Draft’s Heartbleed Reponse
On April 7, 2014 information was released about a security vulnerability in OpenSSL, named Heartbleed. You can read more about it, here:
http://heartbleed.com/
It’s a very serious vulnerability that breaks the SSL encryption we depend on to keep our information secret. It affected two thirds of the websites we visit every day, including sites like Google, Yahoo, Amazon, Etsy, Tumblr, etc. Unfortunately, that includes Draft because it uses OpenSSL through its hosting providers Heroku+Amazon.
I have no evidence the vulnerability was used to attack Draft and our data, but I immediately took the recommended actions to protect the service. And for stronger confidence, you should change your Draft password here:
https://draftin.com/draft/users/edit
And because of how many sites use OpenSSL and were affected by this vulnerability, you should change your passwords across the internet...