A Year After Heartbleed, My Passwords Are Still a Mess

A Year After Heartbleed, My Passwords Are Still a Mess

Tech News heartbleed password-managers passwords security

So it's been a year. A little over a year, technically, Heartbleed got disclosed on April 7th last year, which means as of yesterday we've officially had twelve months to fix the internet's password problem, and I think we can all agree that we mostly didn't.

I still remember the exact night I found out. I was half-watching something on Hulu and scrolling Twitter when the CVE-2014-0160 stuff started blowing up my feed, and within about an hour it went from "some OpenSSL bug" to "basically every HTTPS site you use might be leaking memory to strangers." Codenomicon and a Google engineer named Neel Mehta found it independently around the same time, which is its own weird little story nobody talks about anymore. Two teams, same bug, same week. Kind of eerie when you think about it.

What actually happened after that, though, is the part that stuck with me more than the bug itself. I spent a Saturday afternoon last April going through something like 40 different accounts changing passwords: banks, email, some forum I hadn't logged into since 2012, Yahoo, the works, and about halfway through my dad called asking if his checking account was "one of the hacked ones." I had to explain that no, it wasn't that his bank got hacked, it's that the lock on basically every door in town turned out to have a flaw, and nobody could say for sure which doors had actually been tried. That distinction did not land well with him. I don't think it lands well with most people, honestly.

A year later, here's where I actually think we are

Sites patched. That part worked. OpenSSL got fixed fast, certs got reissued (eventually, some sites dragged their feet embarrassingly long on that part), and the sky did not fall. No mass wave of drained bank accounts that I'm aware of, no smoking-gun breach that got pinned directly on Heartbleed exploitation at scale. Maybe that happened quietly somewhere and we'll never know, which is sort of the whole problem with a memory-leak bug — it doesn't leave the kind of fingerprints a normal break-in does.

But the human side didn't change nearly as much as the marketing around it implied it would. I still reuse passwords across low-stakes sites. I know I shouldn't. I've had LastPass installed since basically the week Heartbleed happened and I still don't use it for everything, because generating a 24-character random string for a newspaper comment account feels like overkill until it very much isn't. My actual habit, if I'm honest, is a decent unique password on anything with money attached and a lazier shared one for stuff that doesn't matter, which every security person will tell you is exactly the wrong mental model, and they're right, and I still do it anyway.

The bigger shift, if there was one, is that "change your password" stopped being a joke people rolled their eyes at and became something people sort of expect now. Two-factor prompts don't feel foreign anymore the way they did in 2013. Google and Twitter both had it going already, but I noticed way more regular non-tech friends turning it on after last April specifically, which I don't think is a coincidence.

Also, small aside, nothing to do with any of this, the Galaxy S6 is finally hitting shelves this week and I keep seeing people compare the camera to the iPhone 6, which feels like a genuinely new thing for Samsung's flagship to be getting said about it unironically. Not the topic of this post. Just noting it because it's the first Android phone release in a while I've actually been curious to go touch in a store instead of reading the spec sheet and moving on.

Anyway. If you're one of the people who changed 40 passwords in an afternoon last spring and then quietly went back to reusing "the good one" for everything by June, you're not alone, I'm right there with you. The bug got patched. The behavior mostly didn't. That's probably the more honest anniversary story than the one about server certificates.