So this was one of those weeks where the security news just kept piling up and I finally ran out of excuses. First there was the Anthem breach a couple weeks back: if you have health insurance through them (or one of the Blue Cross plans they run), your name, birthday, social security number, address, and income info might be sitting on someone's server right now, because about 80 million records got pulled out of their system. No credit card numbers, apparently, which is the one silver lining, but SSNs are arguably worse since you cant just call your bank and get a new one.
Then on Monday Obama did the whole cybersecurity summit thing out at Stanford and signed an executive order about companies sharing threat data with each other and the government. I watched about ten minutes of the livestream during lunch. Tim Cook showed up and gave a pretty pointed talk about privacy without ever saying Apple was better than certain unnamed companies whose CEOs, notably, did not personally show up (Larry Page, Mark Zuckerberg, Marissa Mayer all sent someone else instead). Make of that what you will.
And THEN yesterday Kaspersky dropped this report out of their conference in Cancun about a hacking group theyre calling the Equation Group, who apparently figured out how to rewrite the firmware on hard drives, not just the operating system, the actual firmware, from Western Digital, Seagate, Toshiba and a bunch of other manufacturers, so the malware survives a full wipe and reinstall. Reuters is tying it to the NSA, unofficially. If thats even close to true its honestly kind of amazing from a pure engineering standpoint, in the same way that a really well-built lockpick is amazing even though its also terrifying.
None of that firmware stuff is something a regular person can defend against, to be clear. If a nation-state wants your hard drive specifically, it's getting your hard drive. But the Anthem thing is the ordinary, boring kind of exposure that actually affects normal peoples day-to-day, and it's the one where doing a few basic things actually helps. So I spent Saturday morning doing the thing Ive been putting off for probably two years: actually setting up a real password manager instead of my embarrassing system of "three passwords I rotate depending on how much the site annoys me."
What I actually did
I went with 1Password, paid the $49.99 for a standalone license (no subscription nonsense back then, you just bought the app and it was yours). LastPass is the free alternative if you dont want to pay anything up front, it does 90% of the same job and Ive used it on other machines without complaints. I mention both because people always ask and I dont think it matters much which one you pick as long as you pick one.
The actual process took about ninety minutes, most of which was just importing my genuinely humiliating list of reused passwords from Chrome and then going site by site to change the worst offenders. Banking first, then email, then anything with stored payment info. I did not get through all of them (Ive got maybe 40 more accounts sitting in there still using some variant of a password I first came up with in college), but banking and email were the two that actually mattered so those are done.
The other thing I did, which took five extra minutes and which I'd argue matters more than the password manager itself, was turning on two-factor authentication everywhere it's offered. Gmail, Dropbox, the works. Text message codes aren't perfect (SIM swapping is a whole other can of worms) but they beat nothing, and nothing is what most people currently have.
One thing that's been bugging me since the Anthem news: those security questions sites make you answer when you forget your password — mothers maiden name, city you were born in, that kind of thing — are basically worthless now. That information is exactly the stuff that ends up in breaches like this one. Half my "security questions" are answerable from my own Facebook profile, which, in hindsight, seems like a design flaw someone should've caught a while ago.
Anyway. If you've been putting off the password manager thing the same way I was, this is me telling you it's not actually that bad, and an hour on a Saturday is a pretty low price for not being the easy target in the room.