So I finally did the thing I've been putting off since basically forever: I set up a real password manager. What pushed me over the edge wasn't some New Year's resolution or a lecture from my IT friend, it was reading through the leaked Adobe password hints that started making the rounds last week. If you missed it, Adobe got breached back in October: they said 2.9 million accounts at first, then a few weeks later admitted the real number was closer to 38 million. Turns out Adobe wasn't even hashing the passwords properly, they were encrypting them with the same key in a way that let researchers spot patterns, and they stored password hints in plain text right next to them. Jeremi Gosney over at Stricture Consulting cracked a huge chunk of it and the resulting list of most-common passwords is somehow both hilarious and deeply depressing. "123456" wins, obviously. "adobe123" is right up there too, which tells you people just typed the name of the thing they were signing into. My favorite part was the hints though: hundreds of thousands of people whose hint for their password was just "1-12" or "the numbers" or, my personal favorite from the sample lists going around, "same as always."
Anyway. I use maybe four passwords total across something like thirty accounts, and one of them is a variation on my old college dorm room number, so I don't get to be smug about any of this. Time to fix it.
What I actually did
I went with LastPass, mostly because it's free for the basic version and the premium tier that gets you mobile app sync is only $12 a year, which is nothing. 1Password is the other one everyone recommends and it looked nicer honestly, but it wanted $49.99 up front for the Mac version and I wasn't ready to commit money to something I hadn't tried yet. KeePass is the free/open option a couple of commenters here have mentioned before, and if you want something that never touches a company's servers at all, that's probably the right call, though you just lose the browser autofill convenience unless you mess around with plugins, and I did not have the patience for that on a Tuesday night.
Setup was maybe twenty minutes:
- Install the browser extension (I use Chrome most of the day, so that's the one that mattered)
- Import from Chrome's built-in password manager, which was honestly the scariest part: you get to see just how bad your own habits are laid out in a spreadsheet
- Pick one genuinely strong master password and actually memorize it, don't write it on a sticky note, I promise this is the one step people skip
- Go through your accounts one by one and let LastPass generate new random passwords as you go
I didn't do step 4 for everything in one sitting because that's a multi-day project when you've got sixty-some accounts, half of which you forgot you even had. I did the important ones first — email, banking, and yes, Adobe, since apparently that's the one that started this whole mess for me. I'm doing maybe five a day going forward until the list is clean.
One thing nobody tells you going into this: the generated passwords are genuinely obnoxious to type on a phone if the autofill hiccups for any reason, which it does, semi-regularly, on a couple of sites with weird login forms. I had to manually copy-paste a nineteen-character string into a form on my phone at a coffee shop yesterday and felt like I was defusing a bomb. Worth it, but not fun.
The bigger point, and the thing that actually got me to sit down and do this instead of just nodding along to another "you should use better passwords" post, is that this Adobe leak wasn't really about Adobe. It's about every other site where you reused that same password because it was easy to remember. If "adobe123" is sitting in a cracked list somewhere and you've also got a Gmail account with a variant of it, that's the actual problem. A password manager doesn't fix carelessness, but it at least removes the excuse. I don't have a clean ending for this one — I'm just going to keep working down the list of sixty accounts, five at a time, and probably grumbling the whole way through.