Earlier quoted context omitted.
heartbleed was much much worse than unencrypted logins.
I agree that the worst case scenario is much worse; I don't see how it was much worse for the average website of a small business.
heartbleed let you get random memory out of the webserver!