So I finally did the thing I've been putting off for like ten days now: changed my eBay password. You probably heard about this already because it was everywhere for a while there, but eBay got hit with a breach that exposed encrypted passwords and other account info for something like 145 million users, and they've been nagging everyone to reset since around May 21st. I ignored the email for a full week because, honestly, who reads security emails from eBay in 2014. I mostly use the account to buy old Nintendo cartridges and the occasional weird lamp.
Anyway I finally sat down last night and did it, and it turned into a whole thing, because it turns out my eBay password was the same password I've been using since roughly 2003. Same one from my old Hotmail account. Same one I definitely used on a message board about a TV show I'm not going to name here. That's the part that actually rattled me, not the breach itself. eBay says the passwords were encrypted and there's no evidence of unauthorized access to financial info, fine, sure. But a password I picked as a nineteen year old has apparently been quietly protecting a decade and a half of accounts, and that's a dumb way to live.
So instead of just changing the eBay one and calling it a day, I spent about two hours last night finally setting up 1Password properly, which I'd installed months ago and never actually used for anything beyond the free trial nag screen. Figured I'd write up the short version here since I know at least a couple of you have mentioned doing the same reluctant password-reset shuffle this week.
Getting off the one-password-for-everything plan
The actual setup isn't complicated, which is sort of the whole point. You install 1Password (I'm on the Mac app, there's a Windows version too, and it syncs through Dropbox if you don't want to pay for their separate sync service), you set one genuinely strong master password that you actually memorize, and then you let it generate a unique random password for every single site you use. You never see most of these passwords again. You don't need to.
A few things I'd actually recommend if you're doing this for the first time:
- Don't try to migrate everything in one night. I did about fifteen accounts and my eyes were crossing by the end. Do your email, your bank, and whatever online store has your card saved, then pick off the rest over a week.
- Turn on two-factor where you can. Google and Dropbox both support it now through their authenticator apps, and it's a five minute setup that makes the password itself almost beside the point.
- Longer beats weirder. A four-word phrase like "correct horse battery staple" (yes, the xkcd one, I know, I know) is harder to crack than "P@ssw0rd!" even though it looks less "secure" to a human eye. Length matters more than punctuation gymnastics.
- Write your master password down on actual paper and put it somewhere boring, like inside a book on a shelf. I know that sounds like bad advice from a security standpoint but losing your one master password is a much bigger disaster than someone finding a scrap of paper in your apartment.
I went with 1Password over LastPass mostly because I like that the vault lives on my machine by default instead of sitting on somebody else's server, though I'll admit that's a mild preference and not a hard rule, LastPass is perfectly fine and a lot of people I trust use it. Mainly I just wanted to stop being the guy with one password for everything.
One more thing while I'm thinking about it: WWDC kicks off Monday morning, keynote starts at 10am Pacific like always, and the rumor mill is in full swing about a bigger iPhone screen and a new version of OS X. I'll believe the details when Tim Cook says them out loud. I've been burned by pre-keynote rumor roundups enough times to know better than to write one myself right now.
Anyway. Go change your eBay password if you haven't. Then keep going and change the other twenty that are probably identical to it.