So eBay finally got around to telling everyone about their breach last week, and the fallout from that has been sitting in my browser tabs for going on eight days now. If you missed it: someone got into a database with employee login credentials sometime back in late February or early March, sat on it for months, and eBay didnt make anyone change their password until May 21st. 145 million accounts. Encrypted passwords, they say, but "encrypted" from a company that took three months to notice is not exactly a comfort blanket.
I got the email Tuesday morning while I was still in bed scrolling on my phone, and my first reaction was the same one everybody has: ugh, fine, I'll change it. My second reaction, about four minutes later while I was actually on the eBay site typing in a new password, was a much worse one. I typed my "new" password and the site told me it was too similar to my old one. So I typed the actual new one I use for stuff I care about. Same message. Then I realized why: I use basically three passwords for everything, rotated depending on how paranoid I'm feeling about a given site, and eBay had apparently seen all three of them before in some previous form. That is a bad way to live and Ive known it for years and done nothing about it, the same way I know I should floss more.
So this week I actually did the thing I've been putting off since forever, which is set up a real password manager instead of my incredibly clever system of "adjective plus year plus exclamation point."
What I ended up doing
I looked at both LastPass and 1Password over the weekend, mostly because those are the two everyone in my Twitter feed was yelling about. 1Password is a one-time purchase, $49.99 for the Mac app, and it does not sync across devices out of the box unless you're paying for Dropbox too and pointing the vault file there yourself, which honestly took me a bit of fiddling to get working right between my laptop and my phone. LastPass is free for the desktop stuff and $12 a year if you want the mobile app to actually autofill on your phone, which, come on, just pay the twelve dollars, its a coffee and a half.
I went with LastPass in the end, mostly because I didnt want to deal with syncing a vault file myself and I am lazy. Installed the browser extension in Chrome, imported my terrible existing passwords via the built in importer (which for Chrome just reads out of Chrome's own saved-password list, so that part took maybe ninety seconds), and then spent about forty-five minutes going through my "security challenge" report, which is this feature that shows you a giant embarrassing list of every account where you reused the same password. Mine was something like 60-some sites all sharing two passwords. Not my finest moment as a person who works adjacent to computers for a living.
The actual process if you want to do this yourself is not complicated:
- Install the extension for whatever browser you actually use day to day (they support Chrome, Firefox, Safari, IE, not that anyone should still be using IE in 2014, but here we are).
- Import your existing saved passwords so you're not starting from zero.
- Set one real master password. Long, memorable to you, not written on a sticky note. Mine is a line from a song, mangled, plus some numbers that dont mean my birthday or anything findable.
- Go through your accounts one at a time and let LastPass generate a new random password for each one, starting with the ones that actually matter, banking, email, anything with your card saved. Dont try to do all of them in one sitting, you'll burn out around account 15 and give up. I did two sittings, about 20 accounts each.
- Turn on two-factor where its offered. Google and Dropbox both do it and it takes five minutes.
I still havent gotten through my whole list, if Im honest, there's a graveyard of old forum accounts from like 2009 that I'll probably just never fix and thats a risk Im choosing to accept. But my eBay password is now 24 random characters that I will never once need to remember, and thats already a better spot than I was in last Monday. Somebody had to get hacked for me to do this, which is a pretty dumb way to finally get around to basic account hygiene, but here we are.