be upstream with RapidSSL and PositiveSSL). GoDaddy seems to be speedy even though it looks like the notification emails are not being sent. Fun times :).
It appears so. Many sites that were vulnerable earlier today haven't even inactivated sessions.
I got contacted by Heroku 1h ago to reissue certificate and update my SSL endpoint.