Protecting your passwords after Heartbleed

SLATEApril 12, 2014 

You've probably heard about Heartbleed by now. It's big, bad wolf of an Internet security problem. And though it's mainly server managers who have to take steps to fix it, you can manage your passwords to help protect yourself.

The strangest thing about Heartbleed is that changing your password on a particular site only gives you more protection if that site has already applied to the Heartbleed patch and resolved its vulnerability. If it hasn't, changing your password in advance could theoretically put you at greater risk.

Heartbleed is a vulnerability in a server's memory (RAM), not its data storage, so a hacker has access to things that are being called up by the server not everything that's stored on it. That means that the hacker could ascertain your new password, too.

Lists, which are being frequently updated, can tell you which websites are vulnerable and which have been patched.

For a Heartbleed hit list, go to mashable.com.

CREATE A STRONGER PASSWORD

Once a site is no longer vulnerable, it's time to change your password. You're going to have to do this on a lot of sites, so this is the perfect time so start using a password manager.

A password manager helps you generate random, strong passwords so you don't have to think of them yourself. Then it stores your login information for every site you use, autofilling a password whenever you need one.

You don't need to know or remember your passwords, because they're all stored and protected behind one master password that you make extremely strong and unguessable. I use 1Password, and my master password is a fairly long sentence (without spaces) that includes alternate spellings, numbers in place of certain letters, and punctuation.

HIGH SECURITY

I'll admit it. I kind of hate using a password manager. Setting it up is tedious, and it's a little unsettling to never know any of your passwords.

Password managers aren't about fun, though. They're about proactively protecting yourself from much more annoying, and potentially detrimental, problems down the line.

And they do offer a lot of useful features like super secure notes and a password generator. Many even incorporate two-factor authentication, and in our leaky digital world, it's reassuring to use a service whose only priority is security.

Good options for password managers include LastPass, Dashlane, 1Password, Roboform, SplashID, mSecure, and KeePass. There's initial effort to get your password library going, but once it's up and running it won't get in your way.

Idaho Statesman is pleased to provide this opportunity to share information, experiences and observations about what's in the news. Some of the comments may be reprinted elsewhere in the site or in the newspaper. We encourage lively, open debate on the issues of the day, and ask that you refrain from profanity, hate speech, personal comments and remarks that are off point. Thank you for taking the time to offer your thoughts.

Commenting FAQs | Terms of Service