So Adobe got hacked. You probably heard already, it's been all over the place since Brian Krebs broke the story last Thursday. Attackers made off with data on something like 2.9 million customer accounts, encrypted card numbers included, and (this is the part that actually stuck with me) source code for Acrobat and ColdFusion. Not just "your email got leaked" bad. "Someone now has the blueprints" bad.
I sat with that for about a day before I did the thing I've been putting off for two years: I finally set up a real password manager.
Here's my confession, and I know I'm not alone in this. I had one password. One. It started life around 2009 as a reasonably clever combination of a street name and a number, and by this week it was protecting my email, my bank login, an old Adobe ID I forgot I even had (with a saved card on it, great), a Steam account, and probably a dozen forum logins I haven't touched since 2011. I don't even run Photoshop anymore. I switched to GIMP a while back because I'm cheap and the Creative Cloud subscription math never worked for my budget, but the account was still sitting there, live, with my password on it. That's the part that got me. It wasn't even a service I use.
What I actually did about it
I looked at three options over the weekend: LastPass, 1Password, and KeePass. Quick rundown for anyone else finally getting around to this:
- LastPass is free for the basic version (browser extension, autofill, password generator), $12/year if you want it on your phone too. Cloud-based, so your vault lives on their servers, encrypted.
- 1Password is a one-time purchase, $49.99 for the Mac version last I checked, and it leans on Dropbox for syncing between machines instead of running its own service.
- KeePass is free and open source and very DIY. You manage the database file yourself, which some people like for control and other people (me, initially) find mildly terrifying because there's no "forgot your master password" button to save you.
I went with LastPass. Not because it's objectively the best of the three. People who know more about this than me will argue 1Password's local-storage model is more trustworthy than handing your vault to a company's servers, and that's a fair point. I picked LastPass mostly because I wanted it working on my phone by Sunday night without messing with Dropbox syncing, and the free tier let me test it without committing money before I trusted it.
The actual process took longer than I expected. Not the install, that part's five minutes. It's going back through every account you've ever made. I ended up searching my Gmail for "password" and "welcome to" and "verify your account" to dig up logins I'd completely forgotten existed. Found accounts for a food delivery site I used exactly once in 2012, a browser game, some newsletter signup thing. Each one got a new, random, seventeen-character password I will never memorize and don't need to, because that's the whole point.
The master password is the one thing you do have to actually remember, and I spent way too long on it. Ended up going with a four-word phrase that means something only to me, nothing you'd find by reading my Twitter. If you're doing this too, don't use a quote or song lyric, those get cracked faster than people think because dictionaries of common phrases exist for exactly this reason.
I'm maybe sixty percent through changing everything. Banking and email were priority one, obviously, done Saturday morning. Everything else has been trickling in as I stumble across old accounts or get annoyed enough to bother. There's something a little uncomfortable about handing one app the keys to literally everything, and I get why some people avoid password managers for that exact reason — one master password, one point of failure. But the alternative was what I was already doing, which was worse by a mile. At least now if something gets breached, it's one login and not fifteen.
Still got that old Adobe account to deal with, by the way. Haven't logged in yet to check what card's on file. Not looking forward to it.