The Adobe Breach Made Me Finally Get a Password Manager

The Adobe Breach Made Me Finally Get a Password Manager

Tech News adobe data breach passwords security

Last Thursday Adobe sent me one of those emails you never want to open at 11pm while half-watching a rerun. Subject line: "Important Customer Security Announcement." I almost archived it as spam because who actually reads those, but something made me click, and thank god I did.

Turns out Adobe got hacked, badly. Brian Krebs broke the story on his site (KrebsOnSecurity, if you dont already read it, start now) working with a security outfit called Hold Security, and the numbers Adobe put out officially were bad enough on their own: something like 2.9 million customer accounts, encrypted credit card numbers included. Worse, in my opinion, is that whoever got in also walked off with source code. Photoshop's source code. Not some marketing database, the actual guts of software I use every single day for freelance work.

I run Creative Cloud, $49.99 a month for the full suite, which I griped about when they killed the boxed CS6 license model and I'm going to gripe about it again right here because I still think it was a bad trade for a lot of people who dont touch half the apps in the bundle. That's a separate rant though. The point is I've got an Adobe account tied to a credit card, and I had zero idea whether my specific record was sitting in that pile.

So Tuesday night, instead of doing literally anything productive, I sat down and started changing passwords. Not just the Adobe one. Because (and this is the embarrassing part I'll admit to on my own blog) I'd reused that same password, or some lazy variant of it, on probably a dozen other sites. Email, a couple of forums, an old Newegg account I'd honestly forgotten existed. That's the actual danger here. It's not that someone drains your Adobe account, it's that a breach on one boring service becomes the skeleton key for everything else you've ever signed up for.

It took me close to two hours to get through every login I could remember, and I'm still sure there are accounts from 2009 out there running that same password on some server nobody's patched in years. I finally caved and installed LastPass afterward. I'd looked at password managers before and always talked myself out of it, too much friction, dont trust a browser plugin with my bank login, all the usual excuses. After Tuesday night those excuses felt pretty thin.

A few things stuck with me about this whole mess.

Adobe's disclosure was actually decent as these things go. They emailed affected users directly instead of burying a line in a blog post nobody reads, and they're offering a year of free credit monitoring for US customers. Doesnt undo the source code theft, but at least it's not radio silence.

The source code angle is the part that should worry people more than it seems to right now. A stolen customer database is bad for the people in it. Stolen source code for something as widely deployed as Photoshop or ColdFusion is a different category of problem, because every unpatched vulnerability someone finds by reading that code is a head start against millions of installs that will never get updated. ColdFusion servers especially. Half the ones still running out there havent been touched since whoever set them up left the company.

And this is the smallest complaint in the world, but changing forty-some passwords by hand at midnight is exactly the kind of chore that makes you resent the entire internet for about an hour straight. Every site has different rules. One wants a symbol, one wont let you use a symbol, one caps you at twelve characters like its still 2004. I dont know how anyone managed this before password managers existed without just giving up and reusing everything anyway, which, judging by how big these breach dumps always turn out to be, is exactly what most people do.

If you've got an Adobe account and you havent changed the password yet, or worse, you've used that same one anywhere else, tonight's a decent night to fix that instead of whatever's queued up on Netflix. I'll take my own advice for once.