The website certificates haven't been updated and the site seems to be possibly vulnerable based on generic version info. Any timeline for securing the site & data?
I don't see any discussion of Heartbleed with the Tornado server. That doesn't mean it's not using it, as a scan of the GitHub for Tornado has comments indicating that OpenSSL is required for SSL.
Interesting response. The certificate that was issued previously has not been revoked and the current cert in use by the top level site was issued on 5/26/2013 and expires on 5/30/2014 but hasn't yet been swapped.
Answers