Fine, I Finally Set Up a Password Manager

Fine, I Finally Set Up a Password Manager

Tutorials heartbleed lastpass password-manager security

So it's been about eleven days since Heartbleed broke the internet, and my inbox is still getting the fallout. Yesterday alone I got "please reset your password" emails from Tumblr, GoDaddy, and some forum I signed up for in 2012 and forgot existed. I think it was about Vespa scooters. I don't own a Vespa.

I'd been putting off actually dealing with this. My old system, and I use "system" generously, was three passwords total. One for stuff I didn't care about, one for stuff I sort of cared about, and one "serious" password with a number and a capital letter tacked on for sites that needed one, which I used for email and banking both. Writing that out now it looks even dumber than it felt at the time. Heartbleed didn't touch all three of those places, but it was enough of a scare that I finally sat down Tuesday night and fixed it properly instead of just changing the passwords back to slight variations of themselves, which is what I did the first four times something like this happened.

What I actually did

I went with LastPass, mostly because it's free for the basic version and because they'd put out that little Heartbleed checker tool a few days after the bug went public, where you paste in a URL and it tells you whether the site was vulnerable and whether it's safe to change your password yet (changing it too early, before the site patched, was apparently pointless, which nobody mentioned loudly enough early on). I know 1Password is the other big name people recommend, and it's probably fine, but it's a one-time purchase through the Mac App Store and I'm on a PC at home and a work laptop that isn't mine, so the browser-based thing made more sense for how I actually live.

Setup took about forty minutes, most of which was the browser extension importing bookmarks I apparently saved from a site called StumbleUpon. The actual painful part was going through and changing passwords on maybe thirty accounts one at a time, because LastPass doesn't do this for you, it just generates you a new one and remembers it. Some sites made this miserable in ways that had nothing to do with security. One financial site capped passwords at 12 characters and wouldn't allow certain symbols, which is somehow worse in 2014 than it would've been in 2004. Another wanted a security question answer that was "your mother's maiden name" and I'd apparently already used a fake answer for that back when I set the account up, and had no memory of what fake answer I'd picked. Small stuff, but it adds up to an evening.

A few notes if you're doing this too, since I know at least a couple people who read this are still on the three-password system I just described:

  • Do your email first. If someone gets into your email they can reset almost everything else, so that's the one account where a genuinely random 20-character password matters most.
  • Don't bother resetting passwords on sites that haven't confirmed they patched OpenSSL yet. Mashable and a couple other places were keeping running lists of which major sites were still vulnerable as of last week; it's worth a quick search before you burn the effort on a site that'll just get your new password intercepted too.
  • Turn on two-factor where it exists. Google, Dropbox, and my bank all offer it and I'd never bothered. Takes five minutes each.
  • The master password for your password manager is the one password you actually have to remember and it has to be good, because it's the key to everything else now. Mine is a sentence, not a word-plus-number thing.

I'm not going to pretend this fixes everything. LastPass itself has been vulnerable to stuff before, and putting all your eggs in one basket is a real tradeoff, not a solved problem. But going from "one password for my entire digital life" to "one password that unlocks a vault of separate strong ones" is a real improvement even if it's not a perfect one, and it's the kind of thing that's easy to keep meaning to do and never actually do until something like Heartbleed makes you feel dumb enough to finally sit down and do it.

Also, briefly, the Galaxy S5 apparently started shipping to actual buyers this week and from what I've read the fingerprint sensor is finicky and needs a very specific swipe angle to work, which is exactly the kind of feature that sounds great in a keynote and annoying in real life. Not switching from my phone yet either way, but noting it.