So last Saturday Evernote decided to ruin everyone's weekend by announcing that "unauthorized parties" had gotten into their network and grabbed usernames, emails, and hashed/salted passwords for basically all 50 million users. Nothing catastrophic sounded like it happened (no note content, they said), but they force-reset every single password anyway, which meant Sunday morning I spent twenty minutes on my phone in bed trying to remember which of my six variations of the same password I'd used for Evernote specifically. Spoiler: I hadn't used any of them, because apparently 2011-me had already given up and just typed "letmein2" like an idiot.
I'm not going to do the whole "here's what happened and here's Evernote's official statement" post, because if you read tech news at all this week you've already seen it four times. What I actually want to talk about is that this is the third password-reset email I've gotten since January (LinkedIn's 2012 breach fallout still trickling through, plus some forum I signed up for once to download a font), and I finally sat down and did the thing I've been putting off for probably a year: got a real password manager going.
I went with LastPass over 1Password mostly because of price and because I bounce between a work Windows box and my own Mac constantly, and 1Password's syncing situation in 2013 is still kind of a mess unless you're all-in on Dropbox folders and hoping nothing gets weird. LastPass premium is twelve bucks a year, which is less than I spend on coffee in a week, and it just works as a browser extension without me thinking about it. If you want free, the free tier is genuinely fine too, you just don't get the mobile app.
The actual setup, if you're doing this today:
- Go export whatever passwords Chrome or Firefox has been quietly hoarding for you. Chrome: Settings > Show advanced settings > Manage passwords. It's ugly but it's there.
- Install the LastPass extension and let it import that mess. Don't panic when you see 140 saved logins, most of them are dead accounts you forgot existed.
- Turn on the LastPass Security Challenge (it's a menu option, not automatic) — it scores every saved password and flags the reused ones in red. Mine came back as a 38 out of 100 the first time, which is embarrassing to admit on a blog with your name on it, but there it is.
- Actually go change the flagged ones, starting with email, banking, and anything with your real name attached. Don't try to do all 140 in one sitting or you'll quit by password nine.
- If the site offers two-step verification, turn it on. Google's had this for a while now and it takes maybe four minutes with Google Authenticator on your phone. Evernote, notably, does NOT have two-step yet, which given the week they just had seems like something they should probably prioritize.
The annoying part nobody tells you about is how many sites still have insane password rules that break generated passwords — no special characters, or a hard cap at 12 characters, or (my personal least favorite) sites that silently truncate anything past 16 characters without telling you, so you generate a beautiful 20-character random string and then can't log back in for ten minutes because you don't realize it only saved the first chunk. I hit that exact wall with an airline site last month and wanted to throw my laptop.
None of this is exciting or new information if you already do it. But I'd guess most people reading this are still in the one-password-with-minor-variations camp, because I was too until Saturday morning gave me a reason to stop being lazy about it. It doesn't take long. It's not fun, exactly, but it's a lot less annoying than the alternative, which is finding out your email got used to reset your bank login because you've been typing "letmein2" everywhere since 2011.
Also, small aside: SXSW starts tomorrow down in Austin and my Twitter feed is already 40% people posting photos of their badges like it's a backstage pass to something. I've never been. I hear the barbecue is worth the trip even if the panels are hit or miss.