n
13

Vent: My password system was a joke until I saw my own data on a paste site

For years I used the same base password with small changes for each site, like adding 'fb1' for Facebook or 'amz2' for Amazon. I thought it was clever and easy to remember. Then last week, a friend sent me a link to a site that lists leaked passwords and usernames. I typed in my old email address, the one I used from 2010 to 2018. There it was, my 'base' password from an old forum breach, plain as day. Seeing it sitting there in a public list, with all my variations basically spelled out next to it, was a real gut punch. It meant anyone who found that list could easily guess my logins for a dozen other places. I spent all of last Sunday changing every single password to completely different, long ones stored in a password manager. Has anyone else had that moment where they saw their own bad security habit written out in the open like that?
3 comments

Log in to join the discussion

Log In
3 Comments
skylerbell
I mean, is it really that big of a deal? Like @burns.fiona said it feels bad, but who's actually going to dig through those lists to target one person? Most of that stuff just gets used for spam bots. Changing everything is smart, but seeing your old password out there doesn't mean you're instantly hacked.
8
dakotacraig
Found my old Runescape password on one of those lists, felt like getting sucker punched.
4
burns.fiona
Ugh same thing happened with my Neopets login! That sinking feeling is the worst.
3