The Password Zuckerberg Reused (And Why I Finally Ditched Mine)

The Password Zuckerberg Reused (And Why I Finally Ditched Mine)

Tech News 2fa linkedin-breach password-managers passwords security

So Mark Zuckerberg's Twitter and Pinterest accounts got hacked this week, and the story going around is basically "ha ha, rich tech guy gets owned too." That's the fun headline. But the actual reason it happened is way more interesting than the schadenfreude, and it's been bugging me enough that I wanted to write it down before I forget the details.

A group calling themselves OurMine got into Zuck's accounts and posted stuff bragging about it. The password they used was "dadada." Not cracked, not brute forced — they just had it, sitting in a massive dump of old LinkedIn credentials that started circulating again a few weeks back. LinkedIn got breached back in 2012, and everybody assumed that was a contained, ancient problem. Turns out someone had been quietly sitting on a much bigger cache from that same breach, something like 117 million email/password pairs, and finally put it up for sale in May. LinkedIn made everyone affected reset their passwords, which is the responsible thing to do, but that doesn't undo the four years where that password was just floating around unused-but-not-forgotten.

Here's the part that actually matters: Zuckerberg apparently used "dadada" on LinkedIn back in 2012, and then reused it on Twitter and Pinterest too. The guy who runs a company with, what, over a billion users worth of personal data, used the same six-character password across multiple services and one of them was a throwaway word doubled up. I don't say this to dunk on him specifically (ok, maybe a little), I say it because if the CEO of Facebook does this, the rest of us have zero excuse pretending we're more careful.

I went and checked my own habits after reading about this and honestly it wasn't pretty. I had exactly one password I used for probably a dozen low-stakes accounts, forum logins, some newsletter site, a couple of shopping accounts I made once and never touched again. None of those felt important individually. But that's exactly the trap: the danger isn't that someone hacks your forgotten Fandango account, it's that the password from your forgotten Fandango account is the same one protecting your email, and your email is the master key to basically everything else you own online. Password reset flows on almost every service just email you a link. If someone has your email password, they don't need to hack your bank, they just click "forgot password" on your bank's site and read the email.

I finally caved and set up 1Password properly this week, which I'd been putting off for embarrassingly long because typing in a master password every time felt like friction I didn't want. Turns out it's not actually that annoying once the browser extension is doing the autofill for you. It's $2.99 a month for the subscription version they rolled out this year, which felt like a weird thing to pay monthly for at first (a password manager, as a subscription, really?) but whatever, it's less than a coffee and I've already generated something like forty new unique passwords this week alone just going through old accounts.

The other thing worth saying: two-factor authentication would have stopped this cold even with the reused password. Twitter's had 2FA for a while now and it takes maybe ninety seconds to turn on. If OurMine had needed a text message code on top of "dadada," none of this happens. I turned it on for Twitter, Gmail, and Dropbox this week too. It's not glamorous work and nobody's going to write a headline about "local blogger enables two-factor auth," but that's kind of the point, the boring security stuff is the stuff that actually works, unlike most of what passes for advice on this topic.

Anyway. If you've had a LinkedIn account since before 2012 and haven't changed that password everywhere else you might've used it, this is your nudge. Go check. I'll wait.