One of the services I use is saying they were unaffected by heartbleed. But when I check their site with the tool at http://possible.lv/tools/hb/, this is what it says:
Looking for TLS extensions on https://xxxxxxxxxx
ext 65281 (renegotiation info, length=1)
TLS extension 15 (heartbeat) seems disabled, so your server is probably unaffected.
I was under the impression that heartbeat was previously considered benign, and people have only been disabling it in the past couple of days if they didn't want to upgrade OpenSSL. Is there any reason a server might have had it disabled all along?
Alternately, is it possible that the tool could be returning this response if they're using different SSL software that never had heartbeat available? Is there a way I can get more complete information on this?