Trying to understand everything while reading http://heartbleed.com/
This sentence Leaked secret keys allows the attacker to decrypt any past and future traffic to the protected services and to impersonate the service at will
this sounds pretty serious.
Now there are many private/small company websites that don't necessarily have SSL encryption for their site. Is this kind of malicious behavior also possible without heartbleed and SSL? If so does that mean every non SSL site could be an impersonated version? Is the information obtainable with heartbleed the same information hackers can get if a site is non-ssl encrypted or less/more?