The Dropbox Email Finally Made Me Fix My Passwords

The Dropbox Email Finally Made Me Fix My Passwords

Tutorials 2fa dropbox password-managers passwords security

So I got the email yesterday. "We're requiring you to update your Dropbox password." Fine, whatever, I thought, until I actually read it and realized this was tied to that 2012 breach getting reopened, apparently something like 68 million account credentials floating around from back then. My account hadn't had its password touched since, I'm guessing, 2013. I honestly couldn't tell you. That's the problem.

I want to be upfront about something embarrassing: I've been using a variant of the same password since college. Not literally the same one everywhere, I'm not a total lunatic, but the same root word with different numbers tacked on depending on the site. Dropbox got one version. My old Yahoo mail (still technically alive, don't ask) got another. If you'd cracked one you'd have had a decent shot at guessing the rest. I've known this was bad for years and just never dealt with it, the way you know you should replace the smoke detector batteries and then don't until the thing starts chirping at 2am.

The chirping, this week, was Dropbox.

What I actually did last night

I'd tried LastPass once, years ago, and bounced off it because the browser extension felt clunky and I got annoyed and gave up after like twenty minutes. This time I sat down after dinner, put on a podcast, and just committed to doing it properly. Took about ninety minutes total, most of that just clicking through old accounts.

Here's roughly what worked for me, in case you're in the same boat:

Pick one and commit. I went with LastPass again because it's free for the basic stuff and the browser extension has apparently improved a lot since I last touched it. 1Password is the other big one people were raving about, it's about $2.99 a month now if you go the subscription route instead of buying the app outright, and honestly it looked nicer, but I didn't want to pay for something I hadn't tested. If you're the paranoid type who doesn't trust cloud-synced vaults at all, KeePass is the local-only option, just know you're on your own for syncing between devices.

Set a real master password, once. This is the only password you actually memorize going forward, so make it count. I used four random unrelated words strung together rather than some clever substitution thing, it's longer than a normal password and somehow easier to actually remember. Skip the leetspeak stuff, it doesn't fool anything anymore and it's harder to type than you'd think at 11pm.

Go through your accounts one at a time and actually change them. Don't try to do this in one sitting for every account you've ever made, you'll burn out. I did the ones that mattered: email, Dropbox obviously, banking, Amazon, Twitter. The generator in LastPass spits out these ugly 20-character strings with symbols, and that's the whole point, you're never typing them by hand again.

Turn on two-factor everywhere it's offered. Google Authenticator is still the one I'd recommend, it's a dumb little app that just shows rotating codes, no fuss. Dropbox has had this option for a while and I'd just never bothered turning it on. Took maybe ninety seconds per account.

One thing that annoyed me: a few sites I use regularly still don't offer any second factor at all, which after a week like this feels a little reckless on their part. I won't name names because I don't want this to turn into a whole separate rant, but you'd be surprised which ones.

I ended up with something like 140 saved logins by the time I was done scrolling through old bookmarks and half-remembered accounts I'd forgotten existed (RIP whatever forum I signed up for in 2009). Most of them I'll never touch again. A handful I probably should just delete outright instead of resetting, and I might get around to that this weekend, or I might not, we'll see how motivated future-me is feeling.

Anyway. If you got that same Dropbox email and clicked "remind me later," don't. It takes less time than you think, and unlike flossing, you only really have to set it up once.