Recent versions of OpenSSL have a buffer overflow vulnerability that can cause data leakage. The bug is only exploitable if you are setting up or already using a secure HTTPS connection. By sending a maliciously-constructed heartbeat request, you can get OpenSSL to reply with up to 64KB of data that wasnt supposed to be sent at all. You might discover the username and password of someone who logged in just before you, thus: heartbleed. Naked Security is promoting Two Factor Authentication.”]
Source: https://nakedsecurity.sophos.com/2014/04/12/heartbleed-would-2fa-have-helped/