That Twitter Password Bug Finally Got Me Off My Butt

That Twitter Password Bug Finally Got Me Off My Butt

Tech News password-managers passwords security twitter

So Twitter dropped a blog post a couple days ago that made my stomach do the thing it does whenever I read the words "plain text" and "password" in the same sentence. Turns out a bug in how they hash passwords meant that before the hashing actually happened, the raw password got written into an internal log. Not exposed publicly, not stolen (as far as anyone's said), just sitting there readable on their own servers longer than it should've been. Their fix was already in place by the time they told us, and they said they'd found no evidence of misuse. Fine. I believe them, mostly. But they also told all 330-something million users to go change their password anyway, and honestly, good.

I want to be annoyed at Twitter for this and I sort of am, but mostly I'm annoyed at myself, because the email telling me to change my password made me actually go look at how many places I'd used some variation of the same one. I wont tell you the base password because thats embarrassing, but I will tell you it had a "2" in it that I'd bump up every time some site forced a reset. Like a little odometer of my own laziness.

I spent Wednesday night doing the thing I've been putting off since roughly 2013: setting up a real password manager and going through, site by site, killing off the reused ones. I ended up on 1Password, mostly because a friend at work wouldnt shut up about it, and it was six bucks a month for the family plan which felt like nothing once I actually sat down and counted how many accounts I had. Forty-one. Forty-one logins, and maybe six unique passwords spread across all of them, with my email and one bank site being the only ones that had something actually distinct. Thats not a great ratio when you think about it for more than four seconds.

The tedious part isnt setting up the manager, its going back through old accounts you forgot you had. I found a Myspace login still active. I found a Woot account I havent touched since maybe 2011. Digg. An old Posterous thing (RIP), which felt weirdly fitting given how this blog started around the same era everything else did. Each one got a new 20-character garbage-string password and I didnt even try to remember any of them, which is sort of the whole point and also the part that took some getting used to. Ive spent my whole adult life memorizing passwords like it was a skill worth having. Turns out it was never a skill, it was just a habit I never questioned.

Twitter's not the only company that had a rough week, by the way, Facebook's F8 conference happened right before this, and there was a lot of noise about Zuckerberg unveiling a "Clear History" feature that lets you disconnect the data Facebook collects about you off-platform. Im not going to go into all of that here because I guarantee every tech blog on earth is writing that same post this week and I dont have anything to add that a hundred other people havent already said better. But it's funny that in the same seven days we got "heres a new privacy control from the company that watches everything you do" and "oops we accidentally logged your password" from two different giants. Not a great week for feeling good about where you type your secrets.

Anyway. If you havent changed your Twitter password yet, do it. And if youre one of the people still running the same six-character word-plus-number combo across your email, your bank, and your Xbox Live account (I know some of you are, dont lie), maybe this is the nudge. It took me about ninety minutes total, split across two evenings, and a glass of wine helped. I'm not going to pretend a password manager is exciting technology. Its the digital equivalent of flossing. Nobody brags about it at parties. But I havent typed a real password into a login box since Wednesday, just autofill and a fingerprint, and there is something genuinely nice about not having that low hum of "did I reuse this one" running in the back of my head every time I log into something.

Go check your own password situation. You probably already know its bad.