Finally Setting Up A Real Password Manager (Thanks, Adobe)
So Adobe sent me one of those emails on Thursday. You probably got one too if you've ever bought so much as a $9.99 Photoshop Elements upgrade from them. Turns out somebody broke into their systems and walked off with account info for something like 2.9 million customers (usernames, encrypted passwords, encrypted card numbers, and, this is the part that actually matters, source code for ColdFusion and chunks of Acrobat). Adobe's official line is that the passwords were "encrypted, not plaintext," which is technically true and also not that comforting once you know they used a single key for every single one and left the password hints sitting right next to them in plaintext. I'm not going to spend this whole post relitigating the breach, everybody and their cousin has already written that post this week. What I actually want to talk about is what it made me do, which is finally stop being lazy about passwords.
I've been using Adobe's Creative Cloud since they rolled it out, $49.99 a month for the full suite because I do freelance design work on the side and Illustrator alone justifies it for me. And until Thursday night my Adobe password was a variant of a password I have used, with minor tweaks, since roughly 2009. Same base password, different suffix, on maybe thirty accounts. I knew this was dumb. I've known it was dumb for years. Getting an email at 11pm telling me my account "may have been affected" was apparently what it took.
What I actually did, in order:
- Signed up for LastPass. The free tier does everything I needed — it wasn't until later they started charging for cross-device sync, so at the time this cost me nothing.
- Installed the browser extension in Chrome and let it scan my existing saved passwords. It found 41 accounts. Forty-one! I genuinely thought it'd be maybe fifteen.
- Went through them one by one over about two evenings, generating a fresh random password for anything that mattered — banking, email, the Adobe account obviously, my domain registrar, Dropbox. I didn't bother with random forum accounts I haven't touched since 2011, honestly not worth the ten seconds per account.
- Turned on two-factor where it existed. Gmail already had it (I'd set that up ages ago after a scare with a friend's account getting compromised). Dropbox had just added it too, so that got flipped on. LastPass itself supports Google Authenticator as a second factor on the master login, which felt slightly paranoid to set up but whatever, better than the alternative.
The master password thing is the part that trips people up and I get why. You're moving from "I remember a bunch of similar passwords" to "I remember exactly one password, and if I forget it or lose my two-factor device I am extremely stuck." I wrote mine down on an actual piece of paper and put it in a drawer, which feels like a very 1998 solution to a 2013 problem but I don't care, it works and nobody's hacking my desk drawer remotely.
Is this an overreaction to one breach? Maybe a little. But the honest truth is the breach didn't create the problem, it just finally embarrassed me into fixing something that was already broken. If I'm being fair to myself, this was overdue regardless of Adobe. The reused-password thing is exactly the kind of risk that feels abstract right up until it isn't, and then everyone acts shocked. I wasn't shocked. I was just annoyed it took an actual incident to move me off the couch.
One complaint while I'm at it: LastPass's mobile app on iOS is rough. It doesn't integrate with Safari the way you'd want, so on my phone I end up copy-pasting passwords out of the app into whatever I'm logging into, which is clunky and also a little bit of a security theater problem since now it's sitting in my clipboard. 1Password apparently handles this better with some kind of built-in browser, but it's $17.99 on the App Store and I'd already committed to LastPass by the time I looked into it. Something to revisit, maybe not this month.
If you got the Adobe email and did nothing about it yet, that's fine, most people probably didn't. But do yourself a favor and at least check whether your Adobe password shows up anywhere else in your life. Mine did, in more places than I'd like to admit.