Following the Heartbleed revelations, the security advice from the great and good was to change all passwords. To support World Password Day, I changed over 40 other them – quite an interesting exercise. Alarmingly, it appears I am still vulnerable.
To tell the story of why I am still vulnerable, this blog is split into three parts:
- How I changed 40+ passwords – each unique, the short-cut I found, and a suggestion for the future to make it easier next time.
- A set of annoying things I found doing it, and finally…
- The alarming finding next time I logged on…
In the first part of this blog series, I look at the process of changing and remembering 40+ passwords.
I expected it to take time, I expected it to be annoying, I did not anticipate it being quite as hard as it was.
How can I remember 40+ new unique passwords?
Solution: I didn’t try.
Following advice from various web sites I took the opportunity to implement a password manager (I won’t say which one; I already give hackers far too much detail about me in this blog series).
In most cases, I chose to use a randomly generated password. The exception is when I use the site regularly from an iPad app, so really needed to be able to remember and type the password. This is a relatively small subset of sites.
For these sites I used a password pattern with something to remind me about the site embedded in the pattern. For example, LinkedIn is by business social media tool, so the characters b, s and m are embedded into a common password somewhere. Not fool-proof as by knowing one password you can start to guess the others, but sufficient to prevent automated attacks.
In addition, where possible I implemented two-factor authentication or two-step verification. 10 sites in total. So, even if you guess my password pattern, and figure out my reminder code, you still need the second factor.
Finally, as I am now using a password manager, I also took the opportunity to remove any stored passwords in the browser, and configure the browser to stop remembering them in future – one less vulnerability.
Changing Process.
The process would seem simple.
- Logon to a site
- Locate the change password screen
- Store the new password in the password manager
- Job done.
Remembering the logon to the site was not easy. Different user names, unique passwords – an issue I discussed in the blog “Logging on is becoming too hard to do securely“.
Having logged on, finding the password change screen was more challenging than I anticipated, almost as if the web site designer thought this was not an important function and it should be hidden away. I found a quick solution. Don’t try to logon. Don’t try to locate the hidden-away screen. From the logon page simply hit the “Forgotten Password” button. Enter your email address and off you go. THIS WAS A HUGE TIME SAVER.
A few sites were annoying (and more secure?) – they wanted extra details before sending me a reset, link account number or postcode. Not sure what to think about that – but it does bring home how critical access to your primary email account is. Get that, and the attacker can reset all my passwords.
Summary advice.
From experience I can recommend
- Implement a password manager
- Use generated, random, passwords – unique to each site
- Use the password reset mechanism, don’t try to log on – takes too long.
- Take extra security measures to protect the email your password reset emails are sent to.
Recommendation for the future.
Wouldn’t it be great if next time I needed to change all my passwords, I could go to the Password Manager and just click a button to do it for every site? Sadly, I suspect this is quite a way off – as far as I am aware there are no standard APIs for this. Do any of my readers know differently? If so, please advise in the comments field below.

Wow, who knew Heartbleed would come and mess up our lives like this? #passwordnightmares
Heartbleed is old news, move on already. Instead of complaining, take responsibility for your own online security. Use unique, strong passwords and enable two-factor authentication. It’s time to be proactive and stop dwelling on nightmares. #TakeAction #StaySecure
Wow, thanks Heartbleed for making me memorize 40+ new passwords! Not. #nightmare
I don’t know about you guys, but I’m seriously considering hiring a personal password manager. #TooManyPasswords
OMG, can we just go back to using “password123” for everything? #HeartbleedNightmare
Are you serious? Using “password123” for everything is like inviting hackers to a free buffet. It’s time to take security seriously and use strong, unique passwords. #WakeUpCall #ProtectYourself
Wow, changing 40+ passwords? Thanks, Heartbleed, for making my life so much easier… not!
I feel your frustration, but let’s not blame Heartbleed for our own lack of security. It’s a wake-up call to prioritize our online safety. Instead of complaining, let’s take this opportunity to strengthen our passwords and protect ourselves better.
Wow, Heartbleed really messed things up! How can anyone remember 40+ new passwords? #TooManyPasswords
I feel your pain, but let’s be honest – blaming Heartbleed won’t solve anything. It’s time to take responsibility and start using password managers. They securely store all your passwords, so you only need to remember one. It’s a small price to pay for better security. #GetWithTheTimes
Honestly, remembering 40+ passwords is a nightmare. Can’t we just go back to carrier pigeons? 🐦
Wow, changing 40+ passwords thanks to Heartbleed is a total nightmare! How about biometric passwords?