Adobe was recently breached and 150,000,000 user accounts were stolen. Adobe was following the one of the worst practices of password storage — reversible encryption (rather than hashing with a salt using a good, slow algorithm like bcrypt). A very, very old throwaway password of mine was among those leaked.
XKCD has referred to this breach as The Greatest Crossword Puzzle in the History of the World!
With the help of LastPass’ Has Adobe Leaked My Password, let me illustrate why:
The following hints have been used by other people that share your password. This information could be used to determine your password as well.
- Life, Universe, Everything
- life?
- DA
- h2g2
- hitchiker’s guide to the galaxy
- yes
- meaningoflife
- theusual
- everything
- hitchhiker
- dolphins
- gta
- a4
- answer
- meaning?
- life
- the answer
- the question of life
- HGTTG
- meaning of life
- the usual
- life..
- life the universe and everything
- a2lae
- the ultimate
- Hitchhiker
- What’s the answer?
- hitchhikers?
- Life the Uni and Every
- life meaning and flower
- common
- douglas adams
- a?
- maiden
- lotr no #
- Adams question
- Hitchhiker’s Guide
- answer?
- question
- Life Meaning
- adams
- life universe everything
- HHGTTG
- the number
- towel
- typical
- The Usual
- How many roads must a man walk down?
- Life, the universe, and everything
- What is the meaning of life, the universe and all?
Would you care to guess what password the naive, young me used for Adobe?
Next steps
- Check whether Adobe lost your password
- Get LastPass browser extensions
- Once your passwords are in LastPass, use the LastPass Security Challenge to eliminate duplicates