How to keep track of all the passwords you (should have) just changed


(Screenshot of 1Password's locker)

If you haven't read about Heartbleed — the security vulnerability that some say affects up to two-thirds of the Web — here's some basic advice: Change all of your passwords, right now. Heartbleed is the result of a simple error in the protocol that secures a lot of the pages on the Web. To simplify, this means that an attacker might be able to seize your login credentials and other information as it's traveling over the Internet.

So the logical next step, beyond perhaps avoiding going online until all your favorite sites have addressed the vulnerability, is to change the passwords you use for those sites. This is also a good time for a general refresher in password hygiene.

Safety in numbers. If you're using a single password across multiple sites, you might want to diversify. The more passwords you have, the harder it will be for an attacker to use one set of credentials to compromise your entire digital life.

What kinds of passwords should I use? There are different ways to pick a password. Multiword phrases can provide good security. You can also select a string of alphanumeric characters — the longer the better. But above all, here's a good rule to keep in mind: The best passwords are ones that you can't remember yourself and that can't therefore be guessed by another human.

How to keep track of your passwords. By this point you should have a good idea of how many sites you use and how many different passwords you'll need to change. The number might feel overwhelming. How will you keep track of them all, especially if each one needs to be unique?

This is where a good password manager comes in. Two great examples are LastPass — which uses the vulnerable protocol OpenSSL but, the developers say, is protected from Heartbleed — and 1Password. Both are password "lockers" created to contain all of your different passwords. To access any of them, you have to enter one, single master password. While that might sound like a big, single point of failure, so long as you choose a strong master password, you'll enjoy more security than using a single weak password for multiple sites, or many weak passwords across many sites.

Update: In a blog post, LastPass now says it supports an automatic check to determine which of your passwords may need changing as a result of Heartbleed.

Related stories:

Major bug called ‘Heartbleed’ exposes Internet data

Heartbleed: What you should know

What you can do about the Heartbleed bug

Brian Fung covers technology for The Washington Post.
SECTION: {section=business/technology, subsection=null}!!!
INITIAL commentConfig: {includereply=true, canvas_permalink_id=washpost.com/8bvh5zpd9k, allow_comments=true, commentmaxlength=2000, includeshare=true, display_comments=true, canvas_permalink_app_instance=bg52e9xhqr, display_more=true, moderationrequired=false, includefeaturenotification=true, comments_period=14, defaultsort=reverseChronological, canvas_allcomments_id=washpost.com/km4ey0dajm, includevoteofftopic=false, allow_videos=false, includesorts=true, markerdisplay=post_commenter:Post Commenter|staff:Post Writer|top_commenter:Post Forum|top_local:Washingtologist|top_sports:SuperFan|fact_checker:Fact Checker|post_recommended:Post Recommended|world_watcher:World Watcher|cultuer_connoisseur:Culture Connoisseur|weather_watcher:Capital Weather Watcher|post_contributor:Post Contributor, childrenitemsperpage=3, includeheader=true, includeverifiedcommenters=true, defaulttab=all, includerecommend=true, includereport=true, maxitemstop=2, source=washpost.com, allow_photos=false, maxitems=7, display_ugc_photos=false, includepause=true, canvas_allcomments_app_instance=6634zxcgfd, includepermalink=false}!!!

UGC FROM ARTICLE: !!!

FINAL commentConfig: {includereply=true, canvas_permalink_id=washpost.com/8bvh5zpd9k, allow_comments=true, commentmaxlength=2000, includeshare=true, display_comments=true, canvas_permalink_app_instance=bg52e9xhqr, display_more=true, moderationrequired=false, includefeaturenotification=true, comments_period=14, defaultsort=reverseChronological, canvas_allcomments_id=washpost.com/km4ey0dajm, includevoteofftopic=false, allow_videos=false, includesorts=true, markerdisplay=post_commenter:Post Commenter|staff:Post Writer|top_commenter:Post Forum|top_local:Washingtologist|top_sports:SuperFan|fact_checker:Fact Checker|post_recommended:Post Recommended|world_watcher:World Watcher|cultuer_connoisseur:Culture Connoisseur|weather_watcher:Capital Weather Watcher|post_contributor:Post Contributor, childrenitemsperpage=3, includeheader=true, includeverifiedcommenters=true, defaulttab=all, includerecommend=true, includereport=true, maxitemstop=2, source=washpost.com, allow_photos=false, maxitems=7, display_ugc_photos=false, includepause=true, canvas_allcomments_app_instance=6634zxcgfd, includepermalink=false}!!
Comments
SECTION: {section=business/technology, subsection=null}!!!
INITIAL commentConfig: {includereply=true, canvas_permalink_id=washpost.com/8bvh5zpd9k, allow_comments=true, commentmaxlength=2000, includeshare=true, display_comments=true, canvas_permalink_app_instance=bg52e9xhqr, display_more=true, moderationrequired=false, includefeaturenotification=true, comments_period=14, defaultsort=reverseChronological, canvas_allcomments_id=washpost.com/km4ey0dajm, includevoteofftopic=false, allow_videos=false, includesorts=true, markerdisplay=post_commenter:Post Commenter|staff:Post Writer|top_commenter:Post Forum|top_local:Washingtologist|top_sports:SuperFan|fact_checker:Fact Checker|post_recommended:Post Recommended|world_watcher:World Watcher|cultuer_connoisseur:Culture Connoisseur|weather_watcher:Capital Weather Watcher|post_contributor:Post Contributor, childrenitemsperpage=3, includeheader=true, includeverifiedcommenters=true, defaulttab=all, includerecommend=true, includereport=true, maxitemstop=2, source=washpost.com, allow_photos=false, maxitems=7, display_ugc_photos=false, includepause=true, canvas_allcomments_app_instance=6634zxcgfd, includepermalink=false}!!!

UGC FROM ARTICLE: !!!

FINAL commentConfig: {includereply=true, canvas_permalink_id=washpost.com/8bvh5zpd9k, allow_comments=true, commentmaxlength=2000, includeshare=true, display_comments=true, canvas_permalink_app_instance=bg52e9xhqr, display_more=true, moderationrequired=false, includefeaturenotification=true, comments_period=14, defaultsort=reverseChronological, canvas_allcomments_id=washpost.com/km4ey0dajm, includevoteofftopic=false, allow_videos=false, includesorts=true, markerdisplay=post_commenter:Post Commenter|staff:Post Writer|top_commenter:Post Forum|top_local:Washingtologist|top_sports:SuperFan|fact_checker:Fact Checker|post_recommended:Post Recommended|world_watcher:World Watcher|cultuer_connoisseur:Culture Connoisseur|weather_watcher:Capital Weather Watcher|post_contributor:Post Contributor, childrenitemsperpage=3, includeheader=true, includeverifiedcommenters=true, defaulttab=all, includerecommend=true, includereport=true, maxitemstop=2, source=washpost.com, allow_photos=false, maxitems=7, display_ugc_photos=false, includepause=true, canvas_allcomments_app_instance=6634zxcgfd, includepermalink=false}!!
Show Comments
Most Read Business
Next Story
Brian Fung | April 9