4 ms·
I feel like I'm missing a partial context but "You can change all of your passwords in 30 minutes tops" is not true. I have a minimal amount of accounts (I clos
by cakes 10y ago
I feel like I'm missing a partial context but "You can change all of your passwords in 30 minutes tops" is not true. I have a minimal amount of accounts (I close accounts I don't use) and I can't imagine it taking me less than several hours of slogging through it to change all my passwords (e.g. updating password database, 2FA confirmations, making sure I don't lock the account I change the password on, etc.)
So I have to aim for the clearly impacted ones from this (if named/discoverable) and then have to decide how vulnerable I feel and whether I should go through the extra effort (or not) for every password I conceivably have.
- sverige 10y agoI am halfway through changing the 60 passwords for services and accounts I have used since last September. Cloudflare's COO publicly dismissing the danger with a wan smile and a wave of his hand was motivation enough for me. That, and this ridiculous statement: "Unfortunately, it was the ancient piece of software that contained a latent security problem and that problem only showed up as we were in the process of migrating away from it," he wrote. My understanding is that they were not "in the process of migrating away from" an "ancient piece of software," but rather that this was something they implemented five months ago and that they had no idea anything was wrong until Google told them what they found. That sort of behavior does not inspire trust and confidence.