Realistically speaking here they found out about this at the same time as everyone else did and addressed it pretty quickly and professionally. Is there really anything else they or anyone else could have done, other then just use KeePass? Which has it's own major inconveniences that can only be addressed by some sort of cloud based solution (whether controlled by you or someone else), which probably would very likely have been using OpenSSL as well ...