Home Depot's Breach and the Password Spreadsheet I Finally Deleted

Home Depot's Breach and the Password Spreadsheet I Finally Deleted

Tutorials data breach lastpass passwords security two-factor-auth

So Home Depot confirmed this week that they're "looking into" reports of a possible payment card breach, after Brian Krebs started poking around and finding a pattern that banks were seeing: a bunch of fraudulent charges all tracing back to cards used at Home Depot stores. Nobody's saying how big it is yet, and Home Depot's statement is doing that thing where a company says as little as legally possible while still sounding concerned. But if the shape of this looks familiar, it's because we did this dance with Target back in December, then Michaels in January, then Neiman Marcus a few weeks after that. At some point you stop being surprised and start just assuming every big-box retailer you've swiped a card at in the last year is a coin flip.

I buy an unreasonable amount of stuff at Home Depot. Two garden hoses, a shop vac, roughly four hundred dollars of lumber for a fence project that is still, as of this month, half-finished. All of it on the same Chase debit card, because I never bothered getting a separate card for purchases like that. So my Tuesday night involved sitting on the couch scrolling through six months of statements looking for anything weird, which, thankfully, there wasn't. Yet.

But it did get me thinking about something I'd been putting off for embarrassingly long: I still had a file called passwords.xlsx sitting in my Dropbox, unencrypted, with something like 60 logins in it, half of them reused across multiple sites. I'm not proud of this. I know better. I write a tech blog, for crying out loud. And yet there it was, plain text, syncing quietly to a cloud folder I access from three different laptops.

So instead of just writing an anxious blog post about a breach, I figured I'd actually fix my own mess and write down what I did, in case anyone else has a passwords.xlsx of their own hiding somewhere.

Step one: pick a password manager and actually use it. I went with LastPass, mostly because the free tier does everything I need on desktop and the premium tier is only $12 a year if I ever want the mobile app to autofill too. 1Password is the other big one people recommend, it's more polished honestly, but it's a $49.99 one-time purchase per platform and I didn't feel like paying that today. Either one beats a spreadsheet by a mile.

Step two: import the mess, then go through it account by account. LastPass has a CSV import that ate my spreadsheet no problem. Don't just import and call it done though — the whole point is generating new, unique, actually-random passwords for the accounts that matter, not keeping your old reused ones in a nicer box.

Step three: do email first. This is the one I'd tell anyone to prioritize if they only have twenty minutes. Your email is the recovery path for basically every other account you own — if someone gets into your Gmail, they can reset your bank login, your Amazon, your everything. I turned on two-factor for my Gmail using the Google Authenticator app on my phone, so now logging in from a new device needs a six-digit code that refreshes every 30 seconds, not just a password. Took maybe four minutes.

Step four: turn on 2FA anywhere else that offers it. Dropbox has it. Facebook and Twitter have it, buried a couple menus deep in security settings. A lot of banks still don't, which is its own kind of frustrating given the week we're having. SMS-based codes are weaker than an authenticator app in theory, since someone could theoretically get your number ported, but I'd still take SMS over nothing every single time.

I did maybe fifteen of my sixty accounts before I ran out of steam and went to bed. The rest are still sitting there in LastPass with the old weak passwords, patiently waiting for me to get back to them, which if I'm honest with myself might be a while. There's always something more urgent than account number forty-two on a list nobody's grading you on. I'll get to the rest. Eventually. Probably around the next breach.