Adobe got popped and now I have to go change like six passwords
So Adobe dropped that breach notice yesterday and I've spent way too much of my evening last night and this morning dealing with the fallout. If you missed it: someone got into Adobe's network and walked off with data on something like 2.9 million customer accounts, plus (and this is the part that actually worries me) source code for Acrobat and ColdFusion. Adobe's line is that passwords were encrypted and not stored in plain text, which is nice, but "encrypted" and "safe" are not the same word and I wish more companies understood that.
I've been a Creative Cloud subscriber since it launched last year, which means Adobe has my card number sitting on a server somewhere, tied to a login I have used, if I'm honest with myself, on at least two other sites too. That's on me, not Adobe. But it's exactly why a breach like this is worse than it looks on paper. It's never just the one account.
Here's my actual complaint though, and it's not really about the hack itself, because breaches happen, companies get hit, whatever. My complaint is about the notification. The email I got this morning was so vague I genuinely couldn't tell for a minute whether it was real or a phishing attempt riffing off the real news. No specifics about what data of mine was involved, just a generic "we take your security seriously" paragraph and a link to change my password. I clicked through manually by typing adobe.com myself instead of using the link, because that's the kind of week it's been.
And look, I get why Adobe wants everyone panicking a little right now, because CC is subscription-only, which means your credit card is permanently on file the second you sign up. That's a decision Adobe made for their own revenue reasons, and it means a breach like this one bites a lot harder than it would have back when you just bought Photoshop in a box at Best Buy and never thought about it again. I actually liked the switch to Creative Cloud for the update cadence (getting Lightroom fixes without waiting for a whole new boxed version is genuinely nice), but this is the tradeoff nobody put on the marketing page.
what I actually did about it
Changed my Adobe password. Changed it again on the two other places I'd reused a version of it, which took embarrassingly long because I had to actually remember where. Turned on the fraud alerts on the card I have attached to my CC subscription just in case, even though Adobe says card data was encrypted too. Might be overkill. Don't care, it took ten minutes.
I've been meaning to actually set up LastPass properly for months and just never got around to it because generating a new random password for every single site felt like a chore I didn't have time for. Yesterday finally pushed me over the line. Downloaded it, ran the extension in Chrome, and I'm now about a third of the way through going site by site and swapping in generated passwords instead of variations on the same three I've used since college. It is, unsurprisingly, way less painful than I expected it to be, and I'm annoyed at past me for putting it off.
None of this is a hot take, I know. "Use a password manager" is the most obvious advice on the internet and I ignored it anyway until a company got hacked and inconvenienced me directly. That's probably how most people actually end up doing it, if they do it at all. The abstract "you should" almost never works. The concrete "here is an email telling you your card number might be floating around" works immediately.
Anyway. If you're on Creative Cloud too, go change your password. It takes two minutes and it's better than finding out the hard way what "encrypted, not hashed" actually meant when someone finally cracks that database open.