Hacker News new | ask | show | jobs
Heartbleed Bug: Public urged to reset all passwords (bbc.co.uk)
8 points by markhemmings 4449 days ago
1 comments

Which is worse?

a) Leaving your password unchanged on a site because it is still vulnerable.

b) Changing your password on a site that is still vulnerable.

I think that depends on your password management policies. If you are using a unique password for every site, change them all now and then change the ones that were vulnerable again after they are patched. If you are like many people and reuse passwords, you should not change that password to be one you use at a patched site.