So I got The Email. You probably did too if you've ever had a Creative Cloud account or bought anything from Adobe going back to whenever. Subject line was something like "Important Customer Security Announcement," and it told me, very politely, that my ID and encrypted password had been part of whatever got pulled off Adobe's servers when they got broken into. They're saying something like 2.9 million accounts so far, plus source code for Acrobat and ColdFusion, which is its own special kind of bad news if you're the kind of person who worries about that stuff. I am that kind of person now, apparently.
Here's the embarrassing part. My Adobe password was the same password I used for maybe nine other things. Not proud of it. I want to say I'm smarter than that but I'm typing this at 11pm on a Thursday with a half-eaten bag of pretzels next to the keyboard, so let's not pretend I have my life together.
I'd been meaning to set up a real password manager since forever, the way you mean to floss more. This was the kick I needed. So instead of just complaining about it on here (which, lets be honest, was my first instinct), I actually went and did it, and figured I'd write up what that looked like in case anyone else is procrastinating on the same thing.
What I ended up using
I went with LastPass over 1Password mostly because it's free for the basic stuff and works as a browser extension without me having to think about syncing a file across three computers. 1Password is genuinely nicer looking and a lot of people I trust swear by it, but it wanted me to manage my own sync through Dropbox and I did not have the patience for that on a Tuesday night. If you're the type who doesn't trust cloud-stored vaults at all, KeePass is the other obvious option — it's free, open source, and keeps everything local, but the interface looks like it was designed in 2004 because, well, it kind of was.
The actual process, roughly
First thing was just installing the browser extension and letting it import my existing saved passwords out of Chrome, which was a genuinely upsetting experience. Seeing all of them lined up in a list, realizing how many were literally the same string with a number swapped at the end, was like opening a closet you'd been avoiding.
Then I went through and changed the important ones first. Email obviously. Banking. Then the Adobe one itself, plus everywhere else I'd used that exact password, which took embarrassingly long to figure out because I hadn't kept track. LastPass has a "generate password" button that spits out something like xQ7#mK2!vLpR9, and I just let it do that for everything instead of trying to come up with my own clever scheme. The whole point is you're not supposed to remember these anymore. That's the trick that took me the longest to actually accept — I kept wanting to make passwords I could type from memory, and the entire idea is you stop doing that.
The one password you do still need to remember is the master one for the vault itself, and for that I did the thing security people always recommend, which is a few random unrelated words strung together rather than a single word with symbols swapped in. Something you can actually type without looking, but that isn't in any dictionary as a phrase. Took about four tries to land on one that felt memorable but wasn't dumb.
Was it annoying
A little, yeah. There's a stretch of a few days where every third site makes you stop and reset something, and it's tedious in the way updating your address with a dozen different companies is tedious. But it took me maybe ninety minutes total spread across two evenings, and now new accounts take less time to set up than before because I'm not sitting there trying to think of a clever new variation.
I'm not going to pretend this makes me immune to the next company that gets its database dumped somewhere. It just means when it happens, it's one password that's compromised instead of nine. Small thing, but it's the kind of small thing that actually matters more than people give it credit for.