Ah, yes, this is definitely true. (And hopefully, they've fixed it in the right way: i.e., applied the software patch, generated new keys, and updated their certificate authority.) > From: ", Flora" <http://www.state.vt.us/~Flora.> > Date: Thu, 10 Apr 2014 19:10:13 +0000 > > Another email I just received. > > From: Bates, Karen L > Sent: Thursday, April 10, 2014 3:03 PM > To: DPS - Everyone > Subject: FW: Heartbleed Follow-up > > One further thing I should make clear: > > If you are going to change your password for one of the affected websites; be > sure they have applied the patch to fix this issue before doing so. > > If I have confused you, my apologies, reach out and I will clarify. > > Thank you, > > Karen