Ask HN: Who's willing to reset user passwords in response to heartbleed?
Most of the emails I've received have been suggestions to do so with the exception of an email from Optimizely.
Is there a sound argument to not reset passwords? I realize it's a pain for users and we've been trained to avoid adding friction at all costs. When is there an exception to that rule? And is it heartbleed?