So this was supposed to be a normal Sunday. Coffee, laundry, maybe finally finishing that RSS reader migration I've been putting off since Google Reader died last year (yes, I'm still bitter, no I'm not over it). Instead I spent about four hours today doing something that felt like digital penance: changing every password I own because of Heartbleed.
If you haven't heard about this yet, congratulations on your peaceful week, and also: go read up on it, because it's kind of a big deal. Short version — there's a bug in OpenSSL, the encryption library that runs a huge chunk of the "secure" web (the little padlock icon you never actually think about), and it's been quietly leakable for something like two years before anyone caught it. It went public last Monday. Since then it's been the only thing anyone in tech has talked about, and I'm not going to rehash the whole explainer here because by now you've read four different versions of it already this week from four different blogs, probably including ones way more qualified than me to talk about cryptography.
What I will talk about is Saturday and Sunday, which I lost to the actual chore of it.
I use LastPass, and generally I like it, but going through and forcing a change on every entry in a vault I've built up since 2011 is not what I'd call a good time. Some sites make it painless — Gmail, Dropbox, Amazon, all quick, in and out in under a minute each. And then there's my actual bank, whose password field, I discovered around 2pm yesterday, caps out at 12 characters and won't accept any symbol except a hyphen. Twelve characters. No exclamation points, no ampersands, nothing. In 2014. I sat there for a solid minute just kind of staring at the error message like it had personally wronged me. It had.
Then there's the sites where you genuinely can't tell if they patched yet or not, so you're stuck in this weird limbo of "do I change it now and maybe leak the new one too, or wait and risk nothing changing at all." I ended up using the Mashable list going around (there were a few of these floating around by midweek) as a rough guide for what had actually patched, which helped, but it's still a lot of manual checking site by site. Filterable Bloomberg or whatever tools exist now, still involves a lot of your own judgment.
The other small thing that happened this week, which got buried under all the Heartbleed coverage but is honestly kind of a bigger deal for a specific slice of people: Windows XP support officially ended last Tuesday. My mom's desktop, the one she uses for email and Facebook and absolutely nothing else, is running XP, and has been running XP since roughly the Bush administration. I keep telling her it's fine as long as she doesn't do online banking on it (she does online banking on it) and I keep getting the same "it works, why would I change it" response that I imagine every tech person's parent gives every tech person, forever, in every decade. I don't have a great answer for that honestly. It does work. That's sort of the whole problem.
Anyway. Somewhere in the middle of this password marathon my cat walked across my keyboard and somehow ended up submitting a form on my credit union's site three times in a row, which locked my account for twenty minutes and meant one more site got added to the pile later than planned. I don't have a point to make about that, I just think you should know it happened, because it felt very on-brand for how this weekend went.
If there's a lesson in here it's not some grand security-hygiene sermon, because honestly by tomorrow half the internet will have moved on to the next thing and I'll be back to reusing three variations of the same password for anything that doesn't matter, and you know it too, don't even pretend. It's more that our whole system of "trust the padlock" has always been a little bit held together with duct tape and best intentions, and every couple years something reminds everybody of that all at once, and for one weekend a bunch of us sit around changing passwords like it's a fire drill. Then we go back to normal. I give it a week.