If the Heartbleed bug was still viable against your service, I'd say that he made the wrong call and should've emailed your team about it. But here, we're basically talking forensics.
I've written at length about the decision to not roll the keys as soon as Heartbleed was discovered, so I won't repeat myself, but in short: him publicizing this, as well as the Cloudflare challenge immediately getting slapped down, should make it clear to everyone that if you have a memory read, you should assume everything is compromised.
Hopefully this is a good thing for security in general.
For what it's worth, I think that the patch you guys threw out there (and have been using for a while) is a great idea, and I really hope it ends up in mainline OpenSSL. I think you guys have acted 100% properly from a tech perspective in this whole thing, even if a bug did pop up (when do they not?).
I disagree strongly with the business decision made w.r.t. keys, but I hope people don't take that as me ragging on the tech team over there; you guys are doing good work.
pub 4096R/5B9283CE 2007-04-04 [expires: 2017-04-01] Key fingerprint = 4A76 FD9B 3603 C9F5 33F8 1490 49E0 5C45 5B92 83CE uid Akamai Security Team (General Public) <security@akamai.com> sub 2048R/DF985919 2013-03-29 [expires: 2015-03-29]