That said, he goes on to claim that even if he had been using a buggy SSL stack, his stunnel setup "keeps the bug away from anything sensitive." But his prior blogpost on the stunnel setup[1] itself acknowledges some limits: "if someone compromises OpenSSL, they will still be ... able to steal the SSL certificate, to be sure, and also able to intercept other HTTPS connections". Meaning, I think, they'd have access to the net traffic in cleartext --- including such goodies as usernames and passwords, which might be shared with other sites.
(Colin might respond, "use a password manager". He very likely does. Most likely, though, a lot of his clients don't.)
So, if they (well, he) had been running a vulnerable OpenSSL, he might still have things to worry about.
[1] http://www.daemonology.net/blog/2009-09-28-securing-https.ht...