NBC just did a story on it. Not chess.com but the most recent bug that affects ALL sites as,"Vulnerable".
Most Recent
Forum Legend
Following
New Comments
Locked Topic
Pinned Topic
A listing on GitHub on 4/8/14 Tuesday listed Chess.com as "vulnerable".
The LastPass site tester on Wed 6pm 4/9/14 at
https://LastPass.com/HeartBleed/ shows:
For Chess.com
The server software is unknown, might use OpenSSL and could have been vulnerable.
The SSL certificate for chess.com valid 6 months ago at Oct 4 18:54:03 2013 GMT.
This is before the heartbleed bug was published, it may need to be regenerated.
Since many of us have done financial transactions, etc with Chess.com, it would be helpful to:
1. update your SSL version;
2. Notify on frontpage, homepages, and/or prominently;
3. Update your certificate; we know it costs a few bucks, but it would be useful in this case.
4. That this occurred is not your fault; you do not have to hide it! But, not responding to it (and/or not notifying your customers) is on you.