ummm I highly advise you look into security issues abit more next time.
I'm not trying to be a dick but a 3rd party could basically see what was in your servers memory... you understand that right ? If a user logged in, a 3rd party could get lucky and see that information. A 3rd party did NOT need the private key to see the unencrypted data.......
To run the exploit you simply had the download the vulnerability checking script written in python and add an extra line to print the 64k worth of data. It was so simple even I was able to get it working and I am in no way a programmer, security expert or developer etc... ( To confirm I never ran the exploit against this site.. i assumed the software was so old there would be no point even bothering to test)
the following scenario was proven to work on many many vulnerable servers.
Alice lives in Australia and logs into her server in the USA via browser/HTTPS
Bob lives in the UK and ran the exploit and the timing was just right, Alice had just logged in
and Bob got back 64k of unencrypted data, which contained Alices password.
This attack did NOT involve MITM or anything like that... you could basically just keep getting 64k of data from the servers memory.. sometimes it might be posts, useless crap and obviously very occasionaly you might get lucky and get passwords. But you DID NOT need to be in the path of the user or server... that is why this was so critical and every other website was concerned and advised people to change passwords, after is fixed.
How do you know someone wasnt doing this exploit for months, but it only went public a few days ago ? Chances are they werent, but how do you now.
The fact you don't think its necessary to change passwords now is very very scary.
You should have a huge alert telling users to change their passwords, as you did with the bitcoin client update.
Seriously.. do you just not give a shit about the users security ??
You only seem concerned with generating revenue from advertisements.
I updated the keys.It's never a bad idea to change your password, but in this case I don't really think that it's necessary.