Then we should just all agree to treat certificates issued before 08/04/2014 to be invalid for everyone.
It will be a day or two of complete mess but given the scale of the exploit it is not crazy to consider every single certificate used before this date to be insecure.
And this way we don't rely on broken revocation mechanism. And it will force sys admins to follow good practice (for instance, the public lab I work for still have not fixed the heartbleed bug on our central auth server and they are not yet convinced it is necessary to regenerate the certificates...).