"The site offered the Heartbeat TLS extension prior to the Heartbleed disclosure, and is still using the same certificate. "
its only getting flagged because they are using the same ssl certificate as before they patched the heartbleed vulnerability - so the site is not vulnerable now, but technically if it was hacked before they patched it, and you haven't changed your password since they patched it, a hacker could have got your password and still be able to use access your account. simple fix is to reset your password again, if you want to be sure.
although thinking about it, it all happened around the time when they moved over to the new store and all the old accounts were lost anyway, so it may be completely irrelevant anyway, but as i said, if you want to be sure, just reset your password again
|